Beecasino Web Game Pentest
Zealynx ran a one-week blackbox penetration test of the Beecasino Unity-built Web2 casino application (beecasino.virtual.tech). The site allows USDC bets against a smart-contract backend with deposit, withdraw, and finish flows. Two issues were identified: one High (decimals not handled by the application frontend, surfaced through Deposit and Withdraw flows and reflected directly in the session balance and rollup balance), and one Informational (Strict-Transport-Security not enforced). Both findings were acknowledged at the time of report publication.
Scope
1 fileFindings
click any row for the full write-upKey Findings
- Decimals not handled by the application frontend (High, acknowledged). The Deposit and Withdraw flows accepted decimal values, which were reflected immediately in the session balance and rollup balance. While bets themselves were rounded, the unconstrained decimal input on deposit / withdraw could lead to balance mishandling that the application is not expecting from user input, and the backend may not handle decimal rounding situations cleanly.
- Strict-Transport-Security not enforced (Informational, acknowledged). The site did not return the HSTS header, leaving the browser without protection against protocol downgrade or SSL-stripping attempts on hostile networks.
Both findings were acknowledged by the Beecasino team at report publication.
Team & approval
Disclaimer
This audit is not an endorsement and does not constitute investment advice. Zealynx reviewed the codebase at the commits listed in section 02 over the engagement window. Findings are limited to issues identified within that scope and do not preclude the existence of other vulnerabilities. Subsequent code changes are not covered by this report unless the engagement is explicitly extended.