Malware in Video Games Compromises 8,000 Devices, Steals $382,000 in Cryptocurrency
Malware hidden in eight downloadable games allegedly compromised approximately 8,000 devices and enabled attackers to access around 80 cryptocurrency wallets. The operation, which ran from May 2024 through February 2026, is believed to have been supported by Zyaire Dontaevious Zamarion Wilkins, a 21-year-old from North Lauderdale, Florida. According to court documents, the malware collected sensitive information such as passwords, wallet credentials, and browser data after victims installed the infected games.
The games in question are BlockBlasters, Chemia, Dashverse/DashFPS, Lampy, Lunara, PirateFi, Tokenova, and possibly others associated with the case. Investigators suspect that Steam was used to distribute the malware, but did not explicitly name the platform. Security researchers had previously identified wallet-stealing malware in PirateFi before it was removed from Steam.
Automated bots searched online communities for individuals with significant cryptocurrency holdings, then sent them tailored messages encouraging them to install the infected games. Once a device was compromised, the malware searched for login credentials and cryptocurrency information. Investigators claim that members of the conspiracy examined the stolen files and identified wallets they could access and drain.
Bitcoin transactions linked to the alleged operation led investigators to Bitrefill, where over 150 digital gift cards were purchased using cryptocurrency tied to the scheme. Most of these gift cards were redeemed for Uber Eats orders, with records connecting deliveries to Wilkins' university addresses and his South Florida residence.