Game Hacking 101
Julian 'Julez' Dunning (Truffle Security)
DEF CON 33 · Day 1 · Main Stage
Overview
In "Game Hacking 101," Julian 'Julez' Dunning, co-founder of Truffle Security and founder of the Game Hacking Village, delves into the fascinating intersection of video games and cybersecurity. This talk isn't about promoting competitive cheating but rather leveraging the engaging world of game hacking as a practical, accessible, and often entertaining vehicle for learning fundamental security concepts. Dunning argues that the methodologies and mindset employed by game hackers—identifying logic flaws, reverse engineering, and manipulating memory—are directly transferable skills for offensive and defensive security professionals.

Key moments
- 0:00 Speaker introduction and talk's "learning, not cheating" disclaimer
- 2:00 Why learn game hacking; overview of talk sections
- 3:00 Introduction to game logic speedrunning and complexity
- 4:10 Detailed explanation of Baldur's Gate 3 "Shadow Boxing" glitch
- 6:50 Explanation of Super Mario 64's famous backwards long jump
Game Hacking 101
Speakers: Julian 'Julez' Dunning, Founder, Truffle Security
Conference: DEF CON
YouTube: https://www.youtube.com/watch?v=XSzXaD6A73s
Overview
In "Game Hacking 101," Julian 'Julez' Dunning, co-founder of Truffle Security and founder of the Game Hacking Village, delves into the fascinating intersection of video games and cybersecurity. This talk isn't about promoting competitive cheating but rather leveraging the engaging world of game hacking as a practical, accessible, and often entertaining vehicle for learning fundamental security concepts. Dunning argues that the methodologies and mindset employed by game hackers—identifying logic flaws, reverse engineering, and manipulating memory—are directly transferable skills for offensive and defensive security professionals.
The presentation provides a comprehensive overview of various game hacking techniques, from exploiting in-game logic bugs for speedrunning to the transformative power of modding and the intricate dance between anti-cheat systems and malicious actors. Dunning emphasizes that understanding these mechanisms not only sharpens one's security acumen but also highlights how innovation in the gaming industry itself often springs from the modding community. By showcasing concrete examples from popular titles like Baldur's Gate 3 and Super Mario 64, the talk demystifies complex security principles, making them relatable and engaging for a broad audience, from budding enthusiasts to seasoned security researchers.
This exploration underscores the idea that the vulnerabilities found in games—be it incorrect handling of negative values, client-side trust issues, or exploitable game engine mechanics—mirror those found in enterprise software. Therefore, practicing game hacking provides a "free" and "interesting" training ground for identifying and mitigating real-world security risks, ultimately fostering a deeper understanding of how software operates and can be subverted.
Background
▶ Watch: Speaker introduction and talk's "learning, not cheating" disclaimer (0:00)
The premise of "Game Hacking 101" is rooted in the idea that video games, despite their entertainment focus, are complex software applications susceptible to many of the same vulnerabilities as enterprise systems. Julian Dunning, with a background in offensive security, including password cracking research and founding Truffle Hog (now Truffle Security) for finding open-source secrets, sees game hacking as a natural extension of his interests. He posits that the mentality of a red teamer—probing systems, identifying weaknesses, and crafting exploits—is inherently aligned with the approach of a game hacker or speedrunner.
This problem exists because games, especially those with intricate mechanics or online components, represent massive attack surfaces. Developers, under pressure to deliver features and engaging experiences, can inadvertently introduce logic bugs, memory handling errors, or insufficient client-side validation. Historically, these flaws have been exploited by players for competitive advantage, creative expression through modding, or simply to achieve feats like rapid game completion (speedrunning). The talk contextualizes this by noting that even modern, highly advanced games are not immune; "just because something is newer that does not necessarily mean that it is more secure." In fact, increased complexity often introduces more potential points of failure.
