Security BTC Privacy Coins

How a Student's Uber Eats Habit Sank a $220K Malware Operation

2026-07-25

A 21-year-old Florida student just learned an expensive lesson: you can't outrun the law when you're ordering food delivery every other day. The FBI arrested Zyaire Wilkins this week for masterminding a malware scheme that infected 8,000 Steam users and stole over $220,000 from 80 cryptocurrency wallets. He's looking at up to a decade in prison on charges of conspiracy to obtain information by computer for private financial gain.

Between 2024 and 2026, Wilkins and his co-conspirators cooked up eight fake games—BlockBlasters, PirateFi, and others—that looked legit but harboured hidden malware designed to steal passwords and crypto keys. They pushed these on Discord, Telegram, and LinkedIn, using bots to target users with substantial holdings. BlockBlasters alone allegedly netted $150,000, including funds a streamer was raising for cancer treatment. Remarkably brutal.

The investigation is where this gets interesting. Wilkins covered his tracks with Bitcoin and privacy coins, which should have made him invisible. Instead, he did something stupid: he converted stolen Bitcoin into gift cards on Bitrefill to buy Uber Eats. Hundreds of Uber Eats. Over 500 deliveries, in fact, concentrated across three specific locations. Some went to his university address during term, others to his family home in North Lauderdale during breaks. The FBI subpoenaed both Bitrefill and Uber, mapped the pattern, and suddenly had him cold.

The feds then layered in Google cookies, T-Mobile records, and browser history to build an airtight chain. Email addresses matching Wilkins' initials showed up linked to his university account. Phone records connected the dots. A 15-page complaint walks through the entire forensic trail—Bitcoin to Bitrefill to Uber to home address, each step a nail in the coffin.

When agents searched the North Lauderdale house, they found several devices and three cryptocurrency wallet seed phrases. One was a Monero wallet. Wilkins' transaction history showed $382,000 in total cryptocurrency movement—though that's cumulative activity, not necessarily all stolen funds. He'd tried to shift money into privacy coins as an OPSEC measure, which shows some awareness. Too little, too late.

Monero, for the uninitiated, is the privacy coin of choice for people who want their transactions invisible. An FBI agent noted in the complaint that it's "frequently used by criminals" because tracing it is nearly impossible. The fact Wilkins had a Monero wallet suggests he understood the vulnerability of Bitcoin. He just forgot that every step before conversion—every Bitcoin transaction, every Bitrefill purchase, every food order—leaves a paper trail in corporate databases.

This is the first arrest from the FBI's public Steam malware investigation, launched in March 2026. The case is being prosecuted in Washington state, conveniently near Valve's headquarters. It's a masterclass in how modern financial crime gets exposed: not through some breakthrough in crypto forensics, but through the mundane reality that criminals still need to eat. They still need to order that food delivered to their actual address. And when they do, corporate systems record every transaction, accessible to law enforcement via subpoena.

The lesson cuts both ways. Criminals who think privacy coins are a silver bullet aren't thinking about the conventional financial paper trail they leave behind. Law enforcement, meanwhile, has learned that sometimes the oldest investigative techniques work best.


Source & further reading:

Sources