If you play new or lesser-known Steam games—especially titles marketed with Web3 themes—this case is a warning sign. The FBI says a Florida man participated in a conspiracy that used malware-infested Steam games to steal cryptocurrency from thousands of users, with losses reaching at least $220,000. Here’s what authorities allege, which games were involved, and what to watch for next.
What changed: an alleged Steam malware conspiracy
A Florida man has been arrested after a federal criminal complaint alleged he took part in a conspiracy to infect Steam users with malware and steal from them. Authorities believe the suspect did not work alone, and they estimate the scheme resulted in at least $220,000 in cryptocurrency stolen from thousands of Steam players.
The complaint also highlights how persistent the platform-versus-threat cycle remains. While Valve is described as having strong, largely automated safeguards for detecting malicious code, malware still occasionally slips into the ecosystem—often through games or mods that later distribute harmful payloads to players.
According to the filing, the FBI identified 21-year-old Zyaire Dontaevious Zamarion Wilkins (North Lauderdale, Florida) on one count of conspiracy to obtain computer information for private financial gain. He was charged by federal criminal complaint, and as of July 25, 2026, he had not yet been indicted by a federal grand jury.
Who is affected: thousands of Steam users and multiple titles
The FBI’s 15-page complaint, filed July 15, 2026, alleges that Wilkins and multiple co-conspirators launched eight malware-embedded games between May 2024 and February 2026. Investigators estimate that roughly 8,000 devices were infected.
Once infected, the conspirators allegedly accessed around 80 cryptocurrency wallets and stole digital assets worth at least $220,000. The complaint names five of the compromised titles, while the remaining three are not identified in the filing because they are reportedly no longer available on Valve’s storefront.
The five named games are listed as follows: Dashverse, Lunara, PirateFi, BlockBlasters, and Lampy. The complaint also says Lampy received a malicious update in January 2026.
Authorities further allege the games were promoted through Discord and Telegram, alongside social platforms such as X and LinkedIn. The scheme reportedly included automated bots used to locate people with substantial cryptocurrency holdings and send targeted messages—an approach that aligns with the complaint’s claim that at least one title marketed Web3 features.
What comes next: removed listings and an ongoing FBI probe
The complaint alleges that once the infected games were installed, they exfiltrated passwords and other data needed to access victims’ cryptocurrency wallets. It also connects the case to a broader FBI investigation into Steam-distributed malware that was disclosed in March 2026.
In that earlier disclosure, federal investigators specifically identified Lunara, PirateFi, and Dashverse as titles under scrutiny. The new filing indicates investigators already had probable cause linking Wilkins to some of the malware identified in the prior investigation, though he was not named in federal court documents until the July filing.
One of the named titles, PirateFi, was reportedly removed from Steam in February 2025 after Valve warned affected users that the game’s developer had uploaded builds containing suspected malware.
The filing also alleges Wilkins operated under the name “Sibel.eth,” and that he helped finance, acquire, and market the malware rather than developing or uploading the infected games himself.
What players should know
- Treat new or obscure Steam releases—especially ones pushing Web3 themes—as higher risk until you verify community reputation.
- Be cautious with unsolicited promotion: the FBI alleges the scheme used Discord, Telegram, and social platforms to reach victims.
- The alleged impact wasn’t just “stealing accounts”—investigators say malware was used to take data needed to access cryptocurrency wallets.
- Even with platform safeguards, malware can appear via titles that later distribute harmful payloads, so keep expectations realistic.
| Game (as named in complaint) | Steam release timing mentioned in filing | Notable detail from the filing |
|---|---|---|
| Dashverse (AKA DashFPS) | Released May 2024 | Part of the alleged malware set |
| Lunara | Released November 2024 | Part of the alleged malware set |
| PirateFi | Released February 2025 | Removed from Steam in February 2025 after Valve warned users |
| BlockBlasters | Released August 2025 | Part of the alleged malware set |
| Lampy | Malicious update in January 2026 | Part of the alleged malware set |
Expert View
This case underlines a difficult reality for Steam players: even strong automated moderation can’t eliminate every threat, because attackers may rely on social engineering, targeted outreach, and late-stage malicious behavior. The most useful takeaway is not panic—it’s vigilance. If a game’s marketing or community signals feel unusually “hyped” or crypto-focused, do extra due diligence before installing, and stay alert to reports of suspicious builds.