Prior work in this space includes decades of community-driven game modding, the development of tools like Cheat Engine, and the ongoing arms race between cheat developers and anti-cheat vendors. Dunning highlights that many foundational security concepts, such as understanding memory layout, process manipulation, and reverse engineering, are readily observable and exploitable within game environments. By framing game hacking as a learning opportunity, the talk positions it as a valuable, hands-on method for understanding software security that is both accessible and highly motivating for individuals passionate about games.
Key Findings
▶ Watch: Why learn game hacking; overview of talk sections (2:00)
Julian Dunning's talk reveals several key findings and insights across the spectrum of game hacking:
- Logic Bugs and Speedrunning as Red Teaming: Dunning effectively demonstrates that speedrunning exploits are, at their core, logic bugs akin to vulnerabilities found in enterprise software. The examples of Shadow Boxing in Baldur's Gate 3 and the Backward Long Jump in Super Mario 64 illustrate how seemingly minor oversights in game design or physics calculations can lead to massive bypasses, reflecting a red teamer's ability to find and exploit unexpected system behaviors.
- Modding as a Driver of Innovation: Far from being a niche activity, modding is presented as a crucial engine for innovation in the gaming industry. Dunning highlights how entire genres and some of the world's most popular games—including Counter-Strike (a Half-Life mod), Dota (a Warcraft mod), and the Battle Royale genre (spawned from Arma 3 mod derivatives like Players Unknown Battleground and Fortnite)—originated as modifications. This underscores the power of community-driven development and experimentation.
- Memory Hacking's Accessibility and Fundamental Nature: The talk emphasizes that memory hacking with tools like Cheat Engine offers a low-barrier entry point into understanding how software stores and manipulates data. The ability to scan, identify, and modify values (like health or position) directly in a game's memory demystifies core computer science concepts and illustrates the client-side trust issues prevalent in insecure applications.
- Reverse Engineering for Deep Understanding: Dunning champions reverse engineering as a powerful technique to understand the underlying code and logic of a game. Specifically, the ease of decompiling C# from Unity games into readable pseudo-code provides a direct window into developer intentions, hidden content, and potential modification points, making it an invaluable skill for both modders and security researchers.
- The Anti-Cheat Arms Race: The discussion on anti-cheat systems highlights the perpetual cat-and-mouse game between developers and cheaters, mirroring the broader cybersecurity landscape. The critical role of kernel-level permissions and signed kernel drivers in this battle, along with strategies like wave bans, showcases the high stakes and sophisticated techniques involved in protecting competitive online environments.
These findings collectively argue that game hacking is not merely a recreational pursuit but a potent educational tool that provides tangible, hands-on experience with principles fundamental to software security.
Technical Deep Dive
▶ Watch: Introduction to game logic speedrunning and complexity (3:00)
The talk provides several compelling technical examples across different facets of game hacking, illustrating core security principles.
Game Logic Exploits (Speedrunning)
Dunning dissects two classic speedrunning glitches that highlight flaws in game logic and physics:
- Shadow Boxing (Baldur's Gate 3): This exploit leverages multiple unintended interactions. First, by placing an ally (e.g., Shadowheart) into a box and setting it on fire, the character temporarily transitions from an active entity to a "storage item." As the box breaks from fire damage, the character "pops out." Crucially, developers sometimes stack unrendered levels or areas above/below the currently active map to save space. When the burning box is thrown into a specific "void" area, the game's collision detection system misinterprets the unrendered level below as solid ground. Upon the character reappearing, if their internal character marker triggers a cutscene condition associated with that unrendered but technically loaded area, the game state can be advanced significantly, effectively skipping vast portions of the game. This demonstrates how unexpected interactions between game objects, physics, and level loading can lead to arbitrary code execution or state manipulation.
- Backward Long Jump (Super Mario 64): This classic glitch exploits an oversight in how Mario's movement and collision are handled. Mario can technically jump infinitely without a cooldown, limited only by needing to return to a lower vertical position. When jumping forward upstairs, the vertical differential is quickly met, preventing infinite jumps. However, developers capped positive horizontal movement speed but neglected to cap negative movement speed. By jumping backwards on stairs, Mario continuously meets the vertical jump condition while accumulating an uncapped negative horizontal momentum. The core technical bypass occurs due to the game's collision detection being frame-based. If Mario's speed is so immense that he transitions from one side of a collider (like a door) to the other side within a single frame, without ever registering a frame where he touched the collider, the game fails to detect the collision. He effectively "teleports" through the door, bypassing entire sections of the game. This highlights the dangers of incomplete input validation (uncapped negative values) and discrete, frame-based collision checks in high-speed scenarios.
