People selling in-game currency in server-sided games

TrioTernura

Platinian
Original poster
Sep 26, 2018
7
6
13
44
Brasil
So, one day i saw some indian dude selling cores in facebook, for the game Marvel Strike, for a cheap price and also 3x the value of the actual currency in-game... I was like, fck it let's see what this dude is made of, so i bought some low value to see if it was true... One hour after the payment the cores appeared in my account and he thanked me in the facebook chat. I tried to ask him wtf he did and all but he wouldn't tell me, said he would only sell his "means" for a very high price and i didn't pushed it any further.

My question is, how could he hack the in-game currency since it's server-sided?! I mean, i even purchased some value that was NOT in the in-game shop so i could see if he was actually hacking or buying himself... How is that possible?
 
  • Like
Reactions: Iibnoe iichall

DaRealPanDa

Co-Administrator
Staff member
Supporting-Team
Global Moderator
Social Media
Mar 12, 2018
6,306
15,379
2,120
27
Skyrim
1. He hacked the Server ( i don't think that he do that )
2. He found a way to hack it in the apk
3. He buy the Currency in a Country where it is cheaper as his own country
4. He have a friend or so from developer team
5. He is one of the Developer and he make double Money with that.

I could count many other ways too, but that are the most used
 

AndnixSH

PMT Elite Modder
Staff member
Modding-Team
Jun 27, 2017
4,576
289,933
1,213
Modding World
It can be server exploits, http/json request exploits or in game glitches.
Some server-sided games don't have proper security check which will let anyone abuse glitches/exploits: replace request/response to give them self unlimited everything, ad reward exploits and etc... use slow connection to spam requests against server to duplicate something

Take a look at GTAV online as example. There are still tons of exploits and glitches with broken security checks. Common glitches are money and car duplications
 
  • Like
Reactions: DaRealPanDa

IvorBigun

Platinian
Mar 26, 2017
16
7
18
37
Definitely not the refund trick as the devs can easily track the dodgy cores. 100's of accounts have been wiped because of these sellers.
The method they use is both easy to detect and very much against the tocs