Cyrex partnered with Mythical Games to conduct grey box penetration testing for Blankos Block Party, securing gameplay systems, backend services, matchmaking, and in-game transactions across its multiplayer ecosystem.
Blankos Block Party is a vibrant, open-world multiplayer game centered around player creation, social interaction, and curated digital collections. With gameplay spanning exploration, mini-games, world-building tools, and in-game transactions, the title relies on both secure backend services and validated gameplay systems.
For Mythical Games, security validation needed to cover:
In a multiplayer environment with user-generated content and economic components, vulnerabilities can impact fairness, progression, and platform integrity. Mythical required structured penetration testing to assess exploit risks across gameplay and backend layers.
Cyrex conducted comprehensive grey box penetration testing, combining architectural insight with real-world attack simulation.
The objective was to validate server-side controls and identify weaknesses across both live services and gameplay systems.
Our testing included evaluation of:
We assessed whether gameplay actions were properly validated server-side and resistant to manipulation.
Cyrex also evaluated:
The goal was to ensure that economic and social systems were secured against tampering, improper access, or logic flaws.
During testing, Cyrex identified vulnerabilities across multiple services, several of which were considered high severity by the development team.
Following remediation:
This ensured that fixes were effective and no additional issues were introduced.
“It was a pleasure working with the security team. They are extremely knowledgeable, capable, and very flexible; partnering with us and adjusting processes and communication to suit our needs. We are very much looking forward to an ongoing relationship between our teams.”
Your launch is months away. Hackers will find exploits in hours. Let our engineers secure your game before it's too late.
Response time: <24 hours • NDA included • No commitment required