Skip to main content
AVOID.NET
Zyaire Wilkins (Steam Malware Crypto Theft Ring)reviewed 2026-09-07 · 32 claims checked

Fact-check findings

What an automated fact-checker found when it re-read Zyaire Wilkins (Steam Malware Crypto Theft Ring) against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed

2 claims

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #5[disputed][awaiting moderator]in section: Criminal Charges and Arrest
    Wilkins made his initial appearance in federal court in Fort Lauderdale, Florida on July 16, 2026, with transfer to Washington pending at the time of reporting.
    reviewerWilkins made his initial appearance in federal court in Fort Lauderdale, Florida on July 16, 2026Multiple sources place the Fort Lauderdale initial appearance on Wednesday, July 15, 2026, not Thursday July 16 as the page states. This appears to be an off-by-one date error, possibly caused by conflating the article's 'Updated' timestamp (July 16) with the day referenced in the text ('Wednesday').
    Proposed correction (not yet applied)
    Wilkins was scheduled to make his initial appearance in federal court in Fort Lauderdale, Florida on July 15, 2026, with transfer to Washington pending at the time of reporting.
  2. #30[disputed][awaiting moderator]in the timeline
    Wilkins makes his initial appearance in federal court in Fort Lauderdale. Transfer to Seattle federal court pending.
    reviewerTimeline: Wilkins makes initial appearance in federal court in Fort Lauderdale 2026-07-16, transfer to Seattle pendingSame underlying date error as the corresponding summary/section claim: the initial appearance was scheduled for Wednesday, July 15, 2026, not July 16. The stored date field ('2026-07-16') should be corrected to '2026-07-15'; note that the current stored value is the field target, quoted_text above records that.
    Proposed correction (not yet applied)
    2026-07-15

unverifiable

1 claim

No source the reviewer could reach confirms or contradicts the claim.

  1. #32[unverifiable][awaiting moderator]in section: Malware Technical Details
    https://www.ghacks.net/2026/07/20/fbi-arrests-florida-man-accused-of-distributing-malware-through-steam-games-in-220000-crypto-theft/
    reviewergHacks article is a live, accessible source supporting malware technical details and victim impact claimsCould not confirm or deny that this source supports the claims it is cited for; the underlying facts (Vidar/HijackLoader/Fickle Stealer/EncryptHub, bot-driven targeting) were independently corroborated via other means, so this is flagged as an access/link-integrity issue rather than a factual dispute. This source is also the only one in sources_used with no archive_url, which is a gap relative to the page's own archiving practice for every other citation.

partially supported

3 claims

The cited evidence supports part of the claim but not all of it.

  1. #4[partially supported][awaiting moderator]in section: Criminal Charges and Arrest
    Zyaire Dontaevious Zamarion Wilkins was arrested on July 14, 2026 and charged in the Western District of Washington (Seattle federal court) with one count of conspiracy to obtain information by computer for private financial gain, in violation of 18 U.S.C. § 1030.
    reviewerWilkins was charged in the Western District of Washington (Seattle federal court) with one count of conspiracy to obtain information by computer for private financial gain, in violation of 18 U.S.C. § 1030, carrying a maximum of 10 yearsThe Western District of Washington / Seattle federal court, the charge description and the 10-year maximum are all independently confirmed by multiple outlets. The specific statute citation '18 U.S.C. § 1030' was not found verbatim in any of the news sources reviewed (none quote a U.S. Code section number); it is plausible given the charge language but could not be independently verified against a primary document (complaint/DOJ press release), so this specific sub-element is unverifiable rather than confirmed.
  2. #17[partially supported][awaiting moderator]in section: Investigative Methods and Digital Trail
    Uber Eats delivery records subpoenaed by investigators showed over 500 food orders totaling more than $9,000 delivered exclusively to two University of West Florida campus addresses and Wilkins' family home, with a seasonal delivery pattern tracking the university academic calendar.
    reviewerUber Eats delivery records showed over 500 food orders totaling more than $9,000 delivered exclusively to two University of West Florida campus addresses and Wilkins' family home, with a seasonal delivery pattern tracking the academic calendarThe order count, dollar total, and three-location pattern are directly confirmed. The added characterization of a 'seasonal delivery pattern tracking the university academic calendar' is a plausible inference from campus-address delivery data but was not found verbatim or clearly substantiated in the source excerpt reviewed.
  3. #20[partially supported][awaiting moderator]in section: Co-Conspirators and Broader Network
    Public court filings as of the time of reporting identify at least one unnamed co-conspirator, referred to as 'Subject #1,' described as the primary game developer who created Steam developer accounts and embedded the malware. A second unnamed individual is alleged to have assisted.
    reviewerAt least one unnamed co-conspirator ('Subject #1') is the primary game developer who created Steam developer accounts and embedded the malware; a second unnamed individual is alleged to have assistedThe existence of 'Subject #1' as primary developer is well-supported. The more specific claim of exactly 'a second unnamed individual' assisting is a reasonable reading of plural 'co-conspirators'/'accomplices' language in sources, but no source reviewed distinctly names or numbers a second co-conspirator separate from Subject #1.

