← Zyaire Wilkins (Steam Malware Crypto Theft Ring)1 decision on this page
Audit log
Every state-changing event for Zyaire Wilkins (Steam Malware Crypto Theft Ring): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-07-30 12:10:53ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
EaDPRmDuK2HU…iZ6MM6Gvsha256 → base58
verifying row…canonical bytes (19349 B) ▸
{"actor":"system:backfill","investigation_id":"ab67741e-aa53-4dae-a2e9-1552ff42dbba","kind":"publish","page_slug":"zyaire-wilkins-steam-malware-crypto-theft-ring","published_at":"2026-07-30T12:10:53.069Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Zyaire Wilkins (Steam Malware Crypto Theft Ring)","sections":[{"content":"Zyaire Dontaevious Zamarion Wilkins was arrested on July 14, 2026 and charged in the Western District of Washington (Seattle federal court) with one count of conspiracy to obtain information by computer for private financial gain, in violation of 18 U.S.C. § 1030. The charge carries a maximum penalty of 10 years in federal prison. Wilkins made his initial appearance in federal court in Fort Lauderdale, Florida on July 16, 2026, with transfer to Washington pending at the time of reporting. Investigators executed a search warrant at his North Lauderdale residence on July 8, 2026, seizing digital devices and cryptocurrency wallet seed phrases. At the time of arrest, Wilkins was a student at the University of West Florida. The FBI's Seattle field office led the investigation.","heading":"Criminal Charges and Arrest","severity":"critical","sources":[{"credibility":1,"name":"FBI arrests man accused of using Steam games to drain victims' crypto wallets — TechCrunch","type":"news_article","url":"https://techcrunch.com/2026/07/17/fbi-arrests-man-accused-of-using-steam-games-to-drain-victims-crypto-wallets/"},{"credibility":1,"name":"Feds accuse Broward man in video game malware conspiracy; victims lost $220K in crypto — Local10","type":"news_article","url":"https://www.local10.com/news/local/2026/07/15/feds-accuse-broward-man-in-video-game-malware-conspiracy-victims-lost-220k-in-crypto/"},{"credibility":2,"name":"Feds Arrest Florida Man Over Video Game Malware That Stole $220K in Crypto — Decrypt","type":"news_article","url":"https://decrypt.co/373631/feds-arrest-florida-man-over-video-game-malware-that-stole-220k-in-crypto"}]},{"content":"According to the federal criminal complaint, Wilkins and at least one unnamed primary developer (referred to in filings as 'Subject #1') allegedly uploaded eight fake video games to Valve Corporation's Steam platform between May 2024 and February 2026. The games — BlockBlasters, Chemia, Dashverse (also marketed as DashFPS), Lampy, Lunara, PirateFi, Tokenova, and one additional title — were submitted to Steam with clean initial builds, then updated post-launch to deliver malicious payloads. The alleged conspiracy structure had Subject #1 creating developer accounts and embedding the malware, while Wilkins allegedly supplied funding for game launch and marketing operations in exchange for a share of stolen cryptocurrency and victim personal data. The complaint alleges Wilkins paid approximately $10,000 to fund a remote access trojan and coordinate the scheme, communicating with Subject #1 via the Signal encrypted messaging application under the handle 'Sibel.eth'.","heading":"Alleged Scheme: Malware-Laced Steam Games","severity":"critical","sources":[{"credibility":1,"name":"FBI Arrests 21-Year-Old for Allegedly Infecting 8,000 Computers by Hiding Crypto-Stealing Malware Inside Fake Steam Games — Yahoo News","type":"news_article","url":"https://www.yahoo.com/news/us/articles/fbi-arrests-21-old-allegedly-192208319.html"},{"credibility":2,"name":"FBI used Google cookies, 500 food orders and a Monero seed phrase to identify Steam malware funder — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/fbi-used-google-cookies-500-food-orders-and-a-monero-seed-phrase-to-identify-steam-malware-funder/"},{"credibility":1,"name":"A Florida man is accused of hiding crypto-stealing malware in Steam games — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/florida-man-accused-hiding-crypto-114500816.html"}]},{"content":"The malware embedded in the fake Steam titles was designed to harvest passwords, browser session cookies, user tokens, autofilled form data, and cryptocurrency wallet credentials from infected computers. Security researchers identified multiple malware strains attributed to the campaign, including Vidar (an information stealer), HijackLoader, and a custom tool called Fickle Stealer. The threat actor cluster associated with this campaign has been tracked by researchers under the label 'EncryptHub.' PirateFi, one of the named titles released in February 2025, was identified early by security researchers as deploying Vidar infostealer and was removed from Steam by Valve within days of its release. The malware was bundled in