The FBI has arrested a 21-year-old Florida resident accused of orchestrating a massive cybercrime operation that infected 8,000 PCs through malware-laced video games on Steam. The suspect, identified as Zyaire Dontaevious Zamarion Wilkins, allegedly operated under the dark web alias Sibel.eth. He is now facing multiple cybercrime charges, including conspiracy to distribute malware.
Between May 2024 and February 2026, Wilkins and unnamed co-conspirators reportedly stole at least $220,000 from roughly 80 cryptocurrency wallets. The syndicate embedded a $10,000 remote access trojan into at least eight titles, including BlockBlasters, Dashverse, Lunara, and PirateFi. These malicious titles remained available on the Steam storefront until earlier this year.
To find high-value targets, the group deployed bots across Discord, Telegram, X, and LinkedIn to identify users with significant cryptocurrency holdings. Once a victim installed the infected game, the malware extracted passwords and sensitive data to drain their online wallets. Investigators also recovered Signal chats from an unidentified malware developer's devices, linking Wilkins to the operation and detailing strategies to trick victims into approving fraudulent transactions.
According to forensic cryptocurrency researcher ZachXBT and the online malware repository vx-underground, the game BlockBlasters alone accounted for roughly $150,000 of the stolen funds across 261 to 478 victims. The casualties included Twitch streamer RastalandTV, who lost $32,000 in September 2025. Tragically, the stolen funds were viewer donations intended to cover the streamer's cancer treatment.
Despite the sophisticated digital heist, the FBI tracked the suspects through a glaring operational security failure. Agents traced the stolen bitcoin to over 150 Bitrefill gift cards, which the syndicate primarily used to purchase fast food via Uber Eats.
How to Protect Your Crypto from Gaming Malware
- Verify the publisher's history and community reviews before downloading unknown indie titles on Steam.
- Never approve cryptocurrency transactions or wallet connection requests prompted by unexpected software or game clients.
- Use a hardware wallet (cold storage) for large cryptocurrency holdings rather than keeping them in hot wallets on your primary gaming PC.
The Uber Eats Downfall and the Evolution of Phishing
This case highlights a terrifying shift in social engineering: threat actors are abandoning traditional email phishing in favor of weaponizing trusted platforms like Steam and Discord. By targeting the gaming community - where users frequently download third-party mods and indie titles - hackers successfully bypass the natural skepticism users apply to their email inboxes.
However, the operational security failure here is staggering. Laundering stolen Bitcoin through Bitrefill to buy fast food demonstrates a massive disconnect between the sophistication of a $10,000 remote access trojan and an amateurish cash-out strategy. It proves that while blockchain analysis can track the money, human error in the physical world remains law enforcement's greatest asset.