CYREX
Back to Portfolio
Security Testing
Load Testing

Dying Light 2: Stay Human

Client:Techland (supported by Tencent)

Cyrex partnered with Techland to deliver penetration testing, high-scale load testing, and EOS API compliance validation for Dying Light 2, ensuring its online services were secure and ready to support 1 million+ concurrent players at launch.

The Challenge

Securing and Scaling a AAA Live Service Launch

Dying Light 2: Stay Human launched as a globally anticipated AAA title. With massive player demand expected from day one, Techland needed absolute confidence in both security and scalability.

The challenge extended across multiple layers of the game’s ecosystem:

  • Securing complex online and gameplay services — Hundreds of client-to-client RPCs and backend APIs required rigorous validation to prevent exploits.
  • Validating 1M+ concurrent user capacity — Infrastructure had to operate reliably at extreme concurrency.
  • Maintaining performance under load — Authentication, inventory, rewards, and player stats systems had to remain responsive.
  • Ensuring Epic Online Services (EOS) API compliance — Misuse or rate-limit violations could trigger throttling or service disruption.

A vulnerability in gameplay logic or instability in backend services would directly impact player experience at scale. This wasn’t about surface-level endpoint checks. It required deep infrastructure testing before millions of players connected.

The Cyrex Solution

Penetration Testing, Load Testing & EOS Compliance Validation

As a Tencent Gold Partner, Cyrex deployed a specialized team of senior security and performance engineers to work directly against the game’s architecture.

Deep Penetration Testing

Gameplay Services

Two senior security engineers tampered with and validated hundreds of client-to-client RPCs. The objective was clear: identify exploit paths that could compromise gameplay integrity, player progression, or multiplayer fairness.

Online Services

Two additional senior security engineers systematically tested dozens of REST API endpoints. This included authentication flows, backend logic, and data handling mechanisms.

Client-Side Implementation

A dedicated security engineer focused on client-side implementations, including the game binary and its underlying Chrome Engine components. The goal was to uncover manipulation vectors or bypass opportunities from the player’s end.

This layered approach ensured both server-side and client-side attack surfaces were rigorously assessed.

High-Scale Load Testing (Online Services Test)

Cyrex executed a targeted Online Services Test designed to simulate real player behavior during initial session flows.

We tested:

  • Authentication
  • News feed retrieval
  • User status checks
  • Reward fetching
  • Inventory loading
  • Player statistics retrieval
  • Storage patch data requests

By targeting all backend API endpoints called during early gameplay sessions, we validated the system’s ability to operate at full intended load capacity.

The engagement aimed to verify stability and performance at 1 million+ concurrent users (CCU), identifying bottlenecks and degradation points long before launch.

Epic Online Services (EOS) API Compliance Check

Beyond performance and security, Cyrex conducted a formal EOS API Compliance Check.

This included:

  • Request pattern analysis
  • Response behavior validation
  • Verification against documented EOS rate limits
  • Best-practice alignment for API usage

The objective was to prevent throttling or disruption caused by excessive or non-compliant API calls. For a title operating at AAA scale, this validation was critical.

The Outcome

A Secure and Scalable AAA Launch

  • Identification and remediation of gameplay and backend vulnerabilities
  • Validation of backend stability at 1M+ CCU
  • Early detection of performance bottlenecks
  • Reduced risk of EOS API throttling or service interruption

Client Feedback

Techland

Our collaboration with Cyrex on the load and penetration testing campaign for Dying Light: The Beast proved to be both productive and insightful. Throughout the process, their team demonstrated a strong technical understanding of our infrastructure and workflow, helping us uncover and address potential bottlenecks before release. The tests provided clear, actionable feedback that guided our optimization efforts and ensured a smoother experience for players. Beyond the technical results, we appreciated the open communication and collaborative spirit that characterized the project from start to finish. Cyrex’s flexibility and professionalism made it easy to align priorities and adapt the testing scope as the project evolved. This partnership contributed meaningfully to our preparation for launch and reinforced the value of close cooperation between development and testing teams.
Techland
CYREX VERIFIED

Don't Let Players Find the Weakness

Your launch is months away. Hackers will find exploits in hours. Let our engineers secure your game before it's too late.

Response time: <24 hours • NDA included • No commitment required