FBI Tracked a Steam Malware Developer Through His Uber Eats Orders

The FBI didn’t catch a Steam malware developer through sophisticated digital forensics or encrypted traffic analysis. They found him because he ordered Uber Eats to his college dorm using stolen cryptocurrency.

Federal investigators arrested Zyaire Dontaevious Zamarion Wilkins, who allegedly conspired with accomplices to publish multiple games on Steam between May 2024 and February 2026 that contained hidden malware. According to a 15-page criminal complaint, the games — including BlockBlasters, Dashverse, Lunara, PirateFi, Chemia, Lampy, and Tokenova — infected roughly 8,000 devices and siphoned more than $220,000 in cryptocurrency.

When players launched any of these titles, the embedded trojan began collecting personal information, login credentials, and account data. It then searched for cryptocurrency wallet access points to drain their digital assets.

The group didn’t rely on random chance. They promoted their malicious games through Discord, X (formerly Twitter), and LinkedIn, and deployed automated bots to identify targets with substantial crypto holdings. The bots would then send direct messages urging those users to download the games, turning a generic scam into a targeted operation.

What unraveled the scheme was a simple paper trail. After stealing cryptocurrency, Wilkins moved portions of the proceeds to Bitrefill, a gift card platform, where he purchased over 150 digital gift cards. Most of them went to Uber Eats.

The FBI subpoenaed Uber for delivery records tied to those gift card accounts. The delivery addresses pointed to two locations: the University of West Florida, where Wilkins was enrolled, and his residence in North Lauderdale, Florida. That was enough.

Wilkins has been charged under the Computer Fraud and Abuse Act. If convicted, he faces up to 10 years in federal prison.