confirmed

26 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in the summary
    Zyaire Dontaevious Zamarion Wilkins, 21, of North Lauderdale, Florida, was arrested on July 14, 2026 and charged with conspiracy to obtain information by computer for private financial gain, a federal offense carrying up to 10 years imprisonment.
    reviewerWilkins, 21, of North Lauderdale, Florida, was arrested on July 14, 2026Day-of-week cross-checked against a calendar: July 14, 2026 is a Tuesday, matching both sources' 'arrested Tuesday' language and the charge/penalty description matches verbatim.
  2. #2[confirmed][no action needed]in the summary
    Wilkins and at least one unnamed co-conspirator allegedly embedded information-stealing malware in eight fake video games distributed on Steam between May 2024 and February 2026, infecting approximately 8,000 computers and draining at least $220,000 from roughly 80 cryptocurrency wallets.
    reviewerWilkins and at least one unnamed co-conspirator embedded malware in eight fake video games on Steam between May 2024 and February 2026, infecting approximately 8,000 computers and draining at least $220,000 from roughly 80 walletsFigures for computers infected, wallets compromised, dollar amount, and campaign date range are consistently corroborated across multiple independent outlets.
  3. #3[confirmed][no action needed]in the summary
    Investigators linked Wilkins to the scheme via a chain of Bitcoin transactions, Bitrefill gift card purchases, Uber Eats delivery records, and Google account browser cookies.
    reviewerInvestigators linked Wilkins to the scheme via Bitcoin transactions, Bitrefill gift card purchases, Uber Eats delivery records, and Google account browser cookiesMatches CryptoSlate's detailed reconstruction of the investigative trail.
  4. #6[confirmed][no action needed]in section: Criminal Charges and Arrest
    Investigators executed a search warrant at his North Lauderdale residence on July 8, 2026, seizing digital devices and cryptocurrency wallet seed phrases.
    reviewerInvestigators executed a search warrant at Wilkins' North Lauderdale residence on July 8, 2026, seizing digital devices and cryptocurrency wallet seed phrasesDate, location, and items seized (devices, seed phrases) match reporting.
  5. #7[confirmed][no action needed]in section: Criminal Charges and Arrest
    At the time of arrest, Wilkins was a student at the University of West Florida.
    reviewerAt the time of arrest, Wilkins was a student at the University of West FloridaCorroborated by CryptoSlate's investigative-trail reporting and independently by other outlets describing Wilkins as a UWF student.
  6. #8[confirmed][no action needed]in section: Criminal Charges and Arrest
    The FBI's Seattle field office led the investigation.
    reviewerThe FBI's Seattle field office led the investigationAlso consistent with the March 2026 FBI victim solicitation notice being issued by the FBI Seattle Division.
  7. #9[confirmed][no action needed]in section: Alleged Scheme: Malware-Laced Steam Games
    The games — BlockBlasters, Chemia, Dashverse (also marketed as DashFPS), Lampy, Lunara, PirateFi, Tokenova, and one additional title — were submitted to Steam with clean initial builds, then updated post-launch to deliver malicious payloads.
    reviewerEight fake games (BlockBlasters, Chemia, Dashverse/DashFPS, Lampy, Lunara, PirateFi, Tokenova, and one additional title) were uploaded to Steam with clean initial builds, later updated to deliver malicious payloadsThe page's hedge ('and one additional title') appropriately reflects the same seven/eight ambiguity present in the FBI's own public notice.
  8. #10[confirmed][no action needed]in section: Alleged Scheme: Malware-Laced Steam Games
    The complaint alleges Wilkins paid approximately $10,000 to fund a remote access trojan and coordinate the scheme, communicating with Subject #1 via the Signal encrypted messaging application under the handle 'Sibel.eth'.
    reviewerWilkins allegedly paid approximately $10,000 to fund a remote access trojan and coordinate the scheme via Signal under the handle 'Sibel.eth'WSVN directly corroborates the Signal/'Sibel.eth' pairing; the $10,000 RAT figure is independently confirmed by Yahoo.
  9. #11[confirmed][no action needed]in section: Malware Technical Details
