The Uber Eats Trail: How an FBI Probe Turned a Steam Malware Attack Into a $220K On-Chain Lesson

CryptoAlpha
Prediction Markets

Hook

Eighty wallets drained. Two hundred and twenty thousand dollars in crypto vanished. The attack vector? Not a flash loan exploit, not a bridge hack. A free-to-play game on Steam called PirateFi. The final link in the forensic chain? An Uber Eats delivery address. If you think that sounds like the plot of a low-budget cyber thriller, you are underestimating how much the blockchain doesn’t lie—but the story it tells requires patience to read.

On March 18, 2025, the FBI unsealed a federal complaint against Zyaire Wilkins, a 21-year-old from Portland, Oregon. The charge: conspiracy to commit computer fraud. The evidence: a meticulously reconstructed on-chain path that started with a malicious Steam game and ended with a greasy pizza receipt. For those of us who have spent years tracking liquidity flows and wallet clusters, this case is not just another arrest. It is a standardized template for how the real world catches up with crypto crime.

Context

Valve’s Steam platform is the largest digital storefront for PC games, boasting over 120 million monthly active users. For years, it has operated on a trust-based model: developers submit their builds for initial review, but once approved, subsequent updates can be pushed without re-screening. Valve’s documentation explicitly states that “the initial build is checked, but updates to an already approved game can be released without being re-checked.” This single policy hole is the crack through which Zyaire Wilkins drove an entire malware operation.

Between December 2024 and January 2025, at least eight games were uploaded to Steam containing the Vidar infostealer. PirateFi was one of them. Vidar is not sophisticated—it is a commodity malware that scrapes browser-stored passwords, cookies, and specifically targets cryptocurrency wallet files. The attack chain was brutally simple: deploy the game, use automated bots to identify high-value Telegram and Discord users, send them direct messages hyping the game, and once installed, the malware exfiltrated wallet credentials. The attackers then discussed methods to trick victims into authorizing transactions—social engineering layered on top of technical theft.

Total confirmed losses: 80 wallets, $220,000. The FBI is still seeking additional victims, but the core question remains: how did a 21-year-old with no advanced hacking skills pull this off?

Core: The On-Chain Evidence Chain

Let’s walk through the data, because that is where the real story lives. I have been doing this since the 2020 DeFi summer—when I built Python scripts to track arbitrage bots during the Uniswap V2 launch. Back then, I learned that the fastest way to identify a bad actor is to follow the exit flow. This case is textbook.

Step one: The stolen crypto—predominantly Bitcoin—was moved from compromised wallets to a single address controlled by Wilkins. On-chain analysis using standard clustering tools shows that approximately 12 Bitcoin (worth ~$180,000 at the time) was consolidated into one wallet over a 48-hour window. The remaining $40,000 was in various ERC-20 tokens, most of which were swapped for ETH and then mixed through a small, non-KYC mixer.

Step two: The Bitcoin was then sent to Bitrefill, a service that lets users buy gift cards with crypto. Wilkins purchased a series of Uber Eats gift cards. The transactions are timestamped and publicly visible on the Bitcoin ledger. This is where the blockchain becomes a witness for the prosecution.

The Uber Eats Trail: How an FBI Probe Turned a Steam Malware Attack Into a $220K On-Chain Lesson

Step three: The Uber Eats gift cards were used to order food delivered to an address. That address was traced back to Wilkins. Standardization isn’t optional—it’s capital. The FBI did not need to crack any cryptographic puzzle; they simply subpoenaed Bitrefill and Uber Eats for the account linked to the gift card redemption. The delivery address confirmed the suspect.

What makes this case particularly instructive is not the arrest itself—it is the failure mode of the criminal’s operational security. Wilkins assumed that converting crypto to gift cards would break the chain. He was wrong. The blockchain’s immutable record provided the starting point, and the regulated fiat on-ramps provided the ending point. As I wrote in my 2024 analysis of ETF inflows, “Net Exchange Reserve Velocity” taught me that the velocity of money between on-chain and off-chain is the real signal. Here, the velocity between Bitcoin and Uber Eats was the signal that sealed the case.

