Paul McNally has been around consoles and computers since his parents bought him a Mattel Intellivision in 1980. He has been a prominent games journalist since the 1990s, spending over a decade as editor of popular print-based video games and computer magazines, including a market-leading PlayStation title. Paul has written high-end gaming content for GamePro, Official Australian PlayStation Magazine, PlayStation Pro, Amiga Action, Mega Action, ST Action, GQ, Loaded, and the The Mirror. He has also hosted panels at retro-gaming conventions and can regularly be found guesting on gaming podcasts and Twitch shows. Believing that the reader deserves actually to enjoy what they are reading is a big part of Paul’s ethos when it comes to gaming journalism, elevating the sites he works on above the norm.
Downloading a game through Steam feels fundamentally different from grabbing an executable from a random website. Gone are the days (pretty much) where we would all flood to Napster and Limewire and download Britney_Spears-Hit_Me_Baby_One_More_time.exe and consign our entire hard drive to death by a thousand pop-ups.
Steam is the official shop. It handles the payment, installation and updates, while Valve has already checked the developer and approved the game for release. Clicking the green Install button should therefore be the safe option. What do you mean, it isn’t?
Well, A recent FBI arrest has made that staple, everyday assumption considerably less comfortable for us all.

US authorities have arrested 21-year-old Florida resident Zyaire Dontaevious Zamarion Wilkins over an alleged operation that distributed malware through video games and used it to steal cryptocurrency. According to a federal criminal complaint, eight infected games compromised around 8,000 computers and provided access to approximately 80 cryptocurrency wallets, from which at least $220,000 was allegedly taken between May 2024 and February 2026. complaint describes the games as being distributed through a “popular digital distribution software company” without naming it directly. However, titles mentioned in the case, including BlockBlasters, Dashverse, Lunara and PirateFi, also appear in an FBI appeal specifically titled the Steam Malware Investigation and were available on the platform until earlier this year.
Wilkins has been accused of helping finance, acquire and promote the malware rather than necessarily writing all of it himself. The complaint alleges that the games were advertised through Discord, Telegram, X and LinkedIn, while bots were used to identify people believed to hold substantial amounts of cryptocurrency. result was not simply a few stolen Steam passwords. These games allegedly provided an entry point into victims’ computers, allowing private data, credentials and cryptocurrency information to be extracted.
So, should you now regard the hundreds of games sitting in your Steam library as potential malware? Not quite. However, the case does expose an uncomfortable gap between how safe Steam feels and what Valve’s approval process can realistically guarantee.
How did malware get onto Steam?
You probably already know that Steam reviews games before they are released.
Valve’s Steamworks documentation states that a game’s store page and product build must be submitted to its review team before launch. The checks include confirming that the game starts properly, supports its advertised features and complies with Steam’s rules around purchases and presentation.
I’ve been looking into “putting” a game on Steam of late, and each “app” you wish to submit via your account also requires a $100 payment (you do get it back if your game makes $1000), so there is a financial issue that helps prevent flooding the platform with nonsense.
However, that initial review is only part of the story. The same documentation contains a section headed “Review once; Update any time”. Once a game has been approved, its developer does not ordinarily need to submit every future update for another full review. Developers can continue changing the build and delivering patches to players.
That freedom is essential for legitimate developers because a studio cannot wait several days for Valve to manually approve every hotfix, balance adjustment or emergency crash repair. We have seen how quickly studios need to get fixes out immediately after launch, a lot of the time. Unfortunately, this necessity also creates an obvious opportunity for abuse. A developer can theoretically submit a harmless version of a game, pass Steam’s initial checks and establish a small audience. A later update can then introduce files or behaviour that were not present in the build Valve originally inspected. That appears to be what may have happened with BlockBlasters.
The 2D platform shooter was released in July 2025 and initially attracted hundreds of positive reviews. Security researchers at G DATA found that an update released on August 30 added files with several forms of malicious behaviour. The patch collected information from infected machines, searched for antivirus products, accessed Steam login information and communicated with an external server. e components were hidden inside password-protected archives, a technique that can make automated inspection more difficult. The malware was also configured to behave differently depending on what security software was running on the machine. game did not necessarily look like malware when it first appeared. By the time the dangerous update arrived, BlockBlasters had a functioning Steam page, user reviews and a history on the platform.
You, know, all the things you use without thinking to decide whether to purchase a game.
Not an isolated case
The FBI’s public appeal names seven games connected to its investigation: BlockBlasters, Chemia, Dashverse or DashFPS, Lampy, Lunara, PirateFi and Tokenova.
The agency believes users were primarily targeted between May 2024 and January 2026. PirateFi was removed from Steam in February 2025 after security software detected malware inside the game. Analysis found that the malicious program could copy browser cookies and potentially provide access to online accounts. People who had installed PirateFi subsequently received a warning from Valve recommending that they scan their computers.

Chemia presented another worrying possibility. Security researchers reported that the Early Access game appeared to be a legitimate project whose Steam build had been compromised by an outside threat actor.
Some malicious games may be created specifically as traps. Others could begin as genuine projects before a developer account, computer or update pipeline is compromised. Even an honest developer can become a route through which malware reaches players.
There have also been cases where criminals used the credibility of a Steam store page to direct players towards a supposed demo hosted elsewhere. Those files were not necessarily downloaded through Steam itself, but the presence of an official-looking store listing made the external download appear safer.
