Loading market data...

FBI Used Uber Eats Orders, Google Cookies to Track Down Crypto Malware Suspect

FBI Used Uber Eats Orders, Google Cookies to Track Down Crypto Malware Suspect

The FBI identified the alleged financier of a Steam malware campaign by tracing over 500 Uber Eats deliveries, Google cookies, and phone records to a 21-year-old Florida man, according to a criminal complaint unsealed this month. Zyaire Dontaevious Zamarion Wilkins was arrested on July 14 and charged with conspiracy to obtain information by computer for private financial gain. Investigators say he supplied funding and marketing for a scheme that infected roughly 8,000 devices, accessed about 80 cryptocurrency wallets, and stole at least $220,000.

The $10,000 Trojan and the Steam Games

Wilkins allegedly put up $10,000 for a remote-access trojan that was hidden inside Steam games. Another participant created developer accounts and launched the titles. Users who downloaded the games found themselves with compromised machines. The malware targeted crypto wallets, draining funds from victims who had no idea their gaming session was the attack vector.

The complaint doesn't name the co-conspirator or the specific games. But the total haul — $220,000 in stolen crypto — makes it a modest but effective operation.

The Digital Trail: Uber Eats, Bitrefill, and Google

The break came when investigators traced a Bitcoin address used to buy gift cards on Bitrefill, including cards for Uber Eats. That Uber Eats account was registered with a phone number linked to Wilkins. Over two years — from March 2024 to May 2026 — the account placed more than 500 food orders, spending over $9,000. Every order was delivered to one of three addresses: two associated with the University of West Florida and Wilkins' family home in North Lauderdale.

The timing matched academic sessions. Orders went to the university addresses during class periods and to the family address during breaks. That pattern helped agents confirm the user was Wilkins, not a random buyer. They also used Google cookies, email records, Snapchat data, and mobile-location info to lock in the link.

The complaint notes that not every Uber Eats order or gift card purchase necessarily involved stolen funds. But the chain of evidence was enough to get a search warrant.

The Monero Seed Phrase Found in His Residence

On July 8, agents searched Wilkins' North Lauderdale home and seized a Monero seed phrase. The phrase unlocked a wallet with eight addresses and cumulative transaction activity of about 1,233 XMR — roughly $382,000 at current prices. That's nearly double the amount stolen in the malware campaign, suggesting the wallet may have held funds from other sources or that the campaign's total losses are higher than the $220,000 figure.

Prosecutors haven't alleged that all the XMR came from the Steam scheme. But the seed phrase sitting in his residence ties Wilkins directly to a significant crypto stash.

What Happens Next in Court

Wilkins remains in custody in Florida. His next court appearance hasn't been scheduled yet. The charge — conspiracy to obtain information by computer for private financial gain — carries a maximum sentence of five years in prison. The government is likely to argue for a longer term if it can prove the Monero wallet was funded by the stolen crypto.

One unresolved question: whether the co-conspirator who coded the malware and ran the Steam storefront will also be charged. The complaint references that person but doesn't name them.