-
FBI investigators linked a Bitcoin wallet to Bitrefill gift cards, Google records, phone data, and Uber Eats orders.
-
The complaint alleges that a malware campaign infected about 8,000 devices and accessed roughly 80 crypto wallets.
-
A later home search found a Monero seed phrase linked to about 1,233 XMR in total transaction activity.

Federal investigators used a long trail of digital records to identify a Florida man in a Steam malware case. The records included Google cookies, phone details, Bitcoin payments, and more than 500 Uber Eats orders. A 15-page federal complaint names Zyaire Dontaevious Zamarion Wilkins as the alleged financier and marketer.
Federal agents arrested the 21-year-old Florida resident on July 14, according to the complaint. The filing charges Wilkins with one count of conspiracy to obtain information by computer for private financial gain.
The FBI alleges that the wider campaign infected about 8,000 devices and reached roughly 80 cryptocurrency wallets. Investigators say the campaign stole at least $220,000 in cryptocurrency from those wallets.
Messages Describe Wilkins’ Alleged Role
The complaint says another person created the developer accounts and launched the infected games. Investigators allege that Wilkins provided money and helped promote the games to potential victims.
The group reportedly promoted the games through Discord, Telegram, X, and LinkedIn. According to the complaint, bots also helped identify people who held large amounts of cryptocurrency. Messages cited by investigators reportedly discussed spending $10,000 on a remote-access Trojan.
The messages also allegedly covered plans to place malware inside games and convince users to download them. The complaint says another participant told investigators that Wilkins provided launch and marketing money. In return, Wilkins allegedly expected part of the stolen cryptocurrency and access to private victim information. The tactic of hiding malware in fake game files has been flagged by the FBI as a growing threat to Steam gamers.
The complaint does not directly name Steam as the game platform involved in the case. However, the games and details described in the filing match titles previously linked to a Steam malware investigation.
Bitcoin Payments Led Investigators to Wilkins
Investigators found a Bitcoin address in messages seized from an unnamed alleged co-conspirator. According to the complaint, Wilkins allegedly provided the address to receive money for the cryptocurrency-draining campaign. Investigators then confirmed that the address received about $10,000 on the day it was provided.
The complaint says investigators later traced payments from that address to Bitrefill. The service allows users to buy gift cards and other digital products with cryptocurrency. Bitrefill records allegedly connected the payments to one account that bought more than 150 gift cards. Some of those gift cards were used for Uber Eats orders, according to the complaint.
Investigators then examined an email address linked to the Bitrefill account through records obtained from Google. Google records allegedly connected the email address to several other accounts through browser cookies.
One account reportedly used Wilkins’ initials and linked to a University of West Florida student. Another account listed a phone number as its recovery contact, according to the complaint.
Investigators then linked that number to an email address containing Wilkins’ name. They also connected it to a Snapchat account that had previously displayed his name. The same trail reportedly led investigators to a T-Mobile account registered at an address linked to his family. Uber records added another key part to the investigation.
The complaint says one Uber account used the same phone number found in the other records. The account reportedly placed more than 500 food orders between March 2024 and May 2026.
Those orders cost more than $9,000 and went to three different locations, according to the complaint. Two locations were linked to the University of West Florida, while another was Wilkins’ North Lauderdale address.
Investigators also noted a pattern in when the deliveries happened. Orders sent to university addresses mostly occurred during periods when classes were running. Orders outside those periods reportedly went to Wilkins’ family address.
The complaint says about 15 deliveries reached the North Lauderdale address between May 6 and May 17, 2026. Investigators used the Uber records alongside Bitrefill data, Google cookies, phone records, and other information. The complaint does not say that every payment or food order came from stolen money.
Search Found Monero Seed Phrase
FBI agents later searched Wilkins’ North Lauderdale home, according to the complaint. The search reportedly uncovered laptops, phones, other digital devices, and three cryptocurrency wallet seed phrases. One seed phrase belonged to a Monero wallet containing eight addresses.
Investigators said the wallet history showed about 1,233 XMR sent or received through those addresses. The total activity was valued at roughly $382,000, according to the complaint. That $382,000 figure represents cumulative transaction activity, not the wallet’s balance. It also remains separate from the alleged $220,000 loss suffered by victims in the malware campaign.
The complaint does not describe all 1,233 XMR as stolen funds or say that Wilkins owned all of it. Investigators found the Monero evidence during the home search, using a seized seed phrase. The FBI therefore did not identify the Monero activity by tracing transactions through Monero’s public transaction history.
Wilkins remains presumed innocent unless proven guilty in court. Local 10 reported that his attorney did not respond to requests for comment. The outlet also reported that Valve had not responded to questions about the case and Steam’s security measures at publication time.