Is Steam still safe?
For the overwhelming majority of players and games, Steam remains a much safer place to obtain PC software than unofficial download sites, pirated releases, cheats or unfamiliar file-hosting services.The existence of several malicious titles does not mean that major releases from established publishers are suddenly likely to empty your bank account. Nor does it mean that every forgotten indie game in your library should immediately be deleted.
The sensible conclusion is that Steam is a distribution platform, not an absolute security guarantee. Valve can review developers, remove offending titles and warn known users after malware has been discovered. Security software on the player’s computer can also identify suspicious files or behaviour, but none of those protections is perfect.
Malware can be designed to avoid automated scanners. A clean game can receive a malicious update. A genuine developer can have an account compromised. Reviews can be manipulated, while a game promoted directly to a targeted victim may not need thousands of players to make the operation profitable.
The alleged campaign described by the FBI illustrates that last point particularly well. Around 8,000 infected devices is a tiny audience by the standards of a major PC game, but access to approximately 80 valuable cryptocurrency wallets was allegedly enough to produce six-figure losses.
Yes, it’s unlikely that this kind of attack will ever affect games you have actually heard of. Big studios are extremely unlikely to be compromised in this manner if you are one of the 40 million who bought Cyberpunk 2077, for example, that is perfectly safe. Those viral games that pop up out of nowhere though? Maybe just check them over for piece of mind.
Steam Guard cannot protect your entire computer
Enabling Steam Guard remains important. It adds another layer of protection to a Steam account and can make it harder for someone with a stolen password to sign in, but what it does not do is turn every game into a sandboxed application. A Windows game can access files and resources available to the user account running it. If an information stealer successfully executes, the target may include browser data, stored passwords, login sessions, cryptocurrency wallets and other material completely separate from Steam.
Two-factor authentication on Steam cannot protect a cryptocurrency wallet or email account if the relevant credentials have already been taken directly from the computer. Players should therefore treat Steam Guard as their account protection rather than malware protection. You still need Windows Security or another reputable security product running and fully updated.
Microsoft says Defender’s real-time protection scans files and programs as they are accessed or executed. It also offers full and offline scanning options when a user suspects that malware may already be present. An antivirus warning should absolutely not automatically be dismissed as a false positive simply because the affected file arrived through Steam. In many ways, that’s when you should take it more seriously.
What should Steam users look out for?
The games connected to this investigation were generally obscure releases rather than household names. Several were promoted directly through social networks and messaging platforms, sometimes to users selected because they were believed to own cryptocurrency.
Be wary when an unknown developer contacts you directly and offers payment, employment or some other incentive to download its game. A game being present on Steam does not prove that the person messaging you represents its real developer. Avoid downloading demos, patches or launchers from external links when the same files are supposedly available through Steam. A Steam store page can be copied, compromised or used to add credibility to files hosted elsewhere.
Check the developer’s history, community discussions and recent reviews rather than relying solely on the overall review score. A game that behaved normally for several weeks could begin generating security complaints after a particular update. Most importantly, never disable antivirus protection or add exclusions simply because an unfamiliar game refuses to launch. Malware frequently attempts to persuade users that security warnings are mistakes.
What to do if you installed one of the named games
Anyone who installed BlockBlasters, Chemia, Dashverse or DashFPS, Lampy, Lunara, PirateFi or Tokenova during the period identified by the FBI should take the matter seriously. Removing the game from Steam may not remove files that the malware placed elsewhere on the computer.
Valve’s own account recovery instructions say users should scan their computer for viruses, keyloggers and spyware before resetting a compromised Steam password. It also recommends changing the password attached to the account’s email address once the device has been secured. Microsoft recommends running a full scan and says Defender Offline provides its most thorough scan option. Passwords should then be changed from a device believed to be clean, beginning with email, financial accounts and Steam.
Cryptocurrency users should also inspect their wallets and transaction histories. Anyone who believes they were affected by the named games can submit information through the FBI’s Steam Malware Investigation form. The agency says victims may be eligible for services, restitution and legal rights, although submitting information does not guarantee that stolen funds will be recovered.
Valve’s difficult security problem
Valve is unlikely to solve this simply by adding a longer manual review before each game launches. BlockBlasters demonstrates why. The malicious files reportedly arrived through an update roughly a month after release. Reviewing the original build more aggressively might not have found code that was not there yet.
Requiring every patch to receive full approval would create significant delays for developers and could leave broken or vulnerable games waiting for essential fixes. The more realistic question is whether Valve should subject updates from new or unusual developers to greater automated analysis, restrict sudden changes to executable files, monitor games that begin contacting unfamiliar servers, or require stronger authentication before developers can publish new builds.
Steam has spent years teaching PC players that installing a game can be almost frictionless. That convenience is one of the platform’s greatest achievements, but it also means players rarely stop to consider that they are granting an unfamiliar program access to their computer.
Your Steam library is not inherently unsafe. The vast majority of games inside it are not waiting to become malware, and panic would be a raging overreaction, but blind trust is no longer a particularly sensible response either. The green Install button means that a game is being delivered by Steam. It does not necessarily mean that every line of code inside it has been inspected, understood and declared harmless.
For most users, that distinction will never matter. For roughly 8,000 alleged victims in the FBI’s investigation, it already has.