installation packages using InnoSetup and disguised as legitimate game executables. The campaign also used bots on Discord, Telegram, X (formerly Twitter), and LinkedIn to identify users with large cryptocurrency holdings and deliver targeted invitations to install the games.","heading":"Malware Technical Details","severity":"critical","sources":[{"credibility":1,"name":"PirateFi game on Steam caught installing password-stealing malware — BleepingComputer","type":"research","url":"https://www.bleepingcomputer.com/news/security/piratefi-game-on-steam-caught-installing-password-stealing-malware/"},{"credibility":2,"name":"Steam Malware Alert: PirateFi Game Spreads Vidar Infostealer — TechRepublic","type":"research","url":"https://www.techrepublic.com/article/steam-piratefi-malware-vidar-infostealer/"},{"credibility":2,"name":"FBI Arrests Florida Man Accused of Distributing Malware Through Steam Games in $220,000 Crypto Theft — gHacks","type":"news_article","url":"https://www.ghacks.net/2026/07/20/fbi-arrests-florida-man-accused-of-distributing-malware-through-steam-games-in-220000-crypto-theft/"}]},{"content":"The FBI complaint alleges approximately 8,000 computers were infected and approximately 80 cryptocurrency wallets were compromised, resulting in at least $220,000 in confirmed cryptocurrency theft. One publicly reported victim was a Twitch streamer whose BlockBlasters infection activated during a live charity stream fundraising for cancer treatment, resulting in a reported loss of approximately $32,000. The campaign targeted users with demonstrated cryptocurrency holdings, using bot-driven social media outreach to maximize the likelihood of encountering high-value targets. All eight named game titles were removed from Steam, and Valve was contacted by investigators during the probe.","heading":"Victim Impact","severity":"critical","sources":[{"credibility":1,"name":"FBI Arrests 21-Year-Old for Allegedly Infecting 8,000 Computers — Yahoo News","type":"news_article","url":"https://www.yahoo.com/news/us/articles/fbi-arrests-21-old-allegedly-192208319.html"},{"credibility":2,"name":"FBI Probes Malware Hidden in Steam Games Targeting PC Players — CryptoNews","type":"news_article","url":"https://cryptonews.com.au/news/fbi-probes-malware-hidden-in-steam-games-targeting-pc-players-133262/"}]},{"content":"Investigators traced stolen Bitcoin from wallets identified in seized communications with Subject #1 to Bitrefill, a gift card platform accepting cryptocurrency. Over 150 gift cards — primarily Uber Eats — were purchased through one Bitrefill account. Google records linked the Bitrefill account's registered email to additional accounts through browser cookies, one of which was associated with a University of West Florida student with Wilkins' initials. A phone number tied to the account appeared as a recovery contact for an email containing Wilkins' full name, a Snapchat account previously displaying his name, and a T-Mobile account registered at his North Lauderdale family residence. Uber Eats delivery records subpoenaed by investigators showed over 500 food orders totaling more than $9,000 delivered exclusively to two University of West Florida campus addresses and Wilkins' family home, with a seasonal delivery pattern tracking the university academic calendar. A July 8, 2026 residential search warrant yielded three cryptocurrency wallet seed phrases, one belonging to a Monero wallet. The FBI's complaint notes that Monero is 'frequently used by criminals' due to its enhanced privacy properties. That Monero wallet showed cumulative transaction history of approximately 1,233 XMR, valued at roughly $382,000 at the time — a figure representing total in-and-out volume, not necessarily current holdings or confirmed victim funds.","heading":"Investigative Methods and Digital Trail","severity":"high","sources":[{"credibility":2,"name":"FBI used Google cookies, 500 food orders and a Monero seed phrase to identify Steam malware funder — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/fbi-used-google-cookies-500-food-orders-and-a-monero-seed-phrase-to-identify-steam-malware-funder/"},{"credibility":1,"name":"Feds accuse Broward man in video game malware conspiracy — Local10","type":"news_article","url":"https://www.local10.com/news/local/2026/07/15/feds-accuse-broward-man-in-video-game-malware-conspiracy-victims-lost-220k-in-crypto/"},{"credibility":2,"name":"FBI Charges Florida Man Over Malware Games That Stole $220K Crypto — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/18/fbi-charges-florida-man-over-malware-games-that-stole-220k-crypto/"}]},{"content":"Public court filings as of the time of reporting identify at least one unnamed co-conspirator, referred to as 'Subject #1,' described as the primary game developer who created Steam developer accounts and embedded the malware. A second unnamed individual is alleged to have assisted. No