According to American investigators, cryptocurrency theft was carried out through infected video games: dozens of users fell victim to the scheme, and the total damage exceeded $220,000. The FBI detained 21-year-old Zaire Wilkins from North Lauderdale, Florida, who is believed to be a member of a group that promoted games with malicious software.
Investigators believe Wilkins financed the development and purchase of malicious tools, and then helped distribute games through which attackers gained access to users’ devices and their crypto wallets.
Key facts of the case:
- Detention: In the US, a suspected participant in the infected video game scheme was detained.
- Damage: According to investigators, at least $220,000 in cryptocurrency was stolen from victims through Steam games.
- Evidence: The suspect was identified through crypto payments related to the purchase of Uber Eats gift cards.
How Attackers Used Games to Steal Cryptocurrency
The games were distributed through a major digital distribution platform. The FBI documents do not directly name the platform, but details of the case point to Steam. Among the projects linked to the investigation are BlockBlasters, Dashverse, Lunara, and PirateFi.
According to agents, from May 2024 to February 2026, members of the scheme gained access to about 80 crypto wallets. The minimum confirmed damage is estimated at $220,000.
In total, eight games are mentioned in the case. Through them, investigators believe, attackers infected the devices of about 8,000 users, then stole personal data, accounts, and funds from wallets.
This type of malware is dangerous because it disguises itself as a regular gaming product. For the user, everything looks familiar: they download the game, launch it, and do not immediately realize that a data theft tool has been installed on their device along with it.
To promote the games, the group used several channels at once:
- Discord.
- Telegram.
- X.
- LinkedIn.
- Bots to search for owners of large sums.
Why Investigators Focused on Zaire Wilkins
Online, Zaire Wilkins, according to the FBI, used the nickname . Under this name, he communicated with the main developer of the malware, whose identity is not disclosed in the documents.
After searching the main developer, law enforcement found correspondence with in Signal. Agents described it as evidence of close interaction between members of the scheme.
From the messages, investigators claim, the financial details also became clear. Wilkins allegedly bought a remote access program for $10,000, and the interlocutors discussed ways to withdraw funds from victims’ crypto wallets.
Cryptocurrency often becomes a convenient tool for such schemes, especially when criminals try to quickly move funds between wallets. In this case, not only stolen assets are mentioned, but also payments that helped identify the suspect.
Uber Eats Gift Cards Became Key Evidence
Investigators traced the movement of money from an account linked to the scheme. The funds went to the Bitrefill service, where more than 150 gift cards were purchased, mostly for Uber Eats.
The chain then led to a delivery account. According to investigators, the gift cards were used in a profile where orders were placed to addresses linked to Wilkins.
During a search of the suspect, devices and three seed phrases from crypto wallets were seized. One of them, agents said, belonged to a Monero wallet — a cryptocurrency with enhanced anonymity that is harder to track.
The case materials mention several cryptocurrencies and related elements:
- Ethereum: The network alias indicates a connection to the Ethereum domain name ecosystem.
- Bitcoin: In similar cases, it is often seen as the main symbol of the crypto market, but here, specific wallets, payments, and gift cards became key for the investigation.
What the Suspect Faces
Zaire Wilkins faces up to ten years in prison. He is accused of conspiracy to unlawfully access others’ data for financial gain.
Essentially, the investigation considers the case a crime related to unauthorized access to devices and theft of digital assets. In different countries, such episodes fall under information technology crimes, and criminal law provides for serious punishment.
This story is also indicative for Russia: the Bank of Russia regularly warns investors about fraud risks in the financial market, including schemes involving crypto assets, fake services, or financial pyramids. The Investigative Committee of the Russian Federation also deals with digital crimes, where correspondence, devices, wallets, and payment traces play an important role.
What to Do If Your Cryptocurrency Is Stolen
Act quickly: the sooner transactions and appeals are recorded, the higher the chance of freezing funds on the platforms they pass through.
- Save transaction hashes, wallet addresses, screenshots of correspondence, profile links, receipts, exchange emails, and any data about the malicious file or site.
- Contact the police and provide all collected materials: time of theft, amount, wallet addresses, names of exchanges, devices, and services.
- If the funds went through an exchange, immediately write to their support and ask them to check transactions, accounts, and possible withdrawal blocks.
- If necessary, involve a specialized cybercrime investigation service or blockchain analysts who help track the movement of funds.
- Report phishing sites and malicious resources to Roskomnadzor if they continue to operate and may attack other users.
Is It Possible to Recover Stolen Cryptocurrency
Recovering digital assets is difficult, but there is a chance if the stolen funds end up on an exchange or another service with client verification. In such cases, transaction tracking, contacting platform support, and working with law enforcement can help.
- It is easiest to act when wallet addresses, transaction hashes, and services through which the funds passed are known.
- It is harder to recover assets if criminals quickly transfer them between wallets, use anonymous cryptocurrencies, or withdraw through a chain of intermediaries.
- Cryptocurrency anonymity is not absolute: investigators analyze the blockchain, compare transactions, and use exchanges’ KYC data if the funds pass through regulated platforms.
Main Cryptocurrency Theft Schemes and Protection
- Phishing: fake sites, emails, and messages trick users into giving up passwords, seed phrases, and access codes.
- Malware: infected games, files, or extensions gain access to the device and wallets.
- Exchange hacking: the attacker tries to access the account or platform infrastructure.
- Social engineering: scammers exploit trust, urgency, or promises of profit.
- SIM swapping: the phone number is transferred to another SIM card to intercept confirmation codes.
A separate risk is that scammers are increasingly using artificial intelligence to craft messages, fake profiles, and more convincing ads. To protect yourself, use hardware wallets, two-factor authentication, backup seed phrases, and separate passwords for different services.
Pay special attention to these risks:
{
“@context”: “https://schema.org”,
“@type”: “Article”,
“about”: [
{
“@type”: “Thing”,
“name”: “cryptocurrency”
},
{
“@type”: “Thing”,
“name”: “bitcoin”
},
{
“@type”: “Thing”,
“name”: “ethereum”
},
{
“@type”: “Thing”,
“name”: “malware”
},
{
“@type”: “Thing”,
“name”: “information technology crimes”
},
{
“@type”: “Organization”,
“name”: “Bank of Russia”
},
{
“@type”: “Organization”,
“name”: “Investigative Committee of the Russian Federation”
},
{
“@type”: “Place”,
“name”: “Russia”
}
]
}
- Unknown games.
- Unknown files.
- Suspicious offers in messengers.
- Suspicious offers on social networks.
