QuiverCrypto QUIVERCRYPTO SUBSCRIBE
QuiverCrypto
← Blog

Steam malware exploits vulnerabilities to steal crypto assets and connect to Uber Eats

Investigators reveal how malware in Steam games steals crypto by tracing payments to Uber Eats deliveries.

12 August 2026 · 4 min read

Steam malware exploits vulnerabilities to steal crypto assets and connect to Uber Eats

Recent investigations have uncovered a troubling trend involving malware embedded in popular Steam games that has compromised thousands of devices and resulted in significant crypto theft. The investigation showcases the vulnerabilities present in software distribution and the importance of secondfi-exploit-as-security-concerns-rise/">wallet security.

The rise of crypto malware in gaming

The FBI has launched a formal investigation into eight games available on the Steam platform. According to reports, these games infected approximately 8,000 devices, leading to unauthorized access to roughly 80 crypto wallets and resulting in losses exceeding $220,000. With the rapid growth of the gaming industry, this incident serves as a wake-up call about the potential dangers hidden within seemingly harmless downloads.

The games at the center of this investigation are BlockBlasters, Chemia, Dashverse, DashFPS, Lampy, Lunara, PirateFi, and Tokenova. The malicious campaign is believed to have been active between May 2024 and January 2026. In the allegations documented by the FBI, the campaign's mastermind, 21-year-old Zyaire Dontaevious Zamarion Wilkins, was arrested on July 14 and is accused of financing the malware and promoting the infected games.

How the malware operates

According to investigators, the malware gains initial access through downloads promoted on platforms like Discord, Telegram, and LinkedIn. The group allegedly employed bots to target individuals with substantial crypto holdings, coaxing them into downloading the infected games.

Once installed, the malware performed various malicious activities, including extracting personal data, credentials, and wallet information. In some cases, operators even discussed tactics to trick victims into approving unauthorized transactions that could empty their wallets. A specific title on the FBI's list, PirateFi, was reported to contain a sophisticated infostealer named Vidar, which was designed to harvest sensitive information such as session cookies and crypto wallet specifics.

The investigation and payment tracing

Following the money trail has become a crucial component of the investigation. Reports indicate that investigators traced Bitcoin payments from the malware-related wallet to Bitrefill, a platform that allows users to purchase digital gift cards—most notably for services like Uber Eats. The payments were tied to an Uber Eats account, leading back to addresses associated with Wilkins.

This connection illustrates a critical aspect of blockchain technology: while it offers transparency that can aid law enforcement in tracking stolen funds, it also reveals shortcomings in security during wallet management. Although the thefts occurred, the ability to trace transactions showcases the potential for blockchain to act as a double-edged sword in the context of crypto custody and security.

The implications for wallet security

This incident brings to light significant concerns regarding wallet security and the processes undertaken during software downloads. The current findings indicate that vulnerabilities can exist not just within wallets but also at the point of software distribution. As such, users cannot rely solely on official marketplaces for protection.

According to Valve’s documentation, initial game builds are subject to checks for harmful behavior; however, once a game is approved, it can later be updated without re-evaluation. This loophole allows malicious actors to exploit the system undetected, raising questions about the integrity of software distribution platforms.

For crypto wallet users, there are steps that can be taken to mitigate these risks. Keeping wallet credentials secure and ensuring transaction prompts are carefully reviewed can help prevent unauthorized access and malicious transfers. Ultimately, the case serves as a reminder that software security must encompass a broad range of digital interactions.

Looking ahead: the future of crypto security

As the gaming industry continues to grow and more players enter the crypto space, the imperative for robust security measures has never been more pressing. The dual challenges of malware in software distribution and the risks associated with wallet management highlight the need for continued innovation and improvement in security practices. Ensuring that software is consistently monitored for vulnerabilities not only protects gamers but also safeguards sensitive financial information.

The collaboration between law enforcement and investigative teams exemplifies how essential it is to address these threats proactively. Future incidents may arise as criminals develop more sophisticated methods, making vigilance paramount in protecting both users and their assets.