FBI Traced Steam Malware Suspect Through Google Cookies, 500 Uber Eats Orders, and a Monero Seed Phrase
How the FBI used Google cookies, 500+ Uber Eats orders, and a Monero seed phrase to charge a 21-year-old Florida man over a $200K Steam malware campaign.
Federal prosecutors have charged a 21-year-old Florida man with financing and marketing a malware campaign that used fake indie games on Steam to steal roughly $200,000 in cryptocurrency from gamers — and the FBI built its case on a trail of digital breadcrumbs that even a privacy coin could not erase.
The suspect is Zyaire Dontaevious Zamarion Wilkins. A 15-page federal criminal complaint lays out how investigators cracked the case by combining a BBTC$64,090.00▼1.60% transaction trail, Google authentication cookies, phone records, and — this is the part that should haunt every would-be crypto criminal — more than 500 Uber Eats food delivery orders. The complaint, reported by TechCrunch on July 17, 2026, describes how the FBI’s Seattle Division launched an investigation into a series of indie games distributed on Steam that had been embedded with information-stealing malware.
This was not crude work. Bitdefender’s analysis found the software capable of harvesting credentials, authentication cookies, and cryptocurrency wallet data from infected machines — the precise combination that lets an attacker bypass two-factor authentication and drain wallets before a victim has any idea something has gone wrong. Download one of the affected titles, and the stealer quietly exfiltrated everything. Silently. Completely.
The flagged Steam titles, according to searches tied to the investigation, include Dashverse, Lunara, DashFPS, Tokenova, and Lampy. The FBI has asked gamers who downloaded any of them to come forward and is collecting victim information through a dedicated form.
What unraveled Wilkins was not a surveillance breakthrough. It was Uber Eats. He allegedly spent proceeds on gift cards from the food delivery platform — a decision that introduced a glaring off-chain vulnerability nobody in the operation apparently thought to question. PCGamer reported that more than 500 orders were traced back to him; each one timestamped, each one tied to a physical delivery address. The gift cards were traceable. The addresses were real. The assumption of anonymity was fiction.
Then came the Bitcoin trail. The public ledger is transparent by design, but correlating on-chain transactions to a living, breathing person still requires off-chain evidence — and investigators had plenty. The complaint details how Google authentication cookies, recovered from machines infected by the malware itself, linked wallet activity to accounts associated with Wilkins. Phone records filled the remaining gaps.
The most consequential find, though, came during a physical search of Wilkins’s property. Investigators recovered a Monero seed phrase — the cryptographic key controlling a Monero wallet — tied to approximately $382,000 in cumulative transactions, according to CryptoSlate. That figure substantially exceeds the $200,000 in alleged theft proceeds, which raises hard questions about whether the wallet was Wilkins’s alone or connected to a broader operation the complaint does not fully detail.
Monero (XMR) is engineered specifically to obscure transaction trails. Unlike Bitcoin, where every transfer sits on a public blockchain, Monero uses ring signatures and stealth addresses to hide sender, receiver, and amount — rendering on-chain analysis nearly useless for tracing funds. A seed phrase, though, is a physical object. Finding one in a suspect’s property is the equivalent of locating a ledger that was never supposed to exist; it sidesteps the entire privacy architecture of the coin in a single search warrant.
The case hammers a point investigators have pressed repeatedly in crypto-related prosecutions: privacy coins do not guarantee anonymity when law enforcement can obtain physical evidence or correlate off-chain spending patterns. Deploy the most sophisticated cryptographic tools available, order 500 meals to a traceable address, and leave a seed phrase in a drawer — the privacy guarantees collapse exactly where the digital meets the physical.
The gap between the $382,000 in Monero transactions and the $200,000 in reported stolen funds remains unresolved in the complaint. It could indicate additional victims who have not yet come forward, a separate revenue stream, or funds routed through the wallet by other actors. The FBI’s victim form suggests the agency is still mapping the full scope of the campaign.
For the gaming community, the warning is immediate. The FBI has explicitly asked players who downloaded any of the flagged Steam titles to report through the agency’s dedicated form. Anyone who installed Dashverse, Lunara, DashFPS, Tokenova, or Lampy should treat their machine as compromised — credentials, cookies, and wallet data may already be in someone else’s hands.
Wilkins faces federal charges that could carry significant prison time if convicted. The complaint stands as one of the more detailed public accounts of how federal investigators are combining old-fashioned physical searches with digital forensics to pursue crypto-related cybercrime — and a hard lesson that the weakest LLINK$8.34▼1.40% in a privacy-focused operation is often the person running it.
The FBI’s Seattle Division is still seeking victim information, and the investigation remains active as prosecutors move toward the next phase of the case.