Crypto malware in 8 Steam games steals tokens after leaving trail to Uber Eats deliveries
The FBI is looking for potential victims who downloaded eight games named in its Steam malware investigation, a case that reveals crypto custody can fail earlier than a pockets ever opens.
In a separate federal grievance reported by Local 10, brokers allege an eight-game marketing campaign contaminated about 8,000 units, gained unauthorized entry to roughly 80 crypto wallets, and stole a minimum of $220,000.
Local 10 reported that brokers arrested 21-year-old Zyaire Dontaevious Zamarion Wilkins on July 14 and accused him of financing and procuring malware and serving to market the contaminated games. The grievance describes the venue solely as a “in style digital distribution software program firm.” Wilkins is presumed harmless until convicted.
The FBI notice lists BlockBlasters, Chemia, Dashverse, DashFPS, Lampy, Lunara, PirateFi and Tokenova, and locations the suspected Steam exercise between May 2024 and January 2026. Local 10 reported that the grievance dates its broader alleged marketing campaign by February 2026.

Custody begins at software program distribution
According to the grievance, the alleged group promoted the games on Discord, Telegram, X, and LinkedIn. Bots recognized individuals with giant crypto holdings and despatched focused messages encouraging them to obtain. Once put in, the malware allegedly captured non-public knowledge and credentials; the group additionally mentioned tricking victims into authorizing transactions that emptied wallets.
One FBI-listed title reveals how a trusted obtain might expose pockets knowledge. A February 2025 cyber advisory stated PirateFi was out there on Steam from Feb. 6 to Feb. 12, 2025, and that it contained the Vidar infostealer, which might steal credentials, session cookies, and crypto wallet data.
The assault chain creates two management layers. Valve’s onboarding documentation says preliminary builds are checked for dangerous habits, however its review documentation says authorized games can later be up to date with out one other evaluation. Those paperwork don’t set up how the games in this case allegedly bypassed controls, however they present that scrutiny should cowl each preliminary and up to date builds.
For pockets customers, an official market can’t be the one belief boundary. Keeping pockets secrets and techniques and authenticated periods away from gaming endpoints limits what an infostealer can attain, whereas intentionally reviewing transaction prompts addresses the separate threat of approving a malicious switch. Neither management replaces market screening.
The alleged cost trail exposes the reverse aspect of the assault. Local 10 reported that investigators adopted Bitcoin funds from a scheme-linked pockets to Bitrefill, an internet service used to purchase greater than 150 digital present playing cards, principally for Uber Eats. A subpoena to Uber then allegedly linked these playing cards to an account with deliveries to addresses related to Wilkins.
Blockchain transparency didn’t stop the thefts, however it allegedly preserved a traceable path till the funds touched an identity-linked service. Software distribution is due to this fact a part of custody safety earlier than an incident; on-chain information and off-ramp knowledge can change into investigative proof after one.
The submit Crypto malware in 8 Steam games steals tokens after leaving trail to Uber Eats deliveries appeared first on CryptoSlate.

