ZG
Home/Articles/Features/How $220,000 Vanished Through Malware on Steam
← Back to Newsroom
Steam logo appears over a collage of game covers in a featured image for the wishlist update.
Credit: Valve
featureFeature

Trojan Horses on Steam: How $220,000 Vanished Under Valve's Radar

July 23, 2026·7 min read

When you click Install on Steam, you are making an assumption you have probably never put into words. You assume Valve checked, the developer is a real person, the build is clean, and the worst thing that can happen is a boring game.


For around 8,000 people, over roughly two years, that assumption was wrong.


On July 14, the FBI arrested Zyaire Dontaevious Zamarion Wilkins, a 21 year old from North Lauderdale, Florida, and a student at the University of West Florida. The following day prosecutors charged him with conspiracy to obtain information by computer for private financial gain, a count carrying up to ten years.


According to a 15 page federal complaint, Wilkins and a group of unnamed co-conspirators embedded information stealing malware in eight games, infected roughly 8,000 computers, and drained at least $220,000 from about 80 cryptocurrency wallets between May 2024 and February 2026.


He has not been convicted, and everything below is an allegation. But the mechanics laid out in that complaint are worth your attention regardless of how the case ends, because none of this happened on a torrent site or a grey market key reseller. It happened through the official Steam store page.

The Flaw Is Not Where You Think It Is

The instinctive read is that malware slipped past Valve's review. The reality is more uncomfortable than that.


According to the complaint, the games passed Steam's review process clean. They were genuine, working, playable games. The malicious payload arrived later, pushed out in a post launch update, which sidesteps the initial check entirely.


Valve inspected the front door and the attackers came back through it once it had already been unlocked.


Getting the door open allegedly relied on identity theft. The complaint says a co-conspirator identified only as Subject #1 created eight Steam developer accounts using the stolen identities of US citizens.


Investigators say they know who he is and that he is based in Seattle, but he has not been named or charged. He has talked to the FBI, telling agents that Wilkins funded the launch and marketing of the games and took a share of the stolen crypto in return.


The eight titles are BlockBlasters, Chemia, Dashverse, DashFPS, Lampy, Lunara, PirateFi and Tokenova. Researchers have tied the operation to a threat actor known as EncryptHub. The malware harvested saved passwords, session tokens, browser cookies and wallet data while the victim played.

The Victims Were Hunted, Not Found

The operation did not sit back and wait for Steam's search algorithm to deliver targets. That would be slow and would catch the wrong people. Almost nobody browsing new indie releases is holding a six figure crypto wallet.


So according to the complaint, they went hunting. The games were promoted on Discord, Telegram, X and LinkedIn, and bots were used to identify people believed to be holding substantial amounts of cryptocurrency. Those people got a personal approach, an invitation to try a new indie game. The link went to a real Steam store page, with a real store listing, for a game that really worked. Every instinct you have been trained to rely on said this was fine.


Except the cost wasn't abstract. In September 2025, Twitch streamer RastalandTV lost around $32,000 while live on one of his streams. The sad part is, that is wasn't even his own trading float. It was donations from his viewers, raised to help cover his cancer treatment.


Forensic researcher ZachXBT, who did much of the early public work on this, later found the attackers dismissing the theft in their own chats.


BlockBlasters alone accounted for roughly $150,000 of that total, taken from between 261 and 478 victims, and it sat on the store for about a month after its July 2025 release.

Valve's Scaling Problem

Steam Store Game Banners in a Darkened Angled Grid
Valve

So where was Valve in all this?


The company removed the games and contacted affected users, but has not commented publicly on the investigation. The complaint does not even name Steam, referring only to a popular digital distribution software company, though the titles it lists match the ones the FBI warned about in March. The case is being prosecuted in Seattle federal court, a short drive from Valve's headquarters in Bellevue.


Silence is a choice, and it is a familiar one from Valve. But the harder problem is structural. In 2025 Steam passed 132 million monthly active users and more than 117,000 games, with thousands of new titles arriving every year.


A review process built to sanity check a store listing was never designed to be a security perimeter against a funded operation using stolen identities and delayed payloads.


That openness is a genuine gift to small developers, and this operation turned it into a delivery mechanism. Valve cannot have the volume without the exposure, and it has not publicly acknowledged that trade.

Caught by Uber Eats

The infiltration was patient and well funded. The exit was not.


Investigators started with Google cookie records, which showed that an email tied to one of the co-conspirators' Steam developer accounts was being accessed from the same devices and browsers as a cluster of other Google addresses.


Those addresses connected to Apple and T-Mobile accounts. A search warrant followed, and in February 2026 agents seized devices from the associated premises. One of them allegedly held messages coordinating the whole scheme, plus Bitcoin payments sent to a Signal user called Sibel.eth.


Then came the part that reads like a sitcom.


The wallet receiving those payments had been used to buy more than 150 digital gift cards through Bitrefill. Many of them went on Uber Eats. Investigators subpoenaed Uber, and the account tied to the cards had deliveries running to Wilkins' family home and his addresses at the University of West Florida, with a linked student email registered in his name.


His crypto history showed around $382,000 moving through it. When agents searched the North Lauderdale property they seized several devices and three wallet seed phrases, one for Monero.


An alleged $10,000 remote access trojan, stolen identities, encrypted messaging, and the thing that reportedly closed the loop was takeaway food.

What This Actually Changes For You

A game working properly is no longer evidence that its code is safe. That used to be a reasonable heuristic. It is not one anymore, because the build you install today is not necessarily the build that passed review.


The practical advice is boring, which is usually a sign it is correct. Treat unsolicited playtest invitations and free keys with real suspicion, especially by DM on Discord, Telegram or LinkedIn, and with more suspicion, not less, when the link points at a legitimate Steam page.


That link is the bait, not the reassurance. If you hold meaningful crypto, stop keeping it on the machine you install random games on.


If you installed any of those eight games, assume the machine is compromised: move funds from a clean device, treat any seed phrase stored on that PC as burned, and reset credentials from somewhere you trust. The FBI is still asking people who downloaded them to come forward.


None of that is as satisfying as demanding Valve fix it. But Valve has not said much, the games were live for months, and the store page you trusted is the one that served the payload.

Tagged In

SteamMalwareValve