Cyrex partnered with Wangyuan Shengtang to conduct black box penetration testing for Sword of Legends Online, securing its custom engine networking, MMORPG gameplay systems, and multiplayer services ahead of European release.
Sword of Legends Online is a story-driven MMORPG inspired by Chinese mythology, built on a custom engine and proprietary networking services. With sophisticated combat systems and deep progression mechanics, the game required validation of multiplayer and gameplay security prior to wider release.
Cyrex was engaged under a black box penetration testing model, meaning:
The scope focused on gameplay services and multiplayer systems, including:
In MMORPG environments built on custom engines, vulnerabilities in matchmaking, progression, or combat validation can disrupt game balance and player trust.
Cyrex conducted structured black box penetration testing, interacting with the title as an external malicious actor would.
Our engagement evaluated:
We tested whether gameplay actions could be manipulated or improperly authorized through crafted requests or networking exploitation.
Following the initial testing phase, Wangyuan Shengtang extended the engagement into a second iteration based on findings.
During testing, Cyrex identified several critical vulnerabilities affecting gameplay services. We delivered:
After patching, Cyrex conducted full sanity and regression testing to confirm that vulnerabilities were properly resolved and no new weaknesses were introduced.
Your launch is months away. Hackers will find exploits in hours. Let our engineers secure your game before it's too late.
Response time: <24 hours • NDA included • No commitment required