FBI arrests 21-year-old who allegedly stole $200,000 via malware Steam games and UberEats gift cards
Zyaire Dontaevious Zamarion Wilkins allegedly used weaponized Steam games to steal crypto and spend it through traceable gift cards.

The FBI arrested 21-year-old Florida resident Zyaire Dontaevious Zamarion Wilkins for allegedly distributing malware embedded in Steam games to about 8,000 PCs. Decision-makers should note how investigators link Steam developer access to crypto theft, then to purchasable UberEats gift cards.
The FBI arrested 21-year-old Florida resident Zyaire Dontaevious Zamarion Wilkins for allegedly stealing over $200,000 by hiding malware inside Steam games and turning infected computers into cryptocurrency theft targets. According to the FBI’s criminal complaint, the malware reached approximately 8,000 PCs, and Wilkins and two unnamed co-conspirators allegedly used stolen private information to steal cryptocurrency.
The money trail is where this gets especially real. Investigators say payments were routed to a Signal user named “Sibel.eth,” and that Sibel.eth was identified as Wilkins after the Bitcoin wallet that received the funds was used to purchase over 150 gift cards, some of which were used for UberEats orders linked to Wilkins’ University of West Florida student email address. In other words, the alleged cybercrime did not just end in anonymous wallets. It allegedly ended in transactions traceable back to identifiable personal accounts.
If you build, operate, invest in, or govern consumer software platforms, the core story is the same every time: the attacker finds a distribution channel, piggybacks on trust, and weaponizes it. Here, the FBI says Wilkins and his associates allegedly encouraged social media users to download malware-laden games via Discord, Telegram, X, and LinkedIn. They also allegedly used chatbots to identify and prioritize “individuals with large cryptocurrency holdings,” which is a clue about targeting discipline rather than random opportunism.
The complaint also lays out that the malware was delivered through specific named games. The FBI does not name Steam in the document, but it describes the games as being “available for download on a popular digital distribution software company for videogames located in the Western District of Washington.” It says the weaponized games used for distributing malware were Dashverse (2024), Lunara (2024), PirateFi (2025), Blockblasters (2025), and Lampy (2026). Crucially, the complaint says those titles had all been previously named in a March 2026 call for information from users who had downloaded malicious software through Steam. That ties this case to an earlier public signal, and suggests an investigation cycle that started after affected downloads were already being reported.
From an investigative and compliance perspective, the linkage method matters. The FBI says it identified Wilkins when Google cookie records indicated that an email address tied to one of the co-conspirators’ Steam developer accounts was accessed through the same devices and web browsers used by a cluster of other Google addresses. Those addresses were associated with Apple and T-Mobile accounts. After obtaining a search warrant for the address associated with the Apple and T-Mobile accounts, the FBI seized devices from the premises in February 2026.
The complaint says one of the seized devices allegedly contained records coordinating the Steam malware scheme and Bitcoin payments sent from the co-conspirator to the Signal user named “Sibel.eth.” Investigators then connected the wallet to Wilkins by looking at how it was used: they allegedly found that the Bitcoin wallet used for receiving payments was used to purchase over 150 gift cards. Some of those gift cards were allegedly used for UberEats orders linked to Wilkins’ University of West Florida student email address. This is the operational reality behind many “money mule” narratives, except here the alleged behavior is tied to a consumer platform like UberEats through gift card purchases that leave a trail.
The theft scope is also large enough to raise governance questions for platform owners. The FBI says that during the two years the co-conspirators distributed malware on the platform, they gained access to roughly 80 cryptocurrency wallets and stole at least $220,000. That amount includes $35,000 stolen from streamer RastalandTV, who had raised money to pay for stage 4 cancer treatments. Even if only the complaint’s allegations are considered, this detail underscores why regulators and platform operators take malware seriously: when the victims include mainstream creators and donors, the reputational and legal risk compounds.
For executives, the second-order implication is how quickly attackers can move between “distribution” and “profit,” and how many different systems they can stitch together: game platforms, social channels, chat tools, cookies, mobile carriers, and consumer payment instruments like gift cards. The FBI’s narrative shows that what looks like a gaming problem can become an identity, payments, and fraud problem in parallel. And for boards, investors, and policy leaders, the strategic stake is clear: the threat is not hypothetical, and the evidence can link broad technical compromise to specific personal accounts. That linkage is what turns an incident response exercise into a courtroom story.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Technology

By 2035, data centers could use 4x more electricity than today
A new build pipeline through 2033 may consume power on par with India, forcing operators to plan for scarcity now.
Frozen-fiber tech couples light and sound 1,000x more strongly than standard glass
A glass capillary frozen into a fiber lets photonic systems trade energy waste for tighter light-sound linkage.
Nvidia publishes Vera AI server CPU specs, posting SPEC CPU 2026 integer lead over AMD
The company released a white paper with SPEC CPU 2026 results, placing Vera ahead of AMD's Epyc 9755 for integer performance.

