Web3 Game Backend Exposed: Players Spam POST Requests for Max Rewards

sterlingcrispin · x · 2026-08-05

Developer Sterling Crispin pointed out a glaring security flaw in certain Web3 games: anyone can easily cheat the system by sending a POST request with an arbitrary score to claim payouts, with users spamming max scores from multiple wallets.

He sarcastically suggested creating a play-to-earn game that is literally just an open POST endpoint where the fastest request wins, jokingly calling the concept a literal DDoS attack.

Original post →

More from Fun

Fun channel →