Memory Hacking with Cheat Engine
Memory hacking is presented as a fundamental technique, easily accessible with tools like Cheat Engine. The process involves:
- Initial Scan: Identifying a known value (e.g., player health "100") within the game's memory space. Cheat Engine scans for all instances of this value.
- Value Change & Next Scan: The value is changed in-game (e.g., player takes damage, health becomes "90"). Cheat Engine then scans again, filtering the previous results to only show memory addresses where the value changed from 100 to 90.
- Refinement: This process is repeated until a unique or small set of addresses representing the target value (e.g., player health) is found.
Once identified, the memory address can be directly modified (e.g., setting health back to 100, or even 9999) or "frozen" to prevent changes. This technique applies to any in-game value stored in memory, such as position (represented by floats), currency, or ammo.
Crucially, Dunning points out the distinction between client-side and server-authoritative games. In offline games, client-side memory manipulation is trivial. In online competitive games, however, a robust server-authoritative model is essential. The server must validate client-reported values. For instance, if a client reports a position change of a "thousand units in a different direction the next frame," the server should deem this impossible and reject it, preventing teleportation cheats. However, Dunning notes that even today, some online games still trust certain client-side memory values, leaving them vulnerable.
Reverse Engineering Unity Games
Reverse engineering offers a deeper understanding of a game's internal workings. Dunning specifically highlights Unity games developed with C# as particularly amenable to this. C# is a managed language that compiles into Intermediate Language (IL), which can often be decompiled back into highly readable pseudo-code. This allows researchers to:
- Understand Game Logic: Directly inspect how game mechanics, interactions, and rules are implemented.
- Identify Secrets: Discover hidden levels (e.g., a "lava level" mentioned in code but not in-game), unused assets, or developer debug features. Dunning cites the arcade game Killer Queen as an example where this technique could be applied.
- Facilitate Modding: By understanding the code, modders can precisely inject or modify game behavior.
- Learn Assembly: For lower-level understanding, Dunning recommends Squalally, a Steam game designed to teach assembly language by having players manipulate the game's assembly directly, with the caveat that a divide-by-zero operation can crash the system.
Anti-Cheat Mechanisms
The talk touches upon the continuous escalation in anti-cheat technologies. The core principle in this cat-and-mouse game is privilege: "whoever has the most privileges will win."
- Kernel-Level Permissions: The ultimate goal for both cheaters and anti-cheat developers is to operate with kernel-level permissions. A kernel-level cheat can override any non-kernel-level anti-cheat, while a kernel-level anti-cheat can detect and block virtually any user-mode cheat.
- Signed Kernel Drivers: Acquiring signed kernel drivers is a significant hurdle for cheat developers, as these are difficult to obtain and can be quickly blacklisted by anti-cheat vendors. This creates a high barrier to entry and cost for maintaining sophisticated cheats.
- Trust Issues: Dunning raises the ethical and security dilemma of installing kernel-level anti-cheat software from potentially untrusted game developers, likening it to trusting any random antivirus with deep system access.
- Wave Bans: Anti-cheat developers often employ wave bans—delaying bans for detected cheaters to allow more accounts to be compromised by a specific cheat. This prevents cheat developers from quickly identifying which detection vector was triggered and pivoting their methods, forcing them to "start all the way over." This strategy is designed to maximize the cost and effort for cheat developers.
