A cyberattack managed to bypass Steam controls, infecting nearly 8,000 computers and allowing the theft of over $220,000 in cryptocurrency from players around the world. The operation was dismantled following the arrest of Zyaire Dontaevious Zamarion Wilkins, according to data from digital security experts at Eset and court documents in the United States. The case demonstrates that, although official platforms maintain strict security policies, cyber attackers continue to seek new ways to undermine user trust.
For nearly two years, between May 2024 and February 2026, the perpetrator of the malicious campaign used video games published on Steam to distribute an infostealer, a program designed to steal credentials, passwords, session tokens, and data associated with cryptocurrency wallets. According to the FBI, the affected titles included: BlockBlasters, Chemia, Dashverse, DashFPS, Lampy, Lunara, PirateFi, and Tokenova, which were promoted in communities like Discord, Telegram, and X, attracting unsuspecting users. The malware ran alongside the game, allowing access to private information and facilitating the theft of digital assets. In some cases, attackers used chatbots to identify profiles with large amounts of cryptocurrency and prioritized these targets. One of the central elements of the attack was the exploitation of the trust that users place in official platforms. Although Steam has technical reviews and controls to detect malicious software, these processes do not equate to a comprehensive security audit. The attackers managed to publish titles that appeared legitimate, surpassing initial verifications and even launching subsequent malicious updates. The strategy was not limited to the technical aspect. The perpetrators leveraged social engineering to convince players of the authenticity of the games, using reviews, forums, and social media campaigns to give them visibility.
The case of Steam is not isolated. In 2025, Apple removed nearly 59,000 applications that, after being approved, introduced changes to commit fraud. This situation highlights that no review system is completely infallible, even in the most recognized digital sector stores. The main lesson for users is that security does not solely depend on the platform. While downloading from official sites remains the best practice, cybercriminals have adapted their tactics to exploit the perception of trust generated by these environments.
To reduce the risk of downloading malware, it is essential for users to adopt additional verification habits:
After the detection of the campaign, the FBI requested the collaboration of those affected to gather evidence and trace the operation. The contribution of information from users was crucial in identifying the compromised titles and associating the evidence with the main suspect. This collaborative approach allowed for the reconstruction of the malware's operation and concluded the investigation with the arrest of the perpetrator. The significance of this incident lies in the fact that it affected one of the largest digital distribution platforms, considered by millions of users as a safe environment for downloading video games. While Steam implements review and verification processes, the sophistication of attacks and the use of social engineering techniques continue to pose risks to the gaming community. The incident highlights the limits of security on official platforms and the need for a more critical attitude from users.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























From Miami to Milan, and from Paris to the Netherlands, WEEX's AI Trading emerged as the standout on-site activation across five major industry events, giving hundreds of users their first hands-on encounter with AI-driven trading through a risk-free simulated environment. The rollout marks a significant step in WEEX's broader strategy to make AI-powered trading tools accessible, intuitive, and engaging for a global audience — both online and offline.