additional individuals had been publicly charged as of July 2026. The FBI's ongoing investigation, first publicly announced in March 2026 via a victim solicitation form (Steam_Malware@fbi.gov), was described by prosecutors as the first arrest to emerge from a broader probe. The existence of uncharged co-conspirators suggests the investigation may be ongoing.","heading":"Co-Conspirators and Broader Network","severity":"high","sources":[{"credibility":1,"name":"FBI seeks victims of Steam games used to spread malware — BleepingComputer","type":"regulatory","url":"https://www.bleepingcomputer.com/news/security/fbi-seeks-victims-of-steam-games-used-to-spread-malware/"},{"credibility":1,"name":"FBI Seeking Victim Information in Steam Malware Investigation — FBI.gov Form","type":"official","url":"https://forms.fbi.gov/victims/Steam_Malware"},{"credibility":2,"name":"South Florida man arrested after FBI links him to a $220k crypto theft scheme — WSVN 7News","type":"news_article","url":"https://wsvn.com/news/local/broward/south-florida-man-arrested-after-fbi-links-him-to-a-220k-crypto-theft-scheme/"}]},{"content":"The FBI's Seattle field office publicly announced an investigation into Steam-distributed malware in March 2026, soliciting victim reports via a dedicated intake form. That announcement named eight game titles — BlockBlasters, Chemia, Dashverse, DashFPS, Lampy, Lunara, PirateFi, and Tokenova — matching those identified in the Wilkins complaint. PirateFi was the earliest publicly identified title, removed by Valve in February 2025 following user reports of malware activity. Security researchers at the time attributed the PirateFi malware to the Vidar infostealer family and linked it to the broader EncryptHub threat cluster. The Wilkins arrest, announced July 17, 2026, was described by media as the first criminal charge resulting from the FBI's broader Steam malware investigation.","heading":"Prior FBI Steam Malware Investigation","severity":"high","sources":[{"credibility":1,"name":"FBI seeks victims of Steam games used to spread malware — BleepingComputer","type":"regulatory","url":"https://www.bleepingcomputer.com/news/security/fbi-seeks-victims-of-steam-games-used-to-spread-malware/"},{"credibility":1,"name":"hackers planted a Steam game with malware to steal gamers' passwords — TechCrunch","type":"news_article","url":"https://techcrunch.com/2025/02/18/hackers-planted-a-steam-game-with-malware-to-steal-gamers-passwords/"},{"credibility":2,"name":"PirateFi Malware Scandal Exposes Steam's Security Gaps — Enterprise Security Tech","type":"research","url":"https://www.enterprisesecuritytech.com/post/piratefi-malware-scandal-exposes-steam-s-security-gaps/"}]}],"sources_used":[{"credibility":1,"name":"FBI arrests man accused of using Steam games to drain victims' crypto wallets — TechCrunch","type":"news_article","url":"https://techcrunch.com/2026/07/17/fbi-arrests-man-accused-of-using-steam-games-to-drain-victims-crypto-wallets/"},{"credibility":1,"name":"FBI Arrests 21-Year-Old for Allegedly Infecting 8,000 Computers — Yahoo News","type":"news_article","url":"https://www.yahoo.com/news/us/articles/fbi-arrests-21-old-allegedly-192208319.html"},{"credibility":2,"name":"Feds Arrest Florida Man Over Video Game Malware That Stole $220K in Crypto — Decrypt","type":"news_article","url":"https://decrypt.co/373631/feds-arrest-florida-man-over-video-game-malware-that-stole-220k-in-crypto"},{"credibility":1,"name":"Feds accuse Broward man in video game malware conspiracy — Local10","type":"news_article","url":"https://www.local10.com/news/local/2026/07/15/feds-accuse-broward-man-in-video-game-malware-conspiracy-victims-lost-220k-in-crypto/"},{"credibility":2,"name":"FBI used Google cookies, 500 food orders and a Monero seed phrase to identify Steam malware funder — CryptoSlate","type":"news_article","url":"https://cryptoslate.com/fbi-used-google-cookies-500-food-orders-and-a-monero-seed-phrase-to-identify-steam-malware-funder/"},{"credibility":1,"name":"A Florida man is accused of hiding crypto-stealing malware in Steam games — Yahoo Finance","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/florida-man-accused-hiding-crypto-114500816.html"},{"credibility":1,"name":"PirateFi game on Steam caught installing password-stealing malware — BleepingComputer","type":"research","url":"https://www.bleepingcomputer.com/news/security/piratefi-game-on-steam-caught-installing-password-stealing-malware/"},{"credibility":1,"name":"FBI seeks victims of Steam games used to spread malware — BleepingComputer","type":"regulatory","url":"https://www.bleepingcomputer.com/news/security/fbi-seeks-victims-of-steam-games-used-to-spread-malware/"},{"credibility":1,"name":"FBI Seeking Victim Information in Steam Malware Investigation — FBI.gov","type":"official","url":"https://forms.fbi.gov/victims/Steam_Malware"},{"credibility":2,"name":"Steam Malware Alert: PirateFi Game