Demo / Proof of Concept
▶ Watch: Detailed explanation of Baldur's Gate 3 "Shadow Boxing" glitch (4:10)
While the talk itself did not feature a live, interactive demo, Julian Dunning extensively described several practical applications and learning opportunities, including his own projects and the activities at the Game Hacking Village. These serve as tangible proofs of concept for the discussed techniques:
- Unity Game for Memory Hacking: Dunning developed a Unity game specifically for the DEF CON Game Hacking Village last year. This game tutorializes memory hacking, allowing participants to learn the concepts of scanning and modifying values directly. It is available for download on the Game Hacking Village website, serving as an accessible, self-paced learning tool.
- Game Hacking Village Activities: The village offers a range of hands-on experiences:
- Hacker vs. Hacker Olympics: Teams compete to develop hacks for relatively new games with minimal anti-cheat, working in cooperation with the developers. This provides a live, competitive environment for applying memory hacking and other techniques, with Dunning noting that some participants quickly developed auto-aim features and even exploits to boot other players from servers. The platform used, Sandbox, is described as a successor to Garry's Mod, offering a similar virtualized environment for experimentation.
- Minecraft Coding Puzzles: These workshops teach Lua scripting, a language popular for creating mods, within the Minecraft environment.
- Modding Workshops & Mobile Game Hacking Workshop: Dedicated sessions for learning different aspects of game modification across various platforms.
- Bug Bounty Challenge: In partnership with sponsors like Epic Games, participants can engage in legitimate bug bounty programs, attempting to find sandbox escapes or other vulnerabilities in actual games and get paid for their discoveries.
- Melon Loader + Unity Explorer Combination: Dunning highlights a powerful combination for exploring and modifying Unity games: Melon Loader (a mod loader) paired with Unity Explorer. This setup allows users to "walk through the matrix of a game," providing real-time access to all in-game objects, their properties, attached scripts, and the ability to modify, enable/disable, or move them. He uses Outer Wilds as an example game where this can be applied, suggesting it as "homework" for the audience due to its captivating design. This effectively turns the running game into a live, interactive debug environment, demonstrating the extent of client-side control.
- Obfuscation Challenge and Bypass: Dunning shared a personal anecdote illustrating the challenge of securing single-player game challenges against data mining. For a game he created, he implemented an obfuscation technique: an invisible, floating cube was randomly rotated on each level, and its vector coordinates were hashed to serve as an encryption key for flags. He was confident in this method, but "a day later, someone sent a script out on GitHub that was like, 'Here's how you do that. Here, this gets all the flags from all the levels of this game.'" This anecdote serves as a humorous but stark proof of concept: even clever obfuscation can be quickly defeated by dedicated hackers, emphasizing the constant struggle and creativity required in both offensive and defensive security.
Defensive Implications
▶ Watch: Explanation of Super Mario 64's famous backwards long jump (6:50)
The insights gleaned from game hacking have significant defensive implications, not just for game developers but for general software security:
- Server-Side Authoritative Logic is Paramount: The most critical takeaway for developers of any networked application, especially competitive online games, is the absolute necessity of server-authoritative logic. As demonstrated by memory hacking and client-side manipulation, clients cannot be trusted to report their state accurately. All critical game state, actions, and values (e.g., player health, position, inventory, critical game events) must be validated and enforced on the server. Developers should not rely solely on client-side checks, as these are trivial to bypass.
- Thorough Input and Value Validation: The Backward Long Jump in Super Mario 64 highlights the danger of incomplete validation. Capping positive movement speed but neglecting negative values created a significant vulnerability. Software developers must consider edge cases, including negative numbers, zero values, and excessively large inputs, ensuring that all data is rigorously validated against expected ranges and types, regardless of whether it originates from a user, another system, or internal calculations.
- Understanding Game Engine Vulnerabilities: The Shadow Boxing exploit demonstrates how specific engine behaviors (like unrendered stacked levels) can be abused. Developers using commercial game engines (Unity, Unreal, etc.) should be aware of known engine quirks and vulnerabilities. Furthermore, custom engines require meticulous internal auditing to prevent similar logic flaws. This extends to understanding how collision detection, physics, and state transitions are handled at a fundamental level.