    Security researchers identified multiple malware strains attributed to the campaign, including Vidar (an information stealer), HijackLoader, and a custom tool called Fickle Stealer. The threat actor cluster associated with this campaign has been tracked by researchers under the label 'EncryptHub.'
    reviewerMalware strains Vidar, HijackLoader, and Fickle Stealer are attributed to the campaign, tracked under the 'EncryptHub' threat cluster labelVidar, HijackLoader, Fickle Stealer, and the EncryptHub cluster label are all independently corroborated via search, though I could not directly WebFetch the cited gHacks article (see link-rot note below) to confirm it is the specific source for this exact combination of strain names.
  10. #12[confirmed][no action needed]in section: Malware Technical Details
    PirateFi, one of the named titles released in February 2025, was identified early by security researchers as deploying Vidar infostealer and was removed from Steam by Valve within days of its release.
    reviewerPirateFi, released in February 2025, was identified early as deploying Vidar infostealer and was removed from Steam by Valve within daysExact dates independently confirmed and match the page's timeline entries for the same events.
  11. #13[confirmed][no action needed]in section: Malware Technical Details
    The malware was bundled in installation packages using InnoSetup and disguised as legitimate game executables.
    reviewerThe malware was bundled using InnoSetup and disguised as legitimate game executablesDirectly confirmed for the PirateFi instance; page presents it as a pattern across the campaign, which is a reasonable generalization given the shared threat-cluster attribution.
  12. #14[confirmed][no action needed]in section: Malware Technical Details
    The campaign also used bots on Discord, Telegram, X (formerly Twitter), and LinkedIn to identify users with large cryptocurrency holdings and deliver targeted invitations to install the games.
    reviewerThe campaign used bots on Discord, Telegram, X, and LinkedIn to identify users with large cryptocurrency holdings and deliver targeted invitationsConfirmed via independent corroboration even though the directly cited gHacks URL could not be fetched (see link-rot finding).
  13. #15[confirmed][no action needed]in section: Victim Impact
    One publicly reported victim was a Twitch streamer whose BlockBlasters infection activated during a live charity stream fundraising for cancer treatment, resulting in a reported loss of approximately $32,000.
    reviewerA Twitch streamer's BlockBlasters infection activated during a live charity stream for cancer treatment, resulting in a loss of approximately $32,000Amount and circumstances independently confirmed by Decrypt; page's 'approximately $32,000' is a fair characterization of Decrypt's 'more than $32,000.'
  14. #16[confirmed][no action needed]in section: Investigative Methods and Digital Trail
    Investigators traced stolen Bitcoin from wallets identified in seized communications with Subject #1 to Bitrefill, a gift card platform accepting cryptocurrency. Over 150 gift cards — primarily Uber Eats — were purchased through one Bitrefill account.
    reviewerOver 150 gift cards, primarily Uber Eats, were purchased through one Bitrefill account after investigators traced stolen Bitcoin thereDirectly confirmed.
  15. #18[confirmed][no action needed]in section: Investigative Methods and Digital Trail
    That Monero wallet showed cumulative transaction history of approximately 1,233 XMR, valued at roughly $382,000 at the time — a figure representing total in-and-out volume, not necessarily current holdings or confirmed victim funds.
    reviewerA July 8, 2026 search warrant yielded three wallet seed phrases, one for a Monero wallet with cumulative transaction history of approximately 1,233 XMR (~$382,000), representing total volume not confirmed victim fundsFigure and framing confirmed; the page's hedge about the figure not representing confirmed victim funds is a responsible, source-consistent clarification rather than an unsupported claim.
  16. #19[confirmed][no action needed]in section: Investigative Methods and Digital Trail
    A phone number tied to the account appeared as a recovery contact for an email containing Wilkins' full name, a Snapchat account previously displaying his name, and a T-Mobile account registered at his North Lauderdale family residence.
