The FBI Just Busted a Steam Game That Was Secretly Draining Crypto Wallets
What Actually Happened
According to federal prosecutors, Zyaire Wilkins — who reportedly went by "Sibel.eth" online — and his associates published several games on Steam over roughly two years, including titles like BlockBlasters, Dashverse, Lampy, Lunara, and PirateFi. These weren't obvious scams. The games installed and ran like real games, which is exactly what let them slip past players' guard. Underneath, they were carrying malware built to steal information and crypto from the machines they landed on.
Investigators say around 8,000 devices got infected before the operation was caught. From there, the malware was used to compromise roughly 80 crypto wallets, pulling out more than $220,000 in stolen funds.
Here's the detail that actually cracked the case: investigators traced crypto payments from the scheme to gift card purchases, including Uber Eats. A subpoena to Uber linked those gift cards to a delivery account — and that account led straight to the suspect. Even "anonymous" crypto spending leaves a trail when it eventually touches a real-world purchase.
How a Video Game Gets Your Crypto
People assume malware needs some dramatic hack to steal crypto. It usually doesn't. Once malicious code is running on your computer — hidden inside a game installer, a "crack," or a bundled app — it can quietly read what's already sitting on your machine: saved passwords, browser data, and any crypto wallet software or browser extension you have installed. If your wallet's seed phrase or private key is saved anywhere on that device, in a text file, a screenshot, a notes app, a browser autofill, the malware is built to go find it.
This is why "it's just a free game" is such a dangerous assumption. The malware doesn't care what the game is about. It cares what else is installed on the same computer.
Red Flags Worth Remembering
- A game from an unknown or brand-new developer with barely any reviews. Established studios rarely vanish after one release; scam accounts often do.
- Free-to-play titles pushed hard through social media or Discord ads. Legitimate indie games get there through word of mouth, not aggressive crypto-community targeting.
- Any crypto wallet, seed phrase, or private key stored on the same device you game on. That's the single biggest thing that turned this into a $220,000 theft instead of a minor annoyance.
- Games bundled with "extra" installers or asking for admin permissions that seem unrelated to gameplay. A game doesn't need deep system access to run.
- Steam listings with copy-paste descriptions or stock screenshots. A little inconsistency in a store page is often the only visible clue before install.
How to Actually Protect Yourself
- Keep crypto wallets off your gaming PC entirely. Use a separate device, or better, a hardware wallet that never exposes your keys to any computer's operating system.
- Never store a seed phrase digitally. Not in a text file, not in a password manager note, not in a photo. Write it down on paper and keep it offline.
- Stick to well-reviewed games from established publishers when possible. New, unknown titles deserve a quick search for the developer's name plus "scam" or "malware" before you install.
- Run antivirus scans regularly, especially after installing anything new. It won't catch everything, but it catches more than nothing.
- If a wallet is ever exposed to a compromised device, move funds to a new wallet immediately. Don't wait to see if anything looks wrong first.
The uncomfortable truth here is that this scam didn't rely on some sophisticated crypto exploit — it relied on people keeping their financial keys on the same machine they use for everyday things like gaming. That's the fixable part. Keep your crypto access separate from anything you download for fun, and a fake game stays exactly that: annoying, not catastrophic.