Steam is one of the most trusted video game platforms in the world, but that made it the perfect hiding place for a malware operation that lasted almost two years. The FBI arrested a 21-year-old man in Florida accused of financing and promoting eight infected video games that managed to break into thousands of computers, steal personal data and steal nearly $220,000 in cryptocurrency.
How they managed to sneak malware into Steam without anyone suspecting
The most disturbing thing about this case is how simple the deception was. Zyaire Dontaevious Zamarion Wilkins and his accomplices did not exploit a technical flaw in Steam, but something much more basic, the trust that players place in the Valve store. They published titles like BlockBlasters, Chemia, Dashverse (also known as DashFPS), Lampy, Lunara, PirateFi and Tokenova, eight games in total that at first glance seemed like legitimate, functional and even entertaining indie projects.
A user would download any of those titles, play a couple of games, leave a positive review and never imagine what was happening in the background. The malware would activate silently and begin collecting saved passwords, cookies, and other sensitive information stored on the computer. With that data in hand, the attackers then accessed the victims' cryptocurrency wallets.
According to the federal complaint, the operation was active between May 2024 and February 2026, infected around 8,000 computers and allowed nearly 80 digital wallets to be emptied for a total of $220,000. They even used bots to track which potential victims had large volumes of crypto stored away, so this wasn't a blind attack, but rather a fairly calculated operation.
Valve removed the eight games from the store as soon as the problem was detected, but the damage had already been done for those who had installed them months or even years before. Wilkins faces federal charges of conspiracy to obtain computer information for profit and is currently awaiting extradition to Washington to stand trial.
What to do if you installed any of these 8 Steam games
If your Steam library includes or included BlockBlasters, Chemia, Dashverse, DashFPS, Lampy, Lunara, PirateFi or Tokenova, it is best to assume that your computer may have been compromised, especially if you downloaded it between May 2024 and early 2026. It is not enough to simply uninstall the game, because the malware could have already created persistent access to your system.
These are the actions that cybersecurity experts recommend taking immediately.
This case leaves an uncomfortable lesson for the entire gaming community, which is that not even a platform as established as Steam guarantees that everything published is safe. Before installing a new game, especially if it is from a small or unknown studio, it is worth checking recent reviews, being wary of requests to execute commands in PowerShell or CMD, and always keeping your system and antivirus up to date. The next threat could be disguised as your next favorite game.