Futures
Access hundreds of perpetual contracts
CFD
Gold
One platform for global traditional assets
Options
Hot
Trade European-style vanilla options
Unified Account
Maximize your capital efficiency
Demo Trading
Introduction to Futures Trading
Learn the basics of futures trading
Futures Events
Join events to earn rewards
Demo Trading
Use virtual funds to practice risk-free trading
CFD
Stock CFD Derivatives
US Stocks
Access real US stocks and ETFs
HK Stocks
Trade quality Hong Kong-listed stocks
Korean Stocks
SK Hynix
Real Korean stocks and top assets
Stock Futures
High leverage, 24/7 trading
Tokenized Stocks
Backed by real stock assets
IPO Access
Unlock full access to global stock IPOs
GUSD
3.8%
Mint GUSD for Treasury RWA yields
Stocks Activities
Trade Popular Stocks and Unlock Generous Airdrops
Launch
CandyDrop
Collect candies to earn airdrops
Launchpool
Quick staking, earn potential new tokens
HODLer Airdrop
Hold GT and get massive airdrops for free
IPO Access
Unlock full access to global stock IPOs
Alpha Points
Trade on-chain assets and earn airdrops
Futures Points
Earn futures points and claim airdrop rewards
Promotions
AI
Gate AI
Your all-in-one conversational AI partner
Gate AI Bot
Use Gate AI directly in your social App
GateClaw
Gate Blue Lobster, ready to go
Gate for AI Agent
AI infrastructure, Gate MCP, Skills, and CLI
Gate Skills Hub
10K+ Skills
From office tasks to trading, the all-in-one skill hub makes AI even more useful.
Hackers who planted a Trojan on Steam to steal wallets lost because they loved ordering delivery too much
Zyaire Wilkins, 21, was arrested in Florida on July 14. A 15-page federal criminal complaint accuses him of funding the insertion of crypto-stealing trojans into eight Steam games, infecting about 8,000 devices, opening about 80 wallets, and stealing at least $220k. And the method used by the FBI to find him was not cracking Monero, but more than 500 Uber Eats delivery orders—along with three sets of wallet recovery seed phrases copied from his home on the day the search warrant was served.
(Background: A cancer-stricken livestreamer playing Steam games had his crypto wallet drained; Valve urgently removed the trojan games.) (Additional context: NTU top student Lin Rensiu was sentenced to 30 years in the U.S.! An underground web built a “drug treasure-hunting site,” earning 3 billion over three years.)
Table of contents
Toggle
Key takeaways
Tags: Monero, Steam, FBI, Bitrefill, BlockBlasters
From May 6, 2026, to May 17, 2026, a Florida North Lauderdale residence received deliveries about 15 times at the doorstep. The payments were made with gift cards purchased with Bitcoin, and the Bitcoin came from 80 looted crypto wallets.
FBI agents laid these orders out one by one, mapping them into a single diagram.
Zyaire Wilkins didn’t not understand cryptocurrencies. Investigators found a set of Monero wallet seed phrases at his home. Monero is widely regarded within the industry as the most difficult privacy coin to track—transaction amounts, receiving and sending addresses, and counterparties are all encrypted. He knew how to convert money into Monero.
But he delivered the meals to his own house.
Eight games attacked 8,000 computers
Last year, this case was covered by 動區 about the victim side. In September 2025, a cancer-stricken livestreamer, while playing a Steam game called BlockBlasters during a live stream, had a wallet emptied on the spot; Valve urgently delisted the game. At the time, no one knew where the funds went.
The complaint now provides the answer. From May 2024 to February 2026, eight games—including BlockBlasters, Dashverse, Lampy, Lunara, and PirateFi—were gradually launched on Steam. Each one hid the same set of remote-access trojans. About 8,000 computers were compromised, about 80 wallets were opened, and confirmed victim losses were at least $220k.
The complaint describes the division of labor as follows: an unnamed Subject #1 was responsible for applying for a developer account and getting the games published; Wilkins paid for it. First, he used about $10k worth of Bitcoin to buy that trojan set, then paid the publishing and marketing fees in exchange for a cut of the proceeds and the victims’ personal information. Marketing was done on Discord, Telegram, X, and LinkedIn, and bots specifically sent direct messages to users with large holdings.
Stolen funds bought gift cards; the gift cards were used for delivery
The first stop of the money was Bitrefill, a platform that buys gift cards with cryptocurrency. More than 150 gift cards came out of there. Investigators followed the linked email addresses to check browser cookies, pulled several email addresses that included Wilkins’ initials, then connected from the account’s recovery phone number to T-Mobile records, a former Snapchat account that once used his real name, and the North Lauderdale house where his family lived.
Next came the most unencrypted part of the entire chain. From March 2024 to May 2026, more than 500 Uber Eats orders totaling more than $9,000 were delivered to three addresses. The FBI matched delivery times against the calendar of the University of West Florida—sending to the school during the semester and sending back home during breaks.
This is a very old-school lesson in digital forensics. Ross Ulbricht of the darknet Silk Road hid for two years using Tor, but ultimately got caught in 2011 due to a forum post that left behind a Gmail address. Technical anonymity can hide you—but your day-to-day schedule is hard to avoid.
Monero written on paper
When the July 8 search warrant was executed, investigators took a laptop, a phone, and three sets of encrypted wallet seed phrases from inside the home—one of which was Monero.
Once the seed phrases were obtained, Monero’s privacy design became useless. Investigators used them to open the wallet, laying out in front of them the entire history of transactions: 8 addresses and accumulated 1,233 XMR, valued at about $382k in current prices. This amount was calculated separately from the confirmed $220k victim losses.
On-chain anonymity can withstand on-chain analysis, but it can’t withstand paper that gets copied at home.
Wilkins is currently charged with one count of conspiracy to obtain information by computer and thereby obtain personal financial gain. He is presumed innocent before conviction, and the complaint also does not argue that the 500 deliveries and each payment came from stolen funds. His lawyer did not respond to media inquiries, and Valve likewise had not commented as of the time this article was submitted.
Frequently asked questions
How does the FBI track crypto crimes that use Monero?
The breakthrough in this case wasn’t on-chain. The FBI traced it from Bitcoin payments to a Bitrefill gift card account, then used browser cookies, the T-Mobile phone number, and more than 500 Uber Eats orders to identify him; during the search, they directly seized the Monero seed phrases, making the privacy design essentially ineffective.
Which Steam games were accused of hiding trojans to steal crypto?
The complaint and related reporting named eight games: BlockBlasters, Dashverse, Lampy, Lunara, and PirateFi, among others. They were gradually listed on Steam from May 2024 to February 2026. About 8,000 devices were infected, about 80 wallets were looted, and Valve has been taking them down.