Players find ways to farm tokens faster than designed — the GameFi market collapses. This is a standard Play-to-Earn problem: the economic model fails under load if the technical implementation has holes. We solve this at the architecture level: the client never calculates rewards, all events are server-verified, and cheaters are blocked before they do damage. If you face similar issues, contact us for an audit of your project. We have delivered over 20 GameFi projects where an off-chain model cut gas costs by 90% and doubled retention.
Client-Side Reward Calculation Is a Vulnerability
If the app itself calculates how many tokens the player earned and sends that number to the server, cheating is trivial via Charles Proxy or Frida instrumentation. Therefore, every game event must be verified server-side: the client sends game_session_id plus actions with a signed timestamp, and the server independently recalculates the result. This closes the primary attack vector.
NFT Ownership: Verify on the Server, Not the Client
If the game requires NFT ownership (character, land), the ownerOf(tokenId) check must be an eth_call to the smart contract from the server. The client can spoof the response. The server caches ownership with a TTL of 30–60 seconds via Redis to avoid exceeding RPC limits.
Why On-Chain Transactions for Every Action Are Impossible
Issuing tokens via an on-chain transaction for every game action is too expensive and slow. The working pattern is: off-chain balance in a database → periodic or on-demand claim → on-chain mint or transfer. A Claim button in the app requests a signed message from the server (EIP-712 typed data), the user confirms via WalletConnect or an embedded wallet, and the smart contract verifies the signature and transfers tokens. The off-chain model reduces gas costs by 90% compared to per-action on-chain transactions. For context, a single on-chain Ethereum transaction at peak can cost $5–50, while an off-chain operation costs fractions of a cent.
Embedded Wallet vs. External Wallet: What to Choose for P2E?
| Feature | Embedded Wallet | External Wallet |
|---|---|---|
| User experience | Login via email/social, no seed phrase required | Requires installation and crypto wallet knowledge |
| Key security | Shamir Secret Sharing (Wikipedia), key shares with provider and on device | Keys on user device, phishing possible |
| Transaction confirmation | PIN or biometrics | Multiple confirmations in wallet app |
| Entry barrier | Low (casual gamers) | High (Web3 audience only) |
For casual P2E games, an embedded wallet (Privy, Thirdweb In-App Wallet, Dynamic) is better. Keys are distributed via Shamir Secret Sharing: shares with the provider, the user, and the device. Recovery requires m of n shares — eliminating a single point of compromise. The user never sees a seed phrase until they export it. On mobile: Privy iOS SDK, Thirdweb React Native SDK. Transactions are confirmed with a PIN or biometrics via LocalAuthentication or BiometricPrompt.
How to Ensure Economic Sustainability of P2E?
A dual-token model (governance token + utility/reward token) became the standard after the Axie Infinity collapse: the governance token with limited supply stores value, the utility token is inflationary and spent on gameplay. A smart-contract reward pool with vesting schedule pays rewards linearly, reducing selling pressure. On the client, there are two balances, two separate Claim flows with different transaction confirmations. We guarantee economic stability at the design and testnet testing stage.
| Component | Purpose | Technology |
|---|---|---|
| Governance token | Stores value, limited supply | ERC-20/BEP-20 |
| Utility token | Spent on gameplay, inflationary | ERC-20/BEP-20 |
| Off-chain balance | Stores earned tokens | PostgreSQL/Redis |
| On-chain claim | Converts off-chain to on-chain | EIP-712 signed message |
Game Engine: Unity, React Native, or Flutter?
Unity with a native blockchain plugin is the standard for complex P2E games. Unity WebGL builds are not suitable for mobile — only native iOS (.xcframework) and Android (.aar) exports. Use Thirdweb Unity SDK or ChainSafe Web3.Unity for on-chain interactions from C#. For simple P2E games (clickers, idle games), React Native with react-native-game-engine or Flutter with flame are good choices. Blockchain integration via JSI or Flutter Platform Channel without performance loss.
Anti-Cheat on Mobile: Protective Measures
Basic layer: SSL pinning (prevents MITM via Charles), certificate transparency check, RASP (Runtime Application Self-Protection) via Guardsquare DexGuard (Android) or iXGuard (iOS). Root/jailbreak detection via RootBeer or DTTJailbreakDetection — not as a hard block, but as a signal for enhanced server monitoring. Gameplay anomalies: if a player does 200 taps per second on a clicker, it's a bot. Server-side analytics with Z-score deviation from the cohort median identifies suspicious sessions. To ensure your game is protected, contact us for a review of your current architecture.
What's Included in the Project
- Audit of game mechanics and economic model
- Design of smart contracts and server-side reward validation
- Development of the game core on Unity, React Native, or Flutter
- Integration of an embedded wallet or WalletConnect v2
- Implementation of the anti-cheat layer (SSL pinning, RASP, anomaly detection)
- Economic testing on testnet
- Publication on the App Store and Google Play, with compliance to gambling/finance requirements
- Technical support for 3 months after launch
How We Work: Stages
- Analytics and design — we break down mechanics, economy, and tokenomics.
- Development of smart contracts and server-side validation.
- Implementation of the game core — Unity/React Native/Flutter with blockchain integration.
- Wallet integration — embedded or external, depending on audience.
- Anti-cheat layer — client and server protection.
- Testnet testing — load the economy, verify all scenarios.
- Mainnet deployment and store submission.
Timeline Estimates
A simple P2E clicker with an embedded wallet, off-chain balance, and a claim mechanic — 6–10 weeks. A full-fledged GameFi platform with a Unity game, NFTs, a dual-token economy, and anti-cheat — 3 to 5 months. Timelines are refined after an audit of your mechanics. The cost is calculated individually per project.
We have delivered 20+ GameFi projects; our engineers understand the nuances of blockchain integration, economic modeling, and anti-cheat. If you want your P2E game to avoid the fate of collapsed projects, get a consultation. Contact us to discuss your project.







