CYREX
Back to Portfolio
Security Testing

Scavengers

Client:Improbable Worlds Limited & Midwinter Entertainment

Cyrex partnered with Improbable to deliver white box penetration testing for Scavengers, securing Unreal Engine networking, live services, and multiplayer systems across PC and console platforms.

The Challenge

Securing a Hybrid PvE/PvP Survival Shooter Built on Unreal Engine

Scavengers combines sandbox-style PvE survival with class-based PvP combat in a free-to-play action shooter. Built on Unreal Engine and deployed across PC and console, the title relies heavily on secure multiplayer networking and live services infrastructure.

For Improbable and Midwinter Entertainment, the security scope spanned:

  • Unreal Engine networking services
  • Live backend services
  • Combat and physics systems
  • Class and tier progression
  • In-game shop functionality
  • VOIP and chat systems
  • Player and inventory management

In hybrid PvE/PvP environments, vulnerabilities in progression systems, combat validation, or multiplayer services can directly impact competitive balance and player trust. The development teams required a deep, code-level security assessment prior to launch.

The Cyrex Solution

White Box Penetration Testing Across Engine & Live Services

Cyrex conducted comprehensive white box penetration testing, reviewing full source code and internal implementations across gameplay and live service layers.

This methodology enabled a detailed assessment of server-side validation, networking flows, and integration points within Unreal Engine.

Unreal Engine & Gameplay Validation

Our engagement focused on:

  • Physics and shooting systems
  • Tier and class progression logic
  • Inventory handling
  • Player management systems

We evaluated whether gameplay actions were properly validated server-side and resistant to client-side manipulation.

Live Services & Multiplayer Infrastructure

Cyrex also assessed:

  • Matchmaking infrastructure
  • In-game shop logic
  • VOIP and chat systems
  • Backend API integrations

By simulating real-world attack scenarios and reviewing internal implementations, we identified potential exploit paths and logic weaknesses that could impact fairness or service stability.

Detailed Documentation & Remediation Guidance

The white box approach enabled:

  • Full source code review
  • Identification of active vulnerabilities
  • Detection of weaker architectural points
  • Clear, prioritized remediation guidance

This allowed the Improbable team to address issues efficiently before public exposure.

The Outcome

Hardened Multiplayer Systems Before Launch

  • Identification and mitigation of potential exploit paths
  • Reinforced validation across Unreal Engine networking systems
  • Improved security posture of progression and shop mechanics
  • Increased launch confidence across PC and console platforms

Client Feedback

The Improbable Team

Cyrex have been consistently great security testing partners for us across a number of complex projects. Improbable often asks Cyrex to test brand new technology, posing a real challenge to testers to get up to speed with our cutting edge software, let alone find vulnerabilities within it. And yet we are consistently impressed by the quality of work we see. Cyrex keeps us one step ahead of our attackers.
The Improbable Team
CYREX VERIFIED

Don't Let Players Find the Weakness

Your launch is months away. Hackers will find exploits in hours. Let our engineers secure your game before it's too late.

Response time: <24 hours • NDA included • No commitment required

Scavengers — Case Study | Cyrex