A 21-year-old Florida man has been arrested for allegedly helping distribute malware through video games that infected about 8,000 devices and stole at least $220,000 in cryptocurrency.
Federal agents arrested Zyaire Dontaevious Zamarion Wilkins (aka Zyaire Wilkins) of North Lauderdale on July 14. A criminal complaint filed in Seattle charges him with conspiracy to obtain information from computers for private financial gain.
Court records accuse Wilkins of financing malware development and helping promote infected games between May 2024 and February 2026. Prosecutors say the operation accessed approximately 80 cryptocurrency wallets using private information stolen from victims’ computers.
Malware-Infected Games Reached Thousands of PCs
Although the complaint refers to an unnamed “popular digital distribution software company,” the details point to Steam. As reported by Hackread.com in March 2026, the FBI’s Seattle Division separately describes its case as a Steam malware investigation and names BlockBlasters, Chemia, Dashverse/DashFPS, Lampy, Lunara, PirateFi and Tokenova.
The games were promoted through Discord, Telegram, X and LinkedIn. According to the complaint, the group also used bots to locate people holding substantial amounts of cryptocurrency and send them messages encouraging them to install the games.
Once installed, the malware collected passwords, browser cookies, saved form data, account tokens, and other private information. The alleged conspirators then searched the stolen data for access to cryptocurrency accounts and drained wallets they could enter.
BlockBlasters became the most widely reported game in the campaign after it stole approximately $32,000 from Latvian streamer Raivo Plavnieks, known online as Rastaland.TV. The money had been donated to support his treatment for stage four cancer. Plavnieks died on November 18, 2025, according to his official website.

VX-Underground Traced the BlockBlasters Malware
Before the arrest, according to a tweet from the malware research community VX-Underground, they reverse-engineered BlockBlasters after receiving reports that the Steam game might contain malicious code. Their analysis traced the malware’s infrastructure, examined its operations, and identified other victims and people it believed were involved.
In a July 18 post on X, VX-Underground said BlockBlasters became notable because it was used in targeted cryptocurrency draining campaigns. The researchers said they began examining the game after users reported suspicious activity and later reconstructed the supporting operation.
The federal complaint does not say VX-Underground’s work directly produced the arrest. However, its earlier analysis documented the BlockBlasters theft and exposed technical evidence while the campaign was still being investigated.

Uber Eats Gift Cards Helped Identify Suspect
Investigators say messages recovered from an alleged co-conspirator’s devices showed extensive communication with a Signal user identified as “Sibel.eth.” The complaint alleges that Wilkins used this account, provided money to launch and promote the games, and discussed campaigns designed to empty cryptocurrency wallets.
Agents also found a conversation in which Wilkins allegedly offered a budget of about $10,000 for a remote access Trojan. Blockchain records showed that approximately $10,000 was transferred to the supplied Bitcoin address that same day.
The investigation later followed cryptocurrency payments to Bitrefill, a service that sells gift cards for crypto. An account associated with the funds purchased more than 150 gift cards, including Uber Eats cards.
Records from Uber, Google and other providers led investigators to a phone number, email accounts and delivery addresses associated with Wilkins, according to the criminal complaint.
Wilkins has been accused, not convicted yet, and the allegations must still be proven in court. The FBI continues to ask anyone who installed one of the identified games to submit information, including the game name, installation date and any financial losses.
Victims should change exposed passwords from a clean device and transfer remaining crypto funds to a new wallet if their seed phrase or private keys were stored on the infected computer.

