Recently, a 21-year-old man living in Florida, USA, was arrested by the FBI. The man is accused of planning and executing a nearly two-year cybercrime campaign that successfully infected about 8,000 personal computers and stole at least $220,000 from about 80 cryptocurrency wallets by planting malware in video games.

According to the FBI's indictment, the suspect, identified as Zyaire Dontaevious Zamarion Wilkins, is accused of working with multiple undisclosed accomplices. Between May 2024 and February 2026, the group spread malware through at least eight video games. Although the indictment does not specify the specific platforms hosting these infected games, it mentions several games that were recently removed from the Steam store.

The gang's methods of committing crimes are very cunning. They not only use social media platforms such as Discord, Telegram, X (formerly Twitter) and LinkedIn to promote these games with malware embedded, but also use automated bots to target target users who hold large amounts of cryptocurrency and conduct precise contact. According to the investigation, the main function of the malware is to steal the victim’s passwords and other sensitive data, thereby illegally invading and emptying their online wallets.

A key breakthrough in this investigation is the tracking of funds. Through analysis, the FBI discovered that the stolen Bitcoins were converted into more than 150 Bitrefill gift cards, which were then used primarily to pay for Uber Eats delivery orders.

According to statistics from well-known cryptocurrency researcher ZachXBT and malware repository vx-underground, the game "BlockBlasters" alone has caused approximately 261 to 478 users to be victimized, with the amount involved as high as $150,000. These include a Twitch anchor named RastalandTV, who was unfortunately stolen from $32,000 in September 2025. The funds were originally raised by enthusiastic viewers to pay for his cancer treatment.

According to a report by Miami local media WPLG Local 10, law enforcement intercepted Signal chat records on the device of a person suspected of being the software's developer, and these records directly linked Wilkins to the case. Information shows that Wilkins, who used the alias "Sibel.eth", not only planned the entire criminal operation, but also spent $10,000 to purchase a remote access Trojan, and discussed with his associates how to trick victims into approving fraudulent cryptocurrency transactions. At present, the developer of the malware has not been formally charged, and the relevant investigation is still ongoing.

The FBI has made it clear that any users who have downloaded these infected games should proactively contact relevant departments to assist in the investigation. As the investigation deepens, more criminal details of this gang are gradually emerging.