FBI used Google cookies, 500 food orders and a Monero seed phrase to identify Steam malware funder

3 hours ago 2

A 15-page federal criminal complaint details how investigators combined a Bitcoin trail with Google cookies, phone records, and more than 500 Uber Eats deliveries to identify Zyaire Dontaevious Zamarion Wilkins as the alleged financier and marketer of a Steam malware campaign. A later search uncovered a Monero seed phrase tied to roughly $382,000 in cumulative transaction activity.

Federal agents arrested Wilkins, 21, in Florida on July 14. The complaint, entered the following day, charges him with one count of conspiracy to obtain information by computer for private financial gain.

The allegations concern the same eight-game campaign CryptoSlate reported on July 19. The FBI and the complaint allege that the campaign infected approximately 8,000 devices, accessed about 80 cryptocurrency wallets and stole at least $220,000.

The complaint also lays out how investigators connected campaign funding to Wilkins and what they found after obtaining a residential search warrant.

Messages describe Wilkins’ alleged financing role

Prosecutors allege that another participant created the developer accounts and launched the games, while Wilkins supplied funding and helped market them.

The games were promoted through Discord, Telegram, X and LinkedIn, while bots allegedly identified people with large crypto holdings for targeted messages.

Messages cited in the complaint include discussions about spending $10,000 on a remote-access trojan, embedding malware in games and persuading more people to download them.

Subject #1 allegedly told investigators that Wilkins provided launch and marketing funds in exchange for a share of stolen cryptocurrency and access to victims’ private information.

Bitcoin payments opened a wider identity trail

Investigators found the Bitcoin address in messages seized from an unnamed alleged co-conspirator identified as “Subject #1,” according to the complaint.

Wilkins allegedly supplied the address to receive funding for a cryptocurrency-draining campaign, and investigators verified that the address received an approximately $10,000 payment on the day it was supplied.

The complaint says investigators subsequently identified payments from the same address to Bitrefill, which allows customers to purchase gift cards and other digital products with cryptocurrency.

Bitrefill records connected the payments to one account that had purchased more than 150 gift cards, including Uber Eats cards. The account was registered using an email address that investigators then examined through records obtained from Google.

Google records allegedly linked that address through browser cookies to other accounts. One appeared to use Wilkins’ initials and was associated with a University of West Florida student, while another listed a phone number as its recovery number.

Investigators also linked that number to an email address containing Wilkins’ name, a Snapchat account that previously displayed his name, and a T-Mobile account registered at an address associated with his family.

More than 500 food orders narrowed the trail to three addresses

Uber identified one account associated with the Uber Eats gift cards, according to the complaint. That account was registered with the same phone number found in the other records.

CryptoSlate Daily Brief

Daily signals, zero noise.

Market-moving headlines and context delivered every morning in one tight read.

5-minute digest 100k+ readers

Free. No spam. Unsubscribe any time.

Whoops, looks like there was a problem. Please try again.

You’re subscribed. Welcome aboard.

Further Uber records showed that the account placed more than 500 food-delivery orders between March 2024 and May 2026, spending over $9,000. Every order went to one of three locations: two addresses associated with the University of West Florida and Wilkins’ North Lauderdale address.

The timing also followed an alleged pattern. Deliveries to the university addresses largely occurred while classes were in session, while orders outside those periods went to Wilkins’ family address. The complaint says approximately 15 deliveries went to the North Lauderdale address between May 6 and May 17, 2026.

The Uber records formed one part of a wider identity chain that included Bitrefill account data, Google cookies, email addresses, phone records, Snapchat data, and mobile-location information.

The complaint does not establish that every payment or food order involved stolen funds.

Search uncovered a Monero seed phrase tied to $382,000 in activity

FBI agents searched Wilkins’ North Lauderdale residence on July 8 and seized laptops, phones, other digital devices, and three cryptocurrency wallet seed phrases, according to the complaint.

One seed phrase was associated with a Monero wallet containing eight addresses. Investigators said the wallet’s transaction history showed that Wilkins had sent or received approximately 1,233 XMR, valued at roughly $382,000.

The $382,000 figure reflects cumulative transaction activity described in the complaint. It is separate from the alleged victim-loss estimate of at least $220,000, and the filing does not characterize all 1,233 XMR as stolen funds or as Wilkins’ wallet balance.

The complaint’s identification narrative relies on the Bitcoin address and records from Bitrefill, Google, Uber, Snap, T-Mobile, and other providers. Investigators obtained the Monero evidence after executing the residential search warrant, using a seized seed phrase rather than tracing Wilkins through Monero’s public transaction history.

Wilkins is presumed innocent unless proven guilty. TechCrunch reported that his attorney did not respond to a request for comment. Local 10 reported that Valve had not responded to its questions about the case and Steam’s security measures by publication.

Read Entire Article
Patroli | Crypto | | |