Skip to content

Part III: Slot Machine Cheating · Electronic & Digital Cheating Methods

SCAM #16: Server-Based Gaming (SBG) Manipulation

Network AttackSkill: Professional

How it works

Server-based gaming systems centralize game logic on remote servers rather than individual slot machines, with terminals acting primarily as display and input devices. This architecture introduces new attack vectors: (1) man-in-the-middle attacks that intercept and modify communications between terminals and game servers, (2) packet injection that sends false outcome commands to terminals, (3) server compromise that allows direct manipulation of game outcomes, (4) latency exploitation where attackers predict outcomes based on network timing. If communications between the terminal and server are not properly encrypted and authenticated, an attacker on the same network could potentially intercept and modify game data in transit. More sophisticated attacks might target the game server directly to alter the RNG seed values or payout tables for specific terminals or during specific time windows.

Where it appears

Server-based gaming terminals, video lottery terminals (VLTs), Class II gaming systems, any slot architecture where game logic executes on a central server

On the record

Server-based gaming has grown significantly in popularity due to operational flexibility, but security concerns have persisted. Various jurisdictions have specific requirements for SBG security, but implementation quality varies. As casinos adopt more centralized gaming architectures, the attack surface concentrated on game servers has increased accordingly.

Published as a detection reference for surveillance, compliance and gaming-operations professionals. Thresholds and tuning are set by the property. Nothing here is instruction — the method is described so it can be recognised.

Related methods