    reviewerA phone number tied to the Bitrefill account appeared as a recovery contact for an email with Wilkins' full name, a Snapchat account previously displaying his name, and a T-Mobile account registered at his family residenceDirectly confirmed, near-verbatim.
  17. #21[confirmed][no action needed]in section: Co-Conspirators and Broader Network
    The FBI's ongoing investigation, first publicly announced in March 2026 via a victim solicitation form (Steam_Malware@fbi.gov), was described by prosecutors as the first arrest to emerge from a broader probe.
    reviewerThe FBI's investigation was first publicly announced in March 2026 via a victim solicitation form (Steam_Malware@fbi.gov), described by prosecutors as the first arrest from a broader probeAll elements independently confirmed.
  18. #22[confirmed][no action needed]in section: Prior FBI Steam Malware Investigation
    PirateFi was the earliest publicly identified title, removed by Valve in February 2025 following user reports of malware activity. Security researchers at the time attributed the PirateFi malware to the Vidar infostealer family and linked it to the broader EncryptHub threat cluster.
    reviewerPirateFi was the earliest publicly identified title, removed by Valve in February 2025 following user reports; researchers linked it to Vidar and the EncryptHub clusterConsistent with earlier verification of the PirateFi timeline and EncryptHub attribution.
  19. #23[confirmed][no action needed]in the timeline
    Alleged malware campaign begins. Wilkins and co-conspirators start uploading fake games to Steam containing information-stealing malware.
    reviewerTimeline: alleged malware campaign begins in 2024-05Month-level date confirmed.
  20. #24[confirmed][no action needed]in the timeline
    PirateFi, one of the alleged malware-laced titles, is released on Steam by a publisher using the name Seaworth Interactive.
    reviewerTimeline: PirateFi released on Steam 2025-02-06Exact date and publisher name confirmed.
  21. #25[confirmed][no action needed]in the timeline
    Valve removes PirateFi from Steam after security researchers identify it as deploying Vidar infostealer malware. Steam advises affected users to reinstall Windows.
    reviewerTimeline: Valve removes PirateFi 2025-02-12Exact date and details confirmed.
  22. #26[confirmed][no action needed]in the timeline
    Alleged malware campaign ends as the final infected games are removed from Steam.
    reviewerTimeline: alleged campaign ends 2026-02 as final infected games removed from SteamNote: the FBI's own March 2026 victim-solicitation notice (BleepingComputer) described the campaign window as 'May 2024 and January 2026,' one month earlier than the February 2026 end date used here and in the criminal complaint reporting. This is not a contradiction of the page (which correctly follows the later complaint-based reporting) but is noted for completeness.
  23. #27[confirmed][no action needed]in the timeline
    FBI Seattle field office publicly announces investigation into Steam-distributed malware, naming eight game titles and soliciting victim reports.
    reviewerTimeline: FBI Seattle publicly announces investigation 2026-03, naming eight titles and soliciting victimsMonth-level date confirmed.
  24. #28[confirmed][no action needed]in the timeline
    FBI executes a residential search warrant at Wilkins' North Lauderdale home, seizing digital devices and three cryptocurrency wallet seed phrases including one Monero wallet.
    reviewerTimeline: FBI executes residential search warrant 2026-07-08Exact date, item count (three seed phrases including a Monero wallet), independently confirmed.
  25. #29[confirmed][no action needed]in the timeline
    Zyaire Dontaevious Zamarion Wilkins arrested by FBI in North Lauderdale, Florida.
    reviewerTimeline: Wilkins arrested by FBI 2026-07-14Confirmed via day-of-week cross-check as above.
  26. #31[confirmed][no action needed]in the timeline
    FBI arrest and charges publicly reported. Case identified as the first criminal charge arising from the FBI's broader Steam malware investigation.
    reviewerTimeline: FBI arrest and charges publicly reported 2026-07-17, first criminal charge from broader Steam malware investigationPublication date and 'first charge' framing confirmed.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.