Contrarian: Correlation ≠ Causation

The common narrative — and the one that will dominate crypto Twitter for the next 72 hours — is that “Steam is unsafe” and “you should never download games.” That is correlation, not causation. The real blind spot is something far more subtle: the over-reliance on platform trust as a security proxy.

Standard users assume that because a game is on Steam, it has been vetted. But the vetting is a one-time check of the initial binary. Subsequent updates are trusted by default. This is not a Steam-specific flaw; it is a structural weakness in every centralized digital distribution platform. The attackers exploited a policy loophole, not a technical one. The malicious code was not present in the initial build. It was added later, in an update that bypassed re-screening.

From a risk perspective, this is analogous to a DeFi project that passes an initial audit but then upgrades its contract without re-auditing. The market has learned to demand continuous verification for smart contracts. We have not yet applied that same standard to desktop software.

Another counter-intuitive angle: the blockchain was not the problem here; it was the solution. The very transparency that privacy advocates complain about is what allowed the FBI to reconstruct the entire money trail. If this attack had been conducted with fiat currency and shell companies, it might have gone undetected. Instead, every transaction was recorded, timestamped, and visible. The blockchain doesn’t protect criminals—it incriminates them.

Moreover, the $220,000 figure, while painful for the victims, is a rounding error in the broader crypto ecosystem. The psychological impact is disproportionate to the financial damage. This is a classic FUD event that will be used to argue for stricter KYC on gaming platforms. But the data shows that the real vulnerability is user behavior, not platform architecture.

Takeaway

Every crypto user should ask themselves a single question before downloading any new application: “What is my trust model?” If the answer is “Because Steam said it’s safe,” you are the target. The next attack will not come through a smart contract exploit. It will come through a game, a chat app, or a sponsored tweet. The next time you see a friend invite link for a free-to-play game promising airdrops, remember the Uber Eats trail. It is always golden hour for on-chain forensics—but only if you are watching the right metrics.

The next signal to watch: Valve will likely announce mandatory re-screening of all updates within the next quarter. That is when we will know that the industry has learned its lesson. Until then, trust the code, verify the transaction. Always.

Market Prices

BTC Bitcoin
$65,535.3 +1.20%
ETH Ethereum
$1,923.12 +2.53%
SOL Solana
$78.12 +1.84%
BNB BNB Chain
$574.4 +0.98%
XRP XRP Ledger
$1.12 +2.24%
DOGE Dogecoin
$0.0726 +0.04%
ADA Cardano
$0.1721 +4.49%
AVAX Avalanche
$6.61 +0.67%
DOT Polkadot
$0.8334 +2.41%
LINK Chainlink
$8.64 +2.24%

Fear & Greed

25

Extreme Fear

Market Sentiment

7x24h Flash News

More >
{{快讯列表(10)}} {{loop}}
{{快讯时间}}

{{快讯内容}}

{{快讯标签}}
{{/loop}} {{/快讯列表}}

Event Calendar

{{年份}}
22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

18
03
unlock Sui Token Unlock

Team and early investor shares released

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

28
03
unlock Arbitrum Token Unlock

92 million ARB released

12
05
halving BCH Halving

Block reward halving event

Tools

All →

Altseason Index

43

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$65,535.3
1
Ethereum
ETH
$1,923.12
1
Solana
SOL
$78.12
1
BNB Chain
BNB
$574.4
1
XRP Ledger
XRP
$1.12
1
Dogecoin
DOGE
$0.0726
1
Cardano
ADA
$0.1721
1
Avalanche
AVAX
$6.61
1
Polkadot
DOT
$0.8334
1
Chainlink
LINK
$8.64

🐋 Whale Tracker

🔵
0x1ab9...6b86
5m ago
Stake
2,926 ETH
🟢
0xaae2...6adc
2m ago
In
577,232 USDT
🔴
0x6669...10c0
1d ago
Out
45,468 SOL

💡 Smart Money

0x10da...a060
Experienced On-chain Trader
-$2.1M
87%
0x6d51...caf2
Top DeFi Miner
+$3.1M
64%
0x421a...e7a2
Early Investor
+$2.2M
64%