Steam Game Lure Led to $220K Crypto Theft

Hack Read · Medium sophistication
Last updated July 30, 2026

Federal investigators arrested a Florida man accused of helping push malware disguised as video games, which infected about 8,000 devices and enabled theft from cryptocurrency wallets. The games were promoted through social platforms and direct messages aimed at people believed to hold significant crypto, convincing them to install the infected titles.

How the attack worked

A group allegedly financed and promoted malware hidden inside playable video games, affecting about 8,000 devices and stealing at least $220,000 in cryptocurrency. Named titles tied to the campaign include BlockBlasters, Chemia, Dashverse/DashFPS, Lampy, Lunara, PirateFi and Tokenova. Rather than relying on a single delivery method, the operators spread these games across Discord, Telegram, X and LinkedIn, using bots to locate people believed to hold substantial amounts of cryptocurrency and send them direct messages encouraging installation.

Once a target installed the game, the malware collected passwords, browser cookies, saved form data, account tokens, and other private information from the device. The stolen data was then searched for access to cryptocurrency accounts, and any wallets the attackers could enter were drained.

Why it succeeded

The lure worked because it blended into normal online behavior for the target audience. Gamers and crypto holders regularly receive links to new titles from communities, streamers, and social platforms, so an unsolicited but plausible-looking game recommendation did not immediately stand out. Using bots to specifically target people who appeared to hold significant crypto also increased the odds that a successful infection would yield a meaningful payout, rather than spreading malware indiscriminately.

What to watch for

  • Unsolicited direct messages on Discord, Telegram, X or LinkedIn urging you to install a game or application
  • Messages that seem to reference or assume your interest in cryptocurrency
  • Game or publisher promotion arriving through chat spam or bot-driven outreach rather than a trusted storefront or known community source
  • Pressure to install and test software quickly, especially from an unfamiliar sender

How to build resistance

Treat unsolicited messages urging software installation as high-risk, even when they arrive on platforms you normally trust for work or networking, such as LinkedIn or Discord. Assume that any "free game" install could expose saved passwords, browser cookies, and session tokens, and avoid storing crypto seed phrases or private keys on everyday computers used for browsing or gaming.

If a suspicious title has already been installed, treat it as an active incident: isolate the device, avoid reusing it to reset credentials, and instead change exposed passwords from a separate, known-clean device. If seed phrases or private keys were stored on the infected machine, move remaining funds to a new wallet as soon as possible. Organizations should extend awareness training beyond phishing emails to cover gaming and social platform lures, since employees who hold or discuss cryptocurrency personally can become entry points even when the compromise happens on a personal device.

Key findings

  • Suspect allegedly helped finance and promote malware hidden inside video games, affecting about 8,000 devices and stealing at least $220,000 in cryptocurrency.
  • The infected games were promoted on Discord, Telegram, X and LinkedIn, including via bots that targeted people believed to hold substantial cryptocurrency.
  • Once installed, the malware stole passwords, browser cookies, saved form data, and account tokens, which were then used to access and drain crypto wallets.
  • Named games tied to the campaign include BlockBlasters, Chemia, Dashverse/DashFPS, Lampy, Lunara, PirateFi and Tokenova.

Who’s being targeted

  • Commonly targeted roles: All employees (personal device hygiene), Executives, Finance/Accounting, IT/Helpdesk, Staff active on Discord/Telegram/LinkedIn, Employees who hold or manage cryptocurrency.
  • Affected industries: Cryptocurrency/financial services, Gaming and digital distribution platforms, Social media and messaging platforms, Individual consumers (gamers/crypto holders).
  • Attack channels: discord, linkedin.
  • Impersonated: Indie game promoter/publisher on a gaming community server, Professional-looking game marketer/recruiter-style profile.

Red flags to watch for

  • Unsolicited DM pushing you to install software
  • Message appears targeted because of your crypto holdings
  • Game/publisher promoted via chat spam/bots rather than trusted channels
  • LinkedIn used for software installs unrelated to your job
  • Pressure to install quickly or “test” something
  • Sender appears to have found you based on your crypto interest/holdings
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did the fake game campaign steal cryptocurrency?

Once installed, the malware collected passwords, browser cookies, saved form data, and account tokens, which attackers then used to search for and drain accessible crypto wallets.

Which platforms were used to promote the infected games?

The games were promoted through Discord, Telegram, X and LinkedIn, with bots used to identify and message people believed to hold substantial cryptocurrency.

What should someone do if they installed one of the malicious games?

Victims should change exposed passwords from a clean device and transfer remaining crypto funds to a new wallet if their seed phrase or private keys were stored on the infected computer.

Which games were tied to this campaign?

Named games linked to the campaign include BlockBlasters, Chemia, Dashverse/DashFPS, Lampy, Lunara, PirateFi and Tokenova.

Read the video transcript

Imagine a Discord DM: “Hey, saw you’re into crypto and gaming, try this new title, BlockBlasters.” That’s exactly how malware games like BlockBlasters, Chemia, Dashverse, Lampy, Lunara, PirateFi and Tokenova helped steal over two hundred twenty thousand dollars in crypto. Once you install, the “game” quietly grabs your passwords, browser cookies, saved forms, and account tokens, then uses them to drain any crypto wallets it can reach. If you get an unsolicited Discord or LinkedIn message pushing a game install, don’t click, report it and only download software from platforms you already trust.

Similar attacks

Fake GitHub Repos and Trojan Apps Steal Data

Fake GitHub Repos and Trojan Apps Steal Data

Researchers described two active social-engineering-driven malware campaigns: one uses trojanized “popular” remote-user apps (e.g., Zoom/WebEx lookalikes) to…

July 17, 2026