Spreads Vidar Infostealer — TechRepublic","type":"research","url":"https://www.techrepublic.com/article/steam-piratefi-malware-vidar-infostealer/"},{"credibility":1,"name":"hackers planted a Steam game with malware to steal gamers' passwords — TechCrunch","type":"news_article","url":"https://techcrunch.com/2025/02/18/hackers-planted-a-steam-game-with-malware-to-steal-gamers-passwords/"},{"credibility":2,"name":"FBI Charges Florida Man Over Malware Games That Stole $220K Crypto — CryptoTimes","type":"news_article","url":"https://www.cryptotimes.io/2026/07/18/fbi-charges-florida-man-over-malware-games-that-stole-220k-crypto/"},{"credibility":2,"name":"South Florida man arrested after FBI links him to a $220k crypto theft scheme — WSVN 7News","type":"news_article","url":"https://wsvn.com/news/local/broward/south-florida-man-arrested-after-fbi-links-him-to-a-220k-crypto-theft-scheme/"},{"credibility":2,"name":"FBI Arrests Florida Man Accused of Distributing Malware Through Steam Games — gHacks","type":"news_article","url":"https://www.ghacks.net/2026/07/20/fbi-arrests-florida-man-accused-of-distributing-malware-through-steam-games-in-220000-crypto-theft/"}],"summary":"Zyaire Dontaevious Zamarion Wilkins, 21, of North Lauderdale, Florida, was arrested on July 14, 2026 and charged with conspiracy to obtain information by computer for private financial gain, a federal offense carrying up to 10 years imprisonment. Wilkins and at least one unnamed co-conspirator allegedly embedded information-stealing malware in eight fake video games distributed on Steam between May 2024 and February 2026, infecting approximately 8,000 computers and draining at least $220,000 from roughly 80 cryptocurrency wallets. Investigators linked Wilkins to the scheme via a chain of Bitcoin transactions, Bitrefill gift card purchases, Uber Eats delivery records, and Google account browser cookies.","timeline":[{"date":"2024-05-01","event":"Alleged malware campaign begins. Wilkins and co-conspirators start uploading fake games to Steam containing information-stealing malware.","source":"Federal criminal complaint via multiple media reports","source_url":"https://www.yahoo.com/news/us/articles/fbi-arrests-21-old-allegedly-192208319.html"},{"date":"2025-02-06","event":"PirateFi, one of the alleged malware-laced titles, is released on Steam by a publisher using the name Seaworth Interactive.","source":"BleepingComputer","source_url":"https://www.bleepingcomputer.com/news/security/piratefi-game-on-steam-caught-installing-password-stealing-malware/"},{"date":"2025-02-12","event":"Valve removes PirateFi from Steam after security researchers identify it as deploying Vidar infostealer malware. Steam advises affected users to reinstall Windows.","source":"BleepingComputer","source_url":"https://www.bleepingcomputer.com/news/security/piratefi-game-on-steam-caught-installing-password-stealing-malware/"},{"date":"2026-02-01","event":"Alleged malware campaign ends as the final infected games are removed from Steam.","source":"Federal criminal complaint via multiple media reports","source_url":"https://finance.yahoo.com/markets/crypto/articles/florida-man-accused-hiding-crypto-114500816.html"},{"date":"2026-03-01","event":"FBI Seattle field office publicly announces investigation into Steam-distributed malware, naming eight game titles and soliciting victim reports.","source":"BleepingComputer","source_url":"https://www.bleepingcomputer.com/news/security/fbi-seeks-victims-of-steam-games-used-to-spread-malware/"},{"date":"2026-07-08","event":"FBI executes a residential search warrant at Wilkins' North Lauderdale home, seizing digital devices and three cryptocurrency wallet seed phrases including one Monero wallet.","source":"Local10 / CryptoSlate","source_url":"https://cryptoslate.com/fbi-used-google-cookies-500-food-orders-and-a-monero-seed-phrase-to-identify-steam-malware-funder/"},{"date":"2026-07-14","event":"Zyaire Dontaevious Zamarion Wilkins arrested by FBI in North Lauderdale, Florida.","source":"Local10 / Decrypt","source_url":"https://decrypt.co/373631/feds-arrest-florida-man-over-video-game-malware-that-stole-220k-in-crypto"},{"date":"2026-07-16","event":"Wilkins makes his initial appearance in federal court in Fort Lauderdale. Transfer to Seattle federal court pending.","source":"Decrypt / Local10","source_url":"https://decrypt.co/373631/feds-arrest-florida-man-over-video-game-malware-that-stole-220k-in-crypto"},{"date":"2026-07-17","event":"FBI arrest and charges publicly reported. Case identified as the first criminal charge arising from the FBI's broader Steam malware investigation.","source":"TechCrunch","source_url":"https://techcrunch.com/2026/07/17/fbi-arrests-man-accused-of-using-steam-games-to-drain-victims-crypto-wallets/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 99236551-2d08-42fd-a259-9ba1f0b5b417
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.