Security Advisory · TEYNA-2026-001

Multiple Critical Vulnerabilities in randomlucky.icu (Telegram Gift Casino)

July 25–28, 2026Researcher: Vlad Piskunteyna.red

Authorized security assessment discovered five high-impact vulnerabilities including an infinite payment duplication exploit and cross-user payment hijacking. All findings were disclosed to the operator and patched within 48 hours.

All findings resolved

Operator patched all critical issues within 48 hours of disclosure. Advisory published after 70-day embargo.

Disclosure Timeline

  1. 2026-07-25Authorized assessment started. Initial critical findings identified and reported to operator same day.
  2. 2026-07-26Operator patched payment deduplication bypass and cross-user payment hijacking within hours of report.
  3. 2026-07-27Balance-bypass payout vulnerability identified and reported. Patched same day.
  4. 2026-07-28Content-proxy XSS chain identified. Final report delivered to operator.
  5. 2026-10-07Advisory published after 70-day embargo.

Findings

F1 · Payment Deduplication Bypass

CATASTROPHIC

The TON payment verification endpoints deduplicated transactions against a raw client-supplied hash string rather than a normalized transaction identifier. Varying the case of hex characters in the same hash value (de5b25… vs DE5B25… vs base64 encoding) caused each variant to pass as a distinct payment. A single 10.23 TON deposit was credited 12 times as raffle tickets plus two NFT items worth 3.3 TON each — a total of ~70 TON value extracted from one real payment.

Because transaction hashes are public on the TON blockchain, any attacker could use any historical transaction — including one they did not originate — as an infinite credit source, limited only by the 2^n case permutations of the hash string.

CWE-345Insufficient Verification of Data Authenticity

F2 · Cross-User Payment Hijacking

CRITICAL

The ticket purchase endpoint (POST /api/verify-ton-transaction) and NFT purchase endpoint (POST /api/portals/verify-ton) looked up transactions by client-supplied hash and verified only that the received amount met the expected threshold. Neither endpoint verified that the on-chain transaction comment matched the calling user's payment session, nor that the sender address belonged to the calling user's wallet.

Exploited live: a fresh raffle session for 7 tickets (0.0703 TON) was submitted with a third-party transaction hash for 1.94 TON from an unrelated user's wallet. The server responded {"success":true,"totalTickets":7} and issued ticket #313173 in the live raffle at zero cost. Because TON transactions are public and near-real-time, a rate-limit-free attacker could monitor the operator's hot wallet and race every incoming payment before the legitimate user claims it.

CWE-639Authorization Bypass Through User-Controlled Key

F3 · Balance-Bypass Payout

CRITICAL

POST /api/payout-request processed TON withdrawal requests without verifying the user's Stars balance against the requested amount before initiating an on-chain transaction. A test account with a lifetime credit of 84 Stars successfully submitted two 100-Star withdrawal requests; both were accepted and one resulted in an executed on-chain transfer of 0.862641 TON (txHash d9237513…, confirmed independently via TonCenter). A request for 999,999 Stars returned {"success":true,"newBalance":0}.

CWE-840Business Logic Errors

F4 · Promo Code Enumeration Oracle

HIGH

POST /api/cases/promo/redeem returned distinguishable error messages for non-existent codes (promo_not_found) versus exhausted codes (promo_limit_reached), creating a full enumeration oracle with no rate limiting. At 25.8 requests/second, 1,864 candidates were tested in ~60 seconds, yielding five valid promotional codes: FREE, FREE1, SUMMER, GIFTROAD, MINES. New influencer codes could be exhausted within minutes of creation.

CWE-203Observable Discrepancy

F5 · Unauthenticated Full User Database Exposure

HIGH

The raffle history endpoints (GET /api/draws/history, GET /api/gifts/{id}) operated without authentication. Raffle IDs were sequential integers starting from 1. Iterating 80 IDs (approximately 1% of the full dataset) returned 3,186 ticket rows containing raw Telegram user IDs, ticket counts, amounts, and timestamps — exposing 1,012 unique paying users and 82,839 Stars of transaction volume. At 6.5 requests/second with no throttling, a complete extraction of all 8,164 raffles would take under three minutes.

CWE-306Missing Authentication for Critical Function

Remediation Status

FindingStatusPatched
F1Payment Hash BypassFixed2026-07-26
F2Payment HijackingFixed2026-07-26
F3Balance-Bypass PayoutFixed2026-07-27
F4Promo Code OracleFixed2026-07-28
F5Unauthenticated User DataFixed2026-07-28

Advisory ID: TEYNA-2026-001 · Published: October 7, 2026 · Contact: hello@teyna.red