CYREX
Nova Legends
Back to Portfolio
Security Testing

Nova Legends

Client:Plarium

Cyrex partnered with Plarium to deliver grey box penetration testing for Nova Legends, securing progression systems, in-game economy mechanics, and multiplayer features ahead of global mobile launch.

The Challenge

Securing a Competitive Mobile Action RPG Before Global Launch

Nova Legends is a sci-fi action RPG built around real-time arena battles, hero collection, and strategic progression. Players upgrade heroes, equip gear, and compete globally in multiplayer environments.

For Plarium, security validation ahead of global launch was critical.

The attack surface included:

  • Class and tier progression systems
  • Upgrade mechanics
  • Reward and mission logic
  • In-game shop transactions
  • Quest and storyline progression systems

In competitive multiplayer RPGs, weaknesses in progression or reward validation can disrupt game balance and player trust. Plarium required a structured penetration testing engagement to identify vulnerabilities before launch and reinforce system integrity across gameplay and economy layers.

The Cyrex Solution

Grey Box Penetration Testing Across Gameplay & Economy Systems

Cyrex conducted comprehensive grey box penetration testing, combining architectural insight with real-world attack simulation.

This approach enabled our engineers to evaluate gameplay systems contextually while testing exploit paths as an external attacker would.

Progression & Gameplay Validation

Our assessment included:

  • Class and tier systems
  • Upgrade mechanics
  • Mission systems
  • Quest progression
  • Reward distribution logic

We evaluated whether server-side validation properly enforced progression rules and prevented manipulation that could grant unfair advantages.

In-Game Shop & Economy Security

Given the importance of secure transactions, Cyrex tested:

  • In-game shop functionality
  • Payment-related flows
  • Reward issuance tied to purchases

The objective was to validate transaction handling and ensure economic systems were protected against tampering or logic flaws.

Vulnerability Identification & Remediation Guidance

Through structured testing, Cyrex identified potential vulnerabilities and exploit paths within core systems.

We provided:

  • Clear documentation of findings
  • Prioritized remediation guidance
  • Recommendations aligned with launch timelines

This allowed Plarium to address security concerns before public exposure.

The Outcome

Hardened Systems & Launch Confidence

  • Identification and mitigation of progression-related vulnerabilities
  • Strengthened validation across reward and upgrade systems
  • Improved security posture of in-game shop mechanics
  • Increased confidence in multiplayer system integrity

Client Feedback

Plarium Team

Cyrex has proven to be a deeply specialised security firm that is incredibly experienced in the gaming industry. They worked on a wide range of different assets, from multiplayer games to launchers and platforms, and consistently delivered excellent results exceeding industry standards. We’re looking forward to more fruitful collaborations.
Plarium Team
CYREX VERIFIED

Don't Let Players Find the Weakness

Your launch is months away. Hackers will find exploits in hours. Let our engineers secure your game before it's too late.

Response time: <24 hours • NDA included • No commitment required

Nova Legends — Case Study | Cyrex