Early rate$2,400 of senior audit time for $500. Early members keep the rate as it climbs.$2,400 of senior audit time for $500See how →
Beecasino · Smart Contract Security AssessmentBeecasino Client Hub

Beecasino Web Game Pentest

Zealynx ran a one-week blackbox penetration test of the Beecasino Unity-built Web2 casino application (beecasino.virtual.tech). The site allows USDC bets against a smart-contract backend with deposit, withdraw, and finish flows. Two issues were identified: one High (decimals not handled by the application frontend, surfaced through Deposit and Withdraw flows and reflected directly in the session balance and rollup balance), and one Informational (Strict-Transport-Security not enforced). Both findings were acknowledged at the time of report publication.

TypescriptSmart Contract Code Review2024-07-12Zealynx methodology
Total findings
2
0 fixed · 2 acknowledged
Critical
00
High
01
Medium
00
Low + Info
01
02

Scope

1 file
Platform
- · Typescript
Methodology
File
beecasino.virtual.tech (Unity Web2 app)
03

Findings

click any row for the full write-up
04

Key Findings

  • Decimals not handled by the application frontend (High, acknowledged). The Deposit and Withdraw flows accepted decimal values, which were reflected immediately in the session balance and rollup balance. While bets themselves were rounded, the unconstrained decimal input on deposit / withdraw could lead to balance mishandling that the application is not expecting from user input, and the backend may not handle decimal rounding situations cleanly.
  • Strict-Transport-Security not enforced (Informational, acknowledged). The site did not return the HSTS header, leaving the browser without protection against protocol downgrade or SSL-stripping attempts on hostile networks.

Both findings were acknowledged by the Beecasino team at report publication.

05

Team & approval

Lead Auditor
Jose Fernando
@0xMrjory
06

Disclaimer

This audit is not an endorsement and does not constitute investment advice. Zealynx reviewed the codebase at the commits listed in section 02 over the engagement window. Findings are limited to issues identified within that scope and do not preclude the existence of other vulnerabilities. Subsequent code changes are not covered by this report unless the engagement is explicitly extended.

Download PDF (12p)
ZEALYNX SECURITY · published 2024-07-12
2 findings · Typescript