Early rate$2,400 of senior audit time for $500. Early members keep the rate as it climbs.$2,400 of senior audit time for $500See how →
Hopium · Smart Contract Security AssessmentHopium Client Hub

Hopium Web Game Pentest

Zealynx ran a one-week blackbox penetration test of Hopium, a Web2 coin-flip game running on Virtual Rollups ZeroGas infrastructure. Five issues were identified: three Medium (the deposit function should be disabled before starting a game; lack of input validation in the deposit function triggers zero-value transactions and gas griefing; decimals are not required in the deposit function), and two Informational (Strict-Transport-Security not enforced; the reset function is redundant). All five findings were acknowledged at report publication.

TypescriptSmart Contract Code Review2024-07-12Zealynx methodology
Total findings
5
0 fixed · 5 acknowledged
Critical
00
High
00
Medium
03
Low + Info
02
02

Scope

1 file
Platform
- · Typescript
Methodology
File
hopium.virtual.tech (Web2 coin-flip app on Virtual Rollups)
03

Findings

click any row for the full write-up
04

Key Findings

  • Deposit function should be disabled before starting a game (Medium, acknowledged). Enabling the deposit function before the user clicks "Start Game" allowed unnecessary transactions and gas griefing scenarios with no associated session state.
  • Lack of input validation in the deposit function triggers zero-value transactions (Medium, acknowledged). The deposit amount input was not sanitized; users could leave the field empty or enter special characters and still submit the transaction, producing zero-value transactions that consumed gas without transferring any value. The transaction also bypassed the "Start a game" precondition.
  • Decimals are not required in the deposit function (Medium, acknowledged). Decimal handling on deposit was unconstrained, mirroring the decimal-rounding class observed across the Virtual Rollups game pentests.
  • Strict-Transport-Security not enforced (Informational, acknowledged). The site did not return the HSTS header.
  • Reset function is redundant (Informational, acknowledged). A reset operation duplicated behavior already available through the session-end flow, increasing surface without adding value.

All five findings were acknowledged by the Hopium team at report publication.

05

Team & approval

Lead Auditor
Jose Fernando
@0xMrjory
06

Disclaimer

This audit is not an endorsement and does not constitute investment advice. Zealynx reviewed the codebase at the commits listed in section 02 over the engagement window. Findings are limited to issues identified within that scope and do not preclude the existence of other vulnerabilities. Subsequent code changes are not covered by this report unless the engagement is explicitly extended.

Download PDF (14p)
ZEALYNX SECURITY · published 2024-07-12
5 findings · Typescript