Introduction
We express our gratitude to the XGame team for the collaborative engagement that enabled the execution of this dApp Security Assessment.
xGame is a betting game where players place cryptocurrency bets and exit before the crash point to win payouts based on their exit multiplier.
Document | |
|---|---|
| Name | dApp Code Review and Security Analysis Report for XGame |
| Audited By | Abdelfattah Ibrahim |
| Approved By | Stephen Ajayi |
| Website | https://xgame.io→ |
| Changelog | 15/07/2025 - Preliminary Report |
| Changelog | 11/08/2025 - Final Report |
| Platform | Base, PulseChain |
| Language | TypeScript |
| Tags | dApp |
| Methodology | https://hackenio.cc/dApp_methodology→ |
Document
- Name
- dApp Code Review and Security Analysis Report for XGame
- Audited By
- Abdelfattah Ibrahim
- Approved By
- Stephen Ajayi
- Website
- https://xgame.io→
- Changelog
- 15/07/2025 - Preliminary Report
- Changelog
- 11/08/2025 - Final Report
- Platform
- Base, PulseChain
- Language
- TypeScript
- Tags
- dApp
- Methodology
- https://hackenio.cc/dApp_methodology→
Review Scope | |
|---|---|
| Repository | https://github.com/xgame-io/crash-monorepo/→ |
| Initial Commit | 5b8c0d3f9e9dd538f651de8e8129ded5ac8f9140 |
| Final Commit | 9644ec48cfad400a787ad3f5a3a69b335a38ff70 |
Review Scope
- Initial Commit
- 5b8c0d3f9e9dd538f651de8e8129ded5ac8f9140
- Final Commit
- 9644ec48cfad400a787ad3f5a3a69b335a38ff70
Audit Summary
The system users should acknowledge all the risks summed up in the risks section of the report
Documentation quality
The codebase has comments, providing clear and detailed information while navigating through the code.
The project is well-organized into packages, making it easy to navigate and understand.
Areas to Improve: Add more tests and a detailed Readme file.
Code quality
Configuration files for ESLint and Prettier ensure consistent code style and formatting.
Code is divided into packages and modules, promoting reusability and maintainability.
System Overview
xGame is a blockchain-based betting application implemented as a monorepo containing multiple microservices. The platform operates a crash game where players place cryptocurrency bets and attempt to exit before the game reaches a random crash point. The architecture consists of four main backend services: an Oracle service that manages game logic and real-time state, an Identity service handling user authentication via SIWE (Sign-In with Ethereum) and JWT tokens, a Price service providing cryptocurrency price feeds and gas estimates, and an Indexer service monitoring blockchain transactions. The frontend is built with React and TypeScript, featuring real-time WebSocket communication for game updates and chat functionality, along with Web3 wallet integration for blockchain interactions.
Findings
Code ― | Title | Status | Severity | |
|---|---|---|---|---|
| F-2025-1167 | Redis Lacks Authentication | fixed | High | |
| F-2025-1167 | JWT Refresh Token Does Not Expire as Intended | fixed | Medium | |
| F-2025-1137 | Weak Rate Limiting Protection | fixed | Medium | |
| F-2025-1168 | Outdated and Vulnerable Dependencies | fixed | Low | |
| F-2025-1167 | Missing protection against Clickjacking | fixed | Low | |
| F-2025-1137 | Insecure Cross-Origin Resource Sharing (CORS) Configuration | fixed | Low | |
| F-2025-1168 | Missing Important Compiler Flags | fixed | Observation | |
| F-2025-1168 | Missing HTTP security headers | fixed | Observation |
Appendix 1. Severity Definitions
Severity | Description |
|---|---|
Critical | These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm. |
High | These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach. |
Medium | These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention. |
Low | These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation. |
Severity
- Critical
Description
- These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.
Severity
- High
Description
- These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.
Severity
- Medium
Description
- These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.
Severity
- Low
Description
- These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
Appendix 2. Scope
The scope of the project includes the following repository:
Scope Details | |
|---|---|
| Repository | https://github.com/xgame-io/crash-monorepo/→ |
| Initial Commit | 5b8c0d3f9e9dd538f651de8e8129ded5ac8f9140 |
| Final Commit | 9644ec48cfad400a787ad3f5a3a69b335a38ff70 |
| Assets | client/ |
| common/ | |
| frontend/ | |
| identity/ | |
| oracle/ |
Scope Details
- Initial Commit
- 5b8c0d3f9e9dd538f651de8e8129ded5ac8f9140
- Final Commit
- 9644ec48cfad400a787ad3f5a3a69b335a38ff70
- Assets
- client/
- common/
- frontend/
- identity/
- oracle/