Steam Malware Suspect Caught via Gift Cards, Delivery App and Seized Crypto Seeds

A Bitcoin address, 500 Uber Eats orders and seized Monero seed phrases unravelled an alleged Steam malware campaign — not XMR’s cryptography.

Investigation workspace showing smartphone with delivery app, gift cards, and cryptocurrency evidence under dramatic lighting

Zyaire Dontaevious Zamarion Wilkins, 21, was arrested in Florida on July 14 after a 15-page federal criminal complaint detailed how investigators linked him to an alleged Steam malware campaign – not by tracing Monero on-chain, but by following a Bitcoin address through gift card purchases, Google cookies, and more than 500 Uber Eats deliveries to his front door.

A subsequent residential search on July 8 turned up three cryptocurrency seed phrases. One controlled a Monero wallet across eight addresses that showed approximately 1,233 XMR in cumulative transaction activity, valued at roughly $382,000 at the time – a figure the complaint keeps explicitly separate from the $220,000 victim-loss estimate attributed to the broader campaign. Wilkins is presumed innocent unless proven guilty.

How a Bitcoin Address Unravelled a Multi-Platform Identity Trail

The FBI’s thread began with a Bitcoin address recovered from messages seized from an unnamed co-conspirator identified in the complaint as Subject #1. According to the complaint, Wilkins allegedly supplied that address to receive funding for a cryptocurrency-draining campaign, and investigators confirmed it received an approximately $10,000 payment on the day it was provided.

From there, investigators traced outbound payments from the same address to Bitrefill, a platform that allows customers to buy gift cards with cryptocurrency. Bitrefill records connected those payments to a single account that had purchased more than 150 gift cards, including Uber Eats cards. The email address on that Bitrefill account became the next link in the chain.

Google records obtained by investigators allegedly linked that email through browser cookies to additional accounts – one appearing to use Wilkins’ initials and associated with a University of West Florida student, another listing a phone number as its account recovery contact. That number then tied to an email containing Wilkins’ name, a Snapchat account that had previously displayed his name, and a T-Mobile account registered at an address associated with his family. The identity chain ran through Bitrefill, Google, Snap, and a mobile carrier

500 Food Orders Mapped Three Physical Locations

Uber records, according to the complaint, identified one account associated with the gift cards, registered to the same phone number found across the other records. That account placed more than 500 food-delivery orders between March 2024 and May 2026, spending over $9,000 – and every order went to one of three locations.

Two addresses were tied to the University of West Florida. The third was Wilkins’ North Lauderdale residence. The complaint notes that orders to the university addresses largely clustered during academic terms, while deliveries outside those periods shifted to the North Lauderdale address – approximately 15 orders went there between May 6 and May 17, 2026 alone. The complaint does not establish that every order or payment involved stolen funds.

Prosecutors allege that a separate participant created the developer accounts and launched the games on Steam, while Wilkins supplied launch and marketing funding in exchange for a share of stolen cryptocurrency and access to victims’ private information. The complaint describes messages discussing spending $10,000 on a remote-access trojan, embedding malware in games, and using bots to identify targets with large crypto holdings for directed messaging across Discord, Telegram, X, and LinkedIn. The FBI and the complaint allege that the campaign infected approximately 8,000 devices, accessed around 80 cryptocurrency wallets, and caused at least $220,000 in victim losses.

The Steam gaming platform logo centered in a purple and white gradient circle on a black background

What the Monero Find Actually Shows – and What It Doesn’t

The Monero evidence is the detail most relevant to privacy-coin holders, and the mechanics matter. Investigators obtained the seed phrase through a physical search warrant and seized it from Wilkins’ residence. They did not deanonymize Monero’s transaction graph or use chain-level tracing to locate the wallet. The $382,000 cumulative activity figure reflects all sends and receives the wallet processed – the complaint explicitly does not characterize the full 1,233 XMR as stolen funds or as Wilkins’ current balance.

That distinction matters for how investors should read this case. Monero’s on-chain privacy appears to have held in the technical sense: the complaint’s identity narrative runs entirely through Bitcoin payments, gift card platforms, Google cookies, a mobile carrier, and a delivery app – not through any public Monero transaction record. The privacy failure was operational, not cryptographic. Centralized touchpoints at Bitrefill, Google, Uber, Snap, and T-Mobile each produced records that contributed to the warrant, and the warrant produced the seed phrase.

That operational pattern is consistent with how law enforcement has approached privacy coins in other enforcement actions – relying on device seizures, KYC records at intermediaries, and conventional surveillance rather than on-chain deanonymization. Criminal exposure for crypto firms and individuals increasingly runs through those same off-chain chokepoints, not through breaks in the underlying cryptography.

For privacy-conscious holders, the lesson is not that Monero is broken – it is that privacy tools are only as effective as the operational security surrounding them. Every centralized service that touches a wallet, a purchase, or a delivery represents a potential warrant target. Bitrefill, by design, requires an email address. Google retains browser cookies. Uber logs every order. Each is a point of failure that has nothing to do with XMR’s ring signatures or stealth addresses.

Regulatory Posture and What Comes Next

Exchanges and regulators have been tightening their posture around privacy coins for several years, and cases like this tend to accelerate that pressure regardless of whether the technical privacy guarantee held. Enforcement narratives treat the presence of Monero as an aggravating factor in risk assessments even when, as here, it played no role in the identity resolution. The result is continued compliance pressure on platforms that list XMR – a dynamic already visible in AML enforcement actions against crypto exchanges globally, where regulators focus on whether platforms have adequate controls regardless of whether those controls would have changed investigative outcomes.

Professional cryptocurrency trading interface showing BTC/USDT candlestick charts and order books

Wilkins faces one count of conspiracy to obtain information by computer for private financial gain. As reporting by TechCrunch noted, his attorney did not respond to a request for comment. Local 10 reported that Valve had not responded to questions about the case or Steam’s security measures by publication. Valve’s developer onboarding and malware-detection processes remain under scrutiny, and policy changes to game submissions are possible as the case moves toward trial.

For crypto investors tracking privacy-coin exposure, the immediate regulatory read is that this case will be cited in policy discussions around privacy-coin delistings and AML rule-making – whether or not those citations accurately reflect what the investigation technically demonstrated. The market will be forced to price that narrative risk separately from any assessment of Monero’s cryptographic integrity.

Follow CoinNews on X and Telegram for ongoing coverage of crypto enforcement actions and market-structure developments.

Source: CryptoSlate

About Author

Ifeanyi Egede

About Author

Ifeanyi Egede

Ifeanyi Egede

Ifeanyi Egede is a seasoned crypto journalist with six years of experience covering the dynamic world of cryptocurrencies and blockchain technology. Specializing in coin news, market analysis, crypto reviews, and comprehensive guides, Ifeanyi delivers insightful and accurate content that empowers readers to navigate the complexities of the crypto space. With a keen eye for market trends and a deep understanding of blockchain innovations, his work combines technical expertise with clear, engaging storytelling. Ifeanyi's contributions have been featured in leading crypto publications, establishing him as a trusted voice in the industry.
ABOUT COINNEWS
100k+
Active Monthly Users Around the World
50+
Guides and Reviews Articles
3
Years on the Market
8+
In-house Authors
At Coinnews, we aim to make cryptocurrency, blockchain, and Web3 understandable, and information available to everyone, no matter what level you are in your investment journey. Founded in 2022, Coinnews has been dedicated to delivering reliable, multilingual coverage of the cryptocurrency industry.