- The Anti-Cheat Arms Race Requires Constant Evolution: For online games, anti-cheat is a continuous, high-stakes battle. Developers must invest in robust, multi-layered anti-cheat solutions, ideally incorporating kernel-level permissions where appropriate and justifiable, while balancing user trust. Strategies like wave bans are effective in increasing the cost for cheat developers. Furthermore, integrating anti-cheat mechanisms with server-side analytics to detect anomalous player behavior (e.g., impossible movement speeds, statistically improbable accuracy) is crucial.
- Obfuscation as a Deterrent, Not a Solution: Dunning's personal experience with his obfuscated challenge highlights that obfuscation can deter casual data miners but is rarely a permanent solution against determined attackers. It increases the effort required but does not fundamentally secure the underlying logic or data. For critical assets, security-by-design, strong encryption, and server-side validation are superior.
- Game Hacking as a Training Ground for Security Professionals: For security professionals, engaging with game hacking provides a low-risk, high-reward environment to practice offensive security skills. It sharpens abilities in reverse engineering, memory analysis, debugging, and identifying logic bugs—skills directly transferable to finding vulnerabilities in business applications, operating systems, and network protocols. Organizations could even consider game hacking challenges as part of their training or recruitment processes.
- Bug Bounty Programs for Enhanced Security: The inclusion of game bug bounty challenges at the Game Hacking Village demonstrates a proactive defensive strategy. Engaging the security community through structured bug bounty programs can uncover vulnerabilities that internal teams might miss, providing a cost-effective way to improve game security and foster positive relationships with researchers.
Key Takeaways
- Game hacking is a powerful, accessible learning tool for cybersecurity fundamentals: It provides a hands-on environment to understand concepts like memory manipulation, reverse engineering, and logic flaws, directly applicable to real-world software security.
- Logic bugs are pervasive, even in modern, complex software: Examples like Shadow Boxing in Baldur's Gate 3 and the Backward Long Jump in Super Mario 64 demonstrate how seemingly minor oversights can lead to significant exploits, regardless of a game's age or sophistication.
- Modding drives significant innovation in the gaming industry: Many popular game genres and titles, including Counter-Strike, Dota, and Battle Royale games like Fortnite, originated from community-driven modifications, showcasing the creative power of open exploration.
- Client-side trust is a critical vulnerability; server-authoritative logic is essential: Relying on client-side data for critical game state (or any application state) is inherently insecure. Robust validation and enforcement must occur on the server to prevent manipulation via memory hacking tools like Cheat Engine.
- The anti-cheat battle is a continuous privilege escalation war: The ongoing cat-and-mouse game between cheaters and anti-cheat developers centers on gaining kernel-level permissions and leveraging techniques like signed kernel drivers and wave bans to gain or maintain control over the execution environment.
- Reverse engineering provides deep insights into software mechanics: Tools for decompiling C# in Unity games allow direct examination of game logic, aiding both legitimate modding and security research, including the discovery of hidden content or exploitable code paths.
About the Speaker(s)
Julian 'Julez' Dunning is a prominent figure in the offensive security space. He has a storied history in security consulting and is the co-founder of Truffle Security (formerly Truffle Hog), a company focused on finding open-source secrets. Dunning has also conducted significant research in password cracking and was recognized on the Forbes 30 under 30 list. More recently, he founded the Game Hacking Village (Gamehacking.gg), an initiative dedicated to exploring the intersection of games and cybersecurity. While he humbly states he is not a professional "game hacker," his passion lies in combining his love for games and computer security to explore vulnerabilities and foster learning within the community.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A competent, enthusiastic introductory talk that uses game hacking as an on-ramp to core security concepts. Dunning is clearly passionate and the framing is clever, but this is a 101 talk in the truest sense — it doesn't go deep enough to teach experienced practitioners anything they don't already know, and the technical content stays firmly at the survey level.
Heather Calloway (CISO) — PASS
A well-constructed introductory talk on game hacking as a security learning vehicle. No governance angle, no institutional relevance, no defender or executive decision it changes. Completely outside my lane — and that's the honest call.