Florida Man Charged After Malware in 8 Games Drains 80 Crypto Wallets

BTC0.45%
ETH1.06%
Key Takeaways
  • Zyaire Dontaevious Zamarion Wilkins faces federal conspiracy charges for funding malware operations distributed through eight video games from May 2024 through February 2026.
  • Malware embedded in eight games compromised approximately 8,000 devices and drained at least 80 cryptocurrency wallets of $220,000 in digital assets.
  • Search warrant execution at Wilkins' residence recovered electronic devices and three cryptocurrency wallet seed phrases, with transaction records showing $382,000 in cryptocurrency transfers.

A 21-year-old Florida man faces a federal conspiracy charge after malware concealed in downloadable video games allegedly compromised approximately 8,000 devices and enabled unauthorized access to about 80 cryptocurrency wallets, resulting in at least $220,000 in stolen digital assets. Federal investigators accuse Zyaire Dontaevious Zamarion Wilkins of North Lauderdale, Florida, of providing financial support for a malware operation that ran from May 2024 through February 2026, according to a 15-page criminal complaint reported by Local 10 News on July 15. The alleged scheme embedded credential-harvesting software inside eight games distributed through what court documents suggest was the Steam platform, illustrating how cybercriminals exploit legitimate gaming marketplaces to distribute malicious software at scale.

Malware-Infected Games Harvested Wallet Credentials Across 8,000 Devices

Court documents describe software embedded inside eight games that allegedly collected passwords, wallet credentials, browser data, and other sensitive information after victims installed the titles. The FBI is gathering information from potential victims who downloaded BlockBlasters, Chemia, Dashverse/DashFPS, Lampy, Lunara, PirateFi, Tokenova, or other games associated with the case. Security researchers previously identified wallet-stealing malware inside PirateFi before Steam removed the title. After infecting a device, the malware allegedly searched for login credentials, cryptocurrency wallet information, and authentication data. Investigators maintain that members of the conspiracy examined the stolen files and identified wallets they could access and drain.

Automated Bots Targeted Cryptocurrency Holders on Social Platforms

Discord, Telegram, X, and LinkedIn allegedly became marketing channels for the infected games, while automated bots reportedly searched online communities for people with significant cryptocurrency holdings. The targeted account holders then received customized messages encouraging them to install the software. Encrypted Signal conversations allegedly showed Wilkins using the handle "Sibel.eth" while communicating with the suspected primary malware developer. According to the complaint, those exchanges included discussions about purchasing a $10,000 remote access trojan and conducting campaigns designed to empty victims' cryptocurrency wallets.

Bitcoin Transactions and Gift Card Purchases Led Investigators to Florida Defendant

Bitcoin transactions linked to the alleged operation eventually led investigators to Bitrefill, where more than 150 digital gift cards were allegedly purchased using cryptocurrency tied to the scheme. Most were redeemed for Uber Eats orders, and subpoenaed records connected deliveries to Wilkins' university addresses and his South Florida residence. Agents executing a search warrant recovered electronic devices and three cryptocurrency wallet seed phrases, including one allegedly associated with a Monero wallet. Transaction records reviewed by authorities allegedly showed that Wilkins sent or received approximately $382,000 in cryptocurrency. He now faces one count of conspiracy to obtain computer information for private financial gain, an offense carrying a maximum sentence of 10 years in prison.

FAQ

What did the malware hidden in video games do to cryptocurrency users? Malware embedded in eight downloadable games allegedly collected passwords, wallet credentials, browser data, and other sensitive information from approximately 8,000 infected devices. Investigators maintain that attackers used the stolen data to access about 80 cryptocurrency wallets and remove at least $220,000 in digital assets between May 2024 and February 2026.

How did investigators connect the malware scheme to Zyaire Dontaevious Zamarion Wilkins? Bitcoin transactions linked to the alleged operation led investigators to Bitrefill, where more than 150 digital gift cards were purchased using cryptocurrency tied to the scheme. Subpoenaed records connected Uber Eats deliveries to Wilkins' university addresses and his South Florida residence. A search warrant execution recovered electronic devices and three cryptocurrency wallet seed phrases from his location, and transaction records allegedly showed Wilkins sent or received approximately $382,000 in cryptocurrency.

Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments