Security Privacy Coins

How the FBI Caught a Malware Pusher Using Uber Eats Orders and a Monero Seed Phrase

2026-07-25

A 21-year-old from Florida got arrested this week for peddling malware-infected games on Steam. Zyaire Dontaevious Zamarion Wilkins and unnamed accomplices allegedly embedded info-stealers into eight different titles between May 2024 and February 2026, nicking over $220,000 from eighty wallets. The infected games hit 8,000 PCs. Not exactly subtle work.

What makes this case interesting isn't the malware itself—it's how the feds pinned him down. Bitcoin trails lead everywhere and nowhere. But Wilkins made a fatal mistake: he converted his crypto proceeds into Uber Eats gift cards. Once agents subpoenaed Uber's records, they matched over 500 food orders worth $9,000-plus to accounts linked to his family home and the University of West Florida. The ordering pattern alone was damning. Deliveries clustered around campus during the semester; off-campus orders spiked during breaks. He'd essentially mapped his own schedule in chicken wings and pad thai.

From there the FBI pivoted to his email address on the Bitrefill gift card account. Google records opened up an entire constellation of linked profiles. The malware group had promoted their infected games across Discord, Telegram, X, and LinkedIn, using bots to hunt down targets with fat wallets and pitch them downloads.

The games themselves have names like BlockBlasters, Dashverse, Lunara, PirateFi, Chemia, Lampy, DashFPS, and Tokenova. All yanked from Steam by early 2026. The infostealer code ran clean—no lag, no crashes, just silently harvesting passwords, session tokens, and crypto wallet data. BlockBlasters gained notoriety in 2025 when a streamer watched his holdings drain live on camera. Brutal marketing, that.

When agents finally raided the North Lauderdale house a week before the arrest, they found three seed phrases. One of them unlocked a Monero wallet. His total crypto transaction history showed $382,000 moving in and out, though investigators only traced $220,000 back to victims.

Here's where it gets clever. Monero is built for anonymity. Source and destination addresses stay hidden. Privacy coin advocates tout it as essential; law enforcement calls it a criminal favourite. Yet Wilkins's use of Monero didn't save him. The FBI didn't need to crack the blockchain. They simply seized the physical seed phrase and walked away with the keys. No on-chain forensics required.

The irony is thick. The feds didn't beat Monero's privacy tech. They bypassed it entirely by recovering hardware evidence. Traditional data—credit card receipts, delivery logs, geolocation patterns—trumped cutting-edge privacy coins. A 21-year-old thought he'd covered his tracks with cryptography. He got caught because he was hungry and used his real name on a food app.

Wilkins faces up to ten years if convicted. He's presumed innocent for now. His court appearance in Fort Lauderdale is scheduled for July 15.


Source & further reading:

Sources