Q2 2026 Security & Compliance Report67 incidents, $764M in losses, 88% from operational failures.
Get the report →

Audit name:

[dApp] Xgame | Crash Monorepo | Jun2025

Date:

Aug 11, 2025

Table of Content

→Introduction
→Audit Summary
→System Overview
→Findings
→Appendix 1. Severity Definitions
→Appendix 2. Scope
→Disclaimer

Want a comprehensive audit report like this?

Introduction

We express our gratitude to the XGame team for the collaborative engagement that enabled the execution of this dApp Security Assessment.

xGame is a betting game where players place cryptocurrency bets and exit before the crash point to win payouts based on their exit multiplier.

Document

NamedApp Code Review and Security Analysis Report for XGame
Audited ByAbdelfattah Ibrahim
Approved ByStephen Ajayi
Websitehttps://xgame.io→
Changelog15/07/2025 - Preliminary Report
Changelog11/08/2025 - Final Report
PlatformBase, PulseChain
LanguageTypeScript
TagsdApp
Methodologyhttps://hackenio.cc/dApp_methodology→
  • Document

    Name
    dApp Code Review and Security Analysis Report for XGame
    Audited By
    Abdelfattah Ibrahim
    Approved By
    Stephen Ajayi
    Changelog
    15/07/2025 - Preliminary Report
    Changelog
    11/08/2025 - Final Report
    Platform
    Base, PulseChain
    Language
    TypeScript
    Tags
    dApp

Review Scope

Repositoryhttps://github.com/xgame-io/crash-monorepo/→
Initial Commit5b8c0d3f9e9dd538f651de8e8129ded5ac8f9140
Final Commit9644ec48cfad400a787ad3f5a3a69b335a38ff70

Audit Summary

8Total Findings
8Resolved
0Accepted
0Mitigated

The system users should acknowledge all the risks summed up in the risks section of the report

Documentation quality

  • The codebase has comments, providing clear and detailed information while navigating through the code.

  • The project is well-organized into packages, making it easy to navigate and understand.

  • Areas to Improve: Add more tests and a detailed Readme file.

Code quality

  • Configuration files for ESLint and Prettier ensure consistent code style and formatting.

  • Code is divided into packages and modules, promoting reusability and maintainability.

System Overview

xGame is a blockchain-based betting application implemented as a monorepo containing multiple microservices. The platform operates a crash game where players place cryptocurrency bets and attempt to exit before the game reaches a random crash point. The architecture consists of four main backend services: an Oracle service that manages game logic and real-time state, an Identity service handling user authentication via SIWE (Sign-In with Ethereum) and JWT tokens, a Price service providing cryptocurrency price feeds and gas estimates, and an Indexer service monitoring blockchain transactions. The frontend is built with React and TypeScript, featuring real-time WebSocket communication for game updates and chat functionality, along with Web3 wallet integration for blockchain interactions.

Findings

F-2025-1167Redis Lacks Authentication
Status
fixed
Severity

High
F-2025-1167JWT Refresh Token Does Not Expire as Intended
Status
fixed
Severity

Medium
F-2025-1137Weak Rate Limiting Protection
Status
fixed
Severity

Medium
F-2025-1168Outdated and Vulnerable Dependencies
Status
fixed
Severity

Low
F-2025-1167Missing protection against Clickjacking
Status
fixed
Severity

Low
F-2025-1137Insecure Cross-Origin Resource Sharing (CORS) Configuration
Status
fixed
Severity

Low
F-2025-1168Missing Important Compiler Flags
Status
fixed
Severity

Observation
F-2025-1168Missing HTTP security headers
Status
fixed
Severity

Observation
Code
―
Title
Status
Severity
F-2025-1167Redis Lacks Authentication
fixed

High
F-2025-1167JWT Refresh Token Does Not Expire as Intended
fixed

Medium
F-2025-1137Weak Rate Limiting Protection
fixed

Medium
F-2025-1168Outdated and Vulnerable Dependencies
fixed

Low
F-2025-1167Missing protection against Clickjacking
fixed

Low
F-2025-1137Insecure Cross-Origin Resource Sharing (CORS) Configuration
fixed

Low
F-2025-1168Missing Important Compiler Flags
fixed

Observation
F-2025-1168Missing HTTP security headers
fixed

Observation
1-8 of 8 findings

Protect your dApp with insights like these.

Appendix 1. Severity Definitions

Severity

Description

Critical
These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

High
These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

Medium
These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

Low
These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.
  • Severity

    Critical

    Description

    These issues present a major security vulnerability that poses a severe risk to the system. They require immediate attention and must be resolved to prevent a potential security breach or other significant harm.

    Severity

    High

    Description

    These issues present a significant risk to the system, but may not require immediate attention. They should be addressed in a timely manner to reduce the risk of the potential security breach.

    Severity

    Medium

    Description

    These issues present a moderate risk to the system and cannot have a great impact on its function. They should be addressed in a reasonable time frame, but may not require immediate attention.

    Severity

    Low

    Description

    These issues present no risk to the system and typically relate to the code quality problems or general recommendations. They do not require immediate attention and should be viewed as a minor recommendation.

Appendix 2. Scope

The scope of the project includes the following repository:

Scope Details

Repositoryhttps://github.com/xgame-io/crash-monorepo/→
Initial Commit5b8c0d3f9e9dd538f651de8e8129ded5ac8f9140
Final Commit9644ec48cfad400a787ad3f5a3a69b335a38ff70
Assetsclient/
common/
frontend/
identity/
oracle/

Assets in Scope

client - › client
common - › common
frontend - › frontend
identity - › identity
oracle - › oracle
XGame - XGame

Disclaimer