Hopium Web Game Pentest
Zealynx ran a one-week blackbox penetration test of Hopium, a Web2 coin-flip game running on Virtual Rollups ZeroGas infrastructure. Five issues were identified: three Medium (the deposit function should be disabled before starting a game; lack of input validation in the deposit function triggers zero-value transactions and gas griefing; decimals are not required in the deposit function), and two Informational (Strict-Transport-Security not enforced; the reset function is redundant). All five findings were acknowledged at report publication.
Scope
1 fileFindings
click any row for the full write-upKey Findings
- Deposit function should be disabled before starting a game (Medium, acknowledged). Enabling the deposit function before the user clicks "Start Game" allowed unnecessary transactions and gas griefing scenarios with no associated session state.
- Lack of input validation in the deposit function triggers zero-value transactions (Medium, acknowledged). The deposit amount input was not sanitized; users could leave the field empty or enter special characters and still submit the transaction, producing zero-value transactions that consumed gas without transferring any value. The transaction also bypassed the "Start a game" precondition.
- Decimals are not required in the deposit function (Medium, acknowledged). Decimal handling on deposit was unconstrained, mirroring the decimal-rounding class observed across the Virtual Rollups game pentests.
- Strict-Transport-Security not enforced (Informational, acknowledged). The site did not return the HSTS header.
- Reset function is redundant (Informational, acknowledged). A reset operation duplicated behavior already available through the session-end flow, increasing surface without adding value.
All five findings were acknowledged by the Hopium team at report publication.
Team & approval
Disclaimer
This audit is not an endorsement and does not constitute investment advice. Zealynx reviewed the codebase at the commits listed in section 02 over the engagement window. Findings are limited to issues identified within that scope and do not preclude the existence of other vulnerabilities. Subsequent code changes are not covered by this report unless the engagement is explicitly extended.