QuiverCrypto QUIVERCRYPTO SUBSCRIBE
QuiverCrypto
← Blog

FBI uncovers Steam malware financier using tech and delivery records

FBI reveals a complex investigation using Google cookies, food orders, and cryptocurrency to apprehend a Steam malware financier.

18 August 2026 · 5 min read

FBI uncovers Steam malware financier using tech and delivery records

A meticulously detailed 15-page federal criminal complaint has emerged, shedding light on how the FBI utilized a combination of Bitcoin trails, Google cookies, phone records, and over 500 Uber Eats deliveries to identify Zyaire Dontaevious Zamarion Wilkins. He is accused of being the financier and marketer behind a significant malware campaign targeting Steam.

Wilkins, who was arrested in Florida on July 14, is charged with conspiracy to obtain information by computer for private financial gain. The investigation revolves around a campaign involving eight Steam games that reportedly infected approximately 8,000 devices and accessed around 80 exchanges-and-raises-concerns-over-token-issuance/">cryptocurrency wallets, resulting in losses exceeding $220,000.

Connecting the dots: How investigators pieced together evidence

The FBI's investigation into Wilkins’ activities began with a Bitcoin payment trail that led them to a wider identity network. These initial financial traces were coupled with various digital footprints, lifting the curtain on his alleged involvement. The complaint lays out a clear path from campaign funding to Wilkins himself.

Documents reveal that another individual created developer accounts and published the games. In contrast, Wilkins was primarily responsible for funding and marketing those titles. Promotional efforts spanned platforms like Discord, Telegram, X, and LinkedIn, using bots to target individuals with substantial cryptocurrency holdings.

Messages exchanged among alleged conspirators detail discussions around investing $10,000 in developing a remote-access trojan, integrating malware into games, and strategies for enticing more players to download them. One anonymous source referenced in the complaint explained how Wilkins exchanged launch funds for a cut of stolen cryptocurrency and personal data from victims.

The intricate role of delivery records in the investigation

By analyzing Uber Eats records, investigators narrowed their findings to three specific addresses associated with Wilkins, pinpointing a pattern that connected him to numerous deliveries made over a two-year span. Between March 2024 and May 2026, over 500 food orders were traced back to various locations, highlighting a significant expenditure exceeding $9,000.

Interestingly, these deliveries coincided with the academic calendar at the University of West Florida, with most orders placed while classes were in session. When classes were not in session, records indicated a shift in delivery to Wilkins family's North Lauderdale address. During a brief window, approximately 15 deliveries were made to the North Lauderdale location alone.

Beyond Uber Eats, investigators leveraged a wide array of data sources including Google browser records and phone numbers linked to Wilkins' email addresses. They discovered connections to Wilkins via a Snapchat account, T-Mobile records tied to the same residence, and a Bitrefill account that described purchases of over 150 gift cards, many of which were for Uber Eats.

Uncovering cryptocurrency ties and the Monero connection

The investigation reached a crucial stage when FBI agents executed a search warrant at Wilkins’ North Lauderdale residence on July 8. During this search, agents seized multiple laptops, phones, and several digital devices, alongside three cryptocurrency wallet seed phrases.

Among these findings, one seed phrase was linked to a Monero wallet with eight associated addresses. Notably, the transaction history of this wallet suggested Wilkins sent or received approximately 1,233 XMR, equating to about $382,000. This figure represents all cumulative activities within the wallet, existing separately from the alleged victim-loss estimate of at least $220,000.

What is particularly noteworthy is how investigators acquired evidence related to Monero, a privacy-focused cryptocurrency. Rather than tracing Wilkins through public transactions, they capitalized on a seized seed phrase to separate related activities from general transaction trends visible on the blockchain.

Legal repercussions and future implications

Legal analysts suggest that the charges against Wilkins may carry significant consequences, particularly given the growing scrutiny of digital currencies by law enforcement agencies. The intersection of traditional investigation techniques with technological innovations highlights new challenges in policing cryptocurrency-related crimes.

Wilkins remains presumed innocent until proven guilty, and the legal context surrounding his case is continuously evolving. As the court measures unfold, this case could serve as a pivotal point of contact between regulatory frameworks and decentralized technology.

Wilkins’ defense attorney did not respond to inquiries regarding the case, and major entities like Valve—parent company of Steam—have remained silent on the incident and any potential implications for their security protocols.

As the details of this case ripple through the cryptocurrency community and the wider tech landscape, it reinforces the importance of combining technological awareness with rigorous investigative techniques. The outcomes could set a benchmark for how authorities will tackle similar cases in the future.

Fostering a tech-savvy crime investigation landscape

This incident underscores a reality: as cryptocurrencies continue to grow in influence, so too does the necessity for law enforcement to adapt their methods. The elements of this investigation—the use of food delivery data alongside digital financial trails—illustrate a modern approach to crime detection that may lead to more effective responses in the fight against cybercrime.

As the landscape surrounding cryptocurrencies evolves, both offenders and law enforcement will need to navigate the challenges of anonymity versus accountability. Balancing these factors will be essential to fostering a tech-savvy crime investigation environment that protects users while encouraging innovation.