How the FBI Caught a Malware Pusher Using Uber Eats Orders and a Monero Seed Phrase
2026-07-25A 21-year-old from Florida got arrested this week for peddling malware-infected games on Steam. Zyaire Dontaevious Zamarion Wilkins and unnamed accomplices allegedly embedded info-stealers into eight different titles between May 2024 and February 2026, nicking over $220,000 from eighty wallets. The infected games hit 8,000 PCs. Not exactly subtle work.
What makes this case interesting isn't the malware itself—it's how the feds pinned him down. Bitcoin trails lead everywhere and nowhere. But Wilkins made a fatal mistake: he converted his crypto proceeds into Uber Eats gift cards. Once agents subpoenaed Uber's records, they matched over 500 food orders worth $9,000-plus to accounts linked to his family home and the University of West Florida. The ordering pattern alone was damning. Deliveries clustered around campus during the semester; off-campus orders spiked during breaks. He'd essentially mapped his own schedule in chicken wings and pad thai.
From there the FBI pivoted to his email address on the Bitrefill gift card account. Google records opened up an entire constellation of linked profiles. The malware group had promoted their infected games across Discord, Telegram, X, and LinkedIn, using bots to hunt down targets with fat wallets and pitch them downloads.
The games themselves have names like BlockBlasters, Dashverse, Lunara, PirateFi, Chemia, Lampy, DashFPS, and Tokenova. All yanked from Steam by early 2026. The infostealer code ran clean—no lag, no crashes, just silently harvesting passwords, session tokens, and crypto wallet data. BlockBlasters gained notoriety in 2025 when a streamer watched his holdings drain live on camera. Brutal marketing, that.
When agents finally raided the North Lauderdale house a week before the arrest, they found three seed phrases. One of them unlocked a Monero wallet. His total crypto transaction history showed $382,000 moving in and out, though investigators only traced $220,000 back to victims.
Here's where it gets clever. Monero is built for anonymity. Source and destination addresses stay hidden. Privacy coin advocates tout it as essential; law enforcement calls it a criminal favourite. Yet Wilkins's use of Monero didn't save him. The FBI didn't need to crack the blockchain. They simply seized the physical seed phrase and walked away with the keys. No on-chain forensics required.
The irony is thick. The feds didn't beat Monero's privacy tech. They bypassed it entirely by recovering hardware evidence. Traditional data—credit card receipts, delivery logs, geolocation patterns—trumped cutting-edge privacy coins. A 21-year-old thought he'd covered his tracks with cryptography. He got caught because he was hungry and used his real name on a food app.
Wilkins faces up to ten years if convicted. He's presumed innocent for now. His court appearance in Fort Lauderdale is scheduled for July 15.
Source & further reading:
- FBI used Google cookies, 500 food orders and a Monero seed phrase to identify Steam malware funder — CryptoSlate
- North Korea arrests hackers accused of laundering stolen funds from country's bank via crypto — CoinDesk
- Democratizing weather derivatives through tokenization could be crypto's most important real-world use case — CoinDesk
- Robinhood Chain's real-world assets jump fivefold as tokenized stocks start trading in bigger size — CoinDesk
- Senate Dems should accept the victory they won on Trump's crypto limits: White House — CoinDesk
- Steam Malware Scheme Drained $220K in Crypto, FBI Says — DailyCoin
- FBI arrests man accused of using Steam games to drain victims' crypto wallets — TechCrunch
- Florida man arrested after allegedly stealing $220,000 in crypto using malware hidden in Steam Games — 8,000 devices infected — Tom's Hardware
- Feds Arrest Florida Man Over Video Game Malware That Stole $220K in Crypto — Decrypt
- They Downloaded Free Games. Feds Say Malware Opened 80 Crypto Wallets and Stole $220K — Yahoo News
- FBI Arrests 21-Year-Old for Allegedly Infecting 8,000 Computers by Hiding Crypto-Stealing Malware Inside Fake Steam Games — Yahoo News
- Florida Man Charged in Video Game Malware Scheme That Stole Crypto — Coin Edition
- FBI Arrests Florida Man Accused of Distributing Malware Through Steam Games in $220,000 Crypto Theft — gHacks Tech News
- Feds accuse Broward man in video game malware conspiracy; victims lost $220K in crypto — WPLG Local 10
- Who Is Zyaire Wilkins and the Steam Game Wallet Drains — Phemex
Sources
- FBI used Google cookies, 500 food orders and a Monero seed phrase to identify Steam malware funder
- North Korea arrests hackers accused of laundering stolen funds from country's bank via crypto
- Democratizing weather derivatives through tokenization could be crypto's most important real-world use case
- Robinhood Chain's real-world assets jump fivefold as tokenized stocks start trading in bigger size
- Senate Dems should accept the victory they won on Trump's crypto limits: White House
- Steam Malware Scheme Drained $220K in Crypto, FBI Says
- FBI arrests man accused of using Steam games to drain victims' crypto wallets
- Florida man arrested after allegedly stealing $220,000 in crypto using malware hidden in Steam Games — 8,000 devices infected
- Feds Arrest Florida Man Over Video Game Malware That Stole $220K in Crypto
- They Downloaded Free Games. Feds Say Malware Opened 80 Crypto Wallets and Stole $220K
- FBI Arrests 21-Year-Old for Allegedly Infecting 8,000 Computers by Hiding Crypto-Stealing Malware Inside Fake Steam Games
- Florida Man Charged in Video Game Malware Scheme That Stole Crypto
- FBI Arrests Florida Man Accused of Distributing Malware Through Steam Games in $220,000 Crypto Theft
- Feds accuse Broward man in video game malware conspiracy; victims lost $220K in crypto
- Who Is Zyaire Wilkins and the Steam Game Wallet Drains