The FBI has arrested a 21-year-old Florida man accused of operating a malware campaign that allegedly stole around $220,000 in cryptocurrency by distributing infected video games through Steam. According to federal investigators, the scheme ran for nearly two years and targeted users by hiding password-stealing malware inside downloadable games.
The indictment alleges the suspect worked with multiple co-conspirators to compromise victims’ computers after they installed the affected titles.
According to the U.S. Department of Justice, investigators identified several games that allegedly contained the malware, including PirateFi, Lunara, BlockBlasters, and Lampy. In Lampy’s case, the malicious software was reportedly introduced through a post-launch update.

The malware allegedly collected saved passwords from victims’ computers, allowing attackers to access cryptocurrency wallets and steal digital assets. Authorities also claim the group promoted the infected games through social media and used automated bots to target users believed to own significant cryptocurrency holdings.
Investigators ultimately traced the stolen Bitcoin after it was allegedly used to purchase gift cards that paid for services such as Uber Eats, helping identify the suspect.
The affected games were removed from Steam earlier this year as the FBI investigated the malware distribution. The case highlights the growing cybersecurity risks facing digital game marketplaces and serves as a reminder for players to download software only from trusted developers and enable additional security measures, including two-factor
