Florida Man Arrested for Crypto Theft Scheme

The FBI has arrested a 21-year-old Florida resident accused of running a cybercrime operation that infected around 8,000 PCs with malware spread through video games. The operation reportedly stole about $220,000 in cryptocurrency from roughly 80 wallets between May 2024 and February 2026, according to a federal indictment and reports from TechSpot.
The suspect is identified in court documents as Zyaire Dontaevious Zamarion Wilkins. Several of the infected games mentioned in the FBI complaint were listed on Steam until earlier this year, although the indictment does not specify the storefront by name.
The FBI complaint names BlockBlasters, Dashverse, Lunara, and PirateFi among the infected titles. TechSpot reports that all four games were still available on Steam until earlier this year, when the FBI announced its investigation and urged anyone who had downloaded the malicious games to come forward.
According to forensic cryptocurrency researcher ZachXBT and the malware repository vx-underground, BlockBlasters alone is estimated to have stolen around $150,000 in cryptocurrency from between 261 and 478 victims. This amount includes $32,000 stolen from Twitch streamer RastalandTV in September 2025.
Related: San Francisco demands Apple and Google remove nudify apps
The malware was designed to extract passwords and other sensitive data from victims’ computers, which was then used to drain online cryptocurrency wallets. Investigators allege that Wilkins and associates promoted the infected games on platforms including Discord, Telegram, X, and LinkedIn.
They used bots to find users with large cryptocurrency holdings and contacted them directly. The FBI believes Wilkins financed the operation and marketed the malware to other cybercriminals on underground forums.
TechSpot reports that recovered Signal chats from the suspected malware developer’s devices link Wilkins to the operation. Miami news station WPLG Local 10 reports that these messages suggest Wilkins, operating under the dark web alias Sibel.eth, bought a $10,000 remote access trojan and discussed methods to trick victims into approving fraudulent cryptocurrency transactions.
The FBI traced the stolen bitcoin to over 150 Bitrefill gift cards. TechSpot notes that these gift cards were mostly used to pay for Uber Eats orders. This gift card trail played a key role in identifying the suspects and linking blockchain activity to real-world purchases.
Related: Vibrant Beats Dancing Bridges Highlight Sustainable IoT
Investigators also searched the property of the suspected malware developer for additional evidence. Users who downloaded BlockBlasters, Dashverse, Lunara, or PirateFi on any platform should consider their systems compromised.
Recommended actions based on the malware’s behavior include:- Disconnect the affected PC from the internet before using it further. Transfer any cryptocurrency to a new wallet created on a clean, secure device, and consider existing seed phrases stored on the compromised PC as invalid. Change passwords for email, exchange, and wallet accounts from a trusted device, and enable hardware keys or app-based two-factor authentication where available. Run a full offline scan with reputable anti-malware software, and perform a clean reinstall of the operating system if any credential-stealing components are found. Review browser session tokens and revoke active sessions on exchanges, wallet services, and email accounts.
Wilkins and unnamed co-conspirators face multiple charges, including conspiracy to distribute malware.
Wilkins has been charged but not yet convicted, and the indictment mentions co-conspirators who have not been publicly named.
