Video Games

FBI case alleges Steam games hid malware used in a $220,000 cryptocurrency theft

By Crosspad Gaming July 22, 2026
FBI case alleges Steam games hid malware used in a $220,000 cryptocurrency theft
TechSpot's feature image for its report on the alleged malware distribution through Steam games. Image: TechSpot

Federal prosecutors have accused a 21-year-old Florida man and unnamed collaborators of distributing malware through games uploaded to Steam. The alleged scheme infected roughly 8,000 computers and drained at least $220,000 from cryptocurrency wallets, according to reporting from TechCrunch and TechSpot. The charges describe a serious storefront security failure, but they remain allegations. The accused has not been convicted.

TechCrunch reports that prosecutors charged Zyaire Wilkins after an operation that allegedly used several Steam releases to reach victims. The report names BlockBlasters, Dashverse, Lampy, Lunara, and PirateFi among the games connected to the case. Rock Paper Shotgun separately reports that the affected titles have been removed from Steam and that Wilkins was arrested on July 14.

A Valve warning connected to PirateFi malware on Steam
A Valve-sourced screenshot used by TechCrunch in its coverage of the Steam malware case. — Credit: Valve / TechCrunch
Source

What investigators allege happened

The three reports contribute separate parts of the account. TechCrunch supplies the core allegations from the federal complaint: malware-laden games, about 8,000 affected systems, around 80 drained cryptocurrency wallets, and losses of at least $220,000. Rock Paper Shotgun identifies the games and connects the criminal case to an earlier BlockBlasters incident involving streamer RastalandTV. TechSpot adds that the alleged campaign ran for nearly two years.

TechSpot also reports that the malware was designed to take passwords and other sensitive information before targeting cryptocurrency wallets. Its account says investigators followed some of the stolen funds into more than 150 gift cards, used primarily for Uber Eats purchases. That detail matters because it describes part of the investigative trail. It also shows how digital theft can move quickly through several forms of value after a wallet is compromised.

The scale deserves care in the wording. About 8,000 infections does not mean every affected user lost cryptocurrency, and the reported wallet count is much smaller. The public evidence summarized by these outlets supports a large malware campaign and a six-figure alleged theft. It does not support assuming that every listed game's entire player base was robbed.

A major storefront is one layer of trust

Steam gives players a familiar store, payment system, library, and update process. Those conveniences can create a sense that every download has been fully cleared of danger. This case is a warning against treating storefront presence as a complete security guarantee. A harmful release can exploit the same habits that make PC gaming easy: install a new title, approve its launch, and let it update through a trusted client.

That does not mean players need to panic over every small game or abandon independent developers. It means trust should have layers. Storefront review, operating-system security, account protection, wallet practices, and a player's own attention each cover different risks. When one layer fails, the others can limit the damage.

For families sharing a PC, the practical concern reaches beyond a single Steam account. Passwords, browser sessions, email access, saved payment methods, and cryptocurrency tools may all live on the same machine. A game installed by one person can expose accounts used by everyone else. Shared computers need clear rules about who may install unfamiliar software and what financial tools may remain signed in.

Practical steps for PC players

Players who installed any title named in the reports should treat the machine as potentially compromised. Remove the software, update the operating system and security tools, and run a reputable malware scan. Password changes should happen from a separate device believed to be clean. Start with the email account that controls password resets, then secure Steam, financial services, and other valuable accounts.

Cryptocurrency users have an extra reason to keep gaming activity separated from wallet access. A wallet holding meaningful value should not depend on the same everyday environment used to test unknown games. Hardware wallets and clean transaction practices can reduce exposure, although no tool replaces careful verification. Players should also review recent transactions and act quickly if anything looks wrong.

The reports do not establish that every removed title carried identical code or caused identical harm. Players should use the exact affected-game information from Valve or their security provider when available. Broad social-media claims can turn a real incident into confusion, especially when screenshots circulate without dates or source links.

What remains unresolved

The court process still has to test the government's claims. Reporting an arrest is not the same as establishing guilt, and the named defendant is entitled to the presumption of innocence. Further filings may clarify how the games passed onto Steam, how long each title remained available, and what Valve knew at different points in the alleged operation.

For players, the useful conclusion is narrower and immediate. Storefront convenience reduces friction, not risk to zero. Keep important accounts protected, separate high-value financial access from routine gaming when possible, and respond to credible security warnings promptly. That approach protects people without turning a criminal allegation into a reason for indiscriminate fear.

Crosspad Gaming
The editorial team at Crosspad Gaming — tabletop and digital game coverage with purpose.