Login
Sign Up
Woofun AI reports that the FBI is actively seeking victims of a sophisticated malware campaign embedded within eight Steam games, a case highlighting how crypto custody vulnerabilities can be exploited before a wallet interface is even accessed. This investigation, detailed in a federal complaint covered by Local 10, reveals that the threat vector originated not from direct wallet hacking, but from compromised software distribution channels.
The attack mechanics involved a coordinated social engineering effort across Discord, Telegram, X, and LinkedIn, where bots targeted users with significant crypto holdings. This campaign infected approximately 8,000 devices and granted unauthorized access to roughly 80 crypto wallets, resulting in thefts totaling at least $220,000. Per Woofun AI, the group utilized these platforms to distribute the malicious games, subsequently capturing private data and credentials while also tricking victims into authorizing transactions that drained their assets.
Structurally, this incident underscores that an official marketplace cannot serve as the sole trust boundary for digital asset security. Keeping wallet secrets and authenticated sessions isolated from gaming endpoints limits the reach of infostealer malware, while rigorous review of transaction prompts mitigates the risk of approving malicious transfers. These controls are essential complements to marketplace screening, as they address the distinct threats posed by compromised endpoints and social engineering.
The forensic trail ultimately exposed the reverse side of the operation, with investigators following Bitcoin payments from scheme-linked wallets to Bitrefill, where over 150 digital gift cards were purchased, primarily for Uber Eats. A subpoena to Uber connected these cards to an account with deliveries to addresses associated with Wilkins. While blockchain transparency did not prevent the initial theft, it preserved a traceable path until the funds touched an identity-linked service, demonstrating that software distribution is a critical component of custody security and that on-chain records combined with off-ramp data remain vital investigative evidence.