> Markdown version of [/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Thinking Differently - How to Make Money from Cyber Attacks & Cheats Automated attacks hit mobile games just 137 milliseconds after launch. Instead of banning these exploiters, discover how to transform game cheats into a massive, untapped revenue stream. - **Speakers:** Tom Tovar - **Event:** World Congress 2023 - **Published:** October 6, 2023 - **Duration:** 24:46 - **URL:** https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats ## Summary Mobile applications, particularly games, face automated cyber attacks almost instantly—averaging a mean time to first attack of just 137 milliseconds after publication. Instead of defaulting to standard security responses like immediate application termination or simply ignoring the problem, development teams can entirely reframe application defense by differentiating between malicious fraud and experience-driven cheating. Because roughly 10% to 30% of an application's user base might be actively utilizing exploits, these individuals represent a massive, untapped monetization opportunity rather than just a routine security threat. By systematically capturing threat telemetry, companies can intercept common exploits like memory editing or point manipulation via tools such as GameGuardian and Lucky Patcher. Rather than banning these users, publishers can offer paid subscriptions that allow cheaters to retain their illegitimately gained in-game assets, a strategy that reliably converts around 20% of offenders. Similarly, developers can establish premium server leagues specifically for automated scripts and bot operators to compete against one another, or negotiate bounty agreements with gray market emulation platforms like BlueStacks and Nox to officially license gameplay access. Successfully transforming attacks into revenue streams requires separating raw threat detection from application business logic. Engineering teams should rely on dedicated cyber defense frameworks to gather concrete attack metadata—such as location, device IDs, and attack vectors—while focusing internal development efforts entirely on crafting the in-app conversion funnels. Crucially, while bypassing grind mechanics or modifying game rules can be highly lucrative, product owners must maintain a strict security boundary by never attempting to monetize actual criminal fraud, such as keylogging, overlay attacks, or fake transactions. **Keywords:** mobile application security, cyber attack monetization, memory editing exploits, gray market emulators, android emulation bounties, game cheating conversion, automated bot leagues, threat event telemetry, appdome framework, business logic integration, fraud vs cheating distinction, gameguardian, lucky patcher, mobile game economy, in-app fraud prevention, overlay attack detection ## Chapters 1. **Embracing a new perspective on mobile cyber attacks** (00:00) — Viewing threat vectors as potential monetization channels changes how teams approach application security. 1. **Understanding the speed and scale of app attacks** (04:27) — Automated attack vectors target new mobile applications within milliseconds of deployment to production environments. 1. **Monetizing gray market emulation platforms in mobile games** (07:59) — Detecting players on unauthorized emulation platforms creates opportunities to negotiate bounties with underlying platform providers. 1. **Converting memory editing attempts into paid user upgrades** (10:49) — Identifying runtime memory modifications allows publishers to prompt malicious actors to legally purchase injected currency. 1. **Offering subscription paths for advanced cheat tool users** (13:25) — Intercepting multi-purpose utility tampering tools creates an avenue to upsell features natively via paid subscriptions. 1. **Creating competitive environments for automated bot execution scripts** (15:23) — Isolating automated gameplay scripts into dedicated server clusters retains bot developers within isolated competitive environments. 1. **Differentiating monetizable gameplay manipulation from malicious fraud** (17:52) — Separating economy enhancement tools from destructive financial malware is critical when engineering responsive application business logic. 1. **Implementing runtime threat event frameworks for attack telemetry** (19:27) — Passing attack metadata from embedded control frameworks empowers engineering teams to define downstream application business logic. 1. **Best practices for integrating attack monetization business logic** (20:34) — Separating security detection responsibilities from user experience development teams prevents operational friction during implementation. 1. **Audience questions on memory editing and patch detection** (22:14) — A breakdown of standard patching identification techniques alongside insights into automated defensive framework compilation architectures. ## Related Moments - [Conceptualizing app security defense using gaming mechanics](https://www.wearedevelopers.com/videos/1193-it-s-a-testing-trap-common-testing-pitfalls-and-how-to-solve-them) (from "It's a (testing) trap! - Common testing pitfalls and how to solve them") - [Examining common exploitation techniques against software organizations](https://www.wearedevelopers.com/videos/376-walking-into-the-era-of-supply-chain-risks) (from "Walking into the era of Supply Chain Risks") - [Evaluating mobile game prospects and encountering missed investment opportunities](https://www.wearedevelopers.com/videos/352-coffee-with-developers) (from "Coffee With Developers") - [Retaining the defender advantage in the cybersecurity race](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) (from "Fighting the Next Wave of Cybercrime") - [Answering audience questions on practical application security](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) (from "Software Security 101: Secure Coding Basics") - [Analyzing bizarre technology headlines and software engineering news](https://www.wearedevelopers.com/videos/1788-wearedevelopers-live-you-don-t-need-javascript-modern-css-and-more) (from "WeAreDevelopers LIVE – You Don’t Need JavaScript, Modern CSS and More") ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) ## Related Jobs - [Engineer, Offensive Security Organization](https://www.wearedevelopers.com/jobs/ext/1992296-engineer-offensive-security-organization) at **Twilio** - [Senior Software Engineer, Fraud](https://www.wearedevelopers.com/jobs/ext/1280398-senior-software-engineer-fraud) at **Twilio** - [Staff Engineer - Offensive Security](https://www.wearedevelopers.com/jobs/ext/1226927-staff-engineer-offensive-security) at **Twilio** - [Founding Mobile Engineer (iOS)](https://www.wearedevelopers.com/jobs/ext/1648532-founding-mobile-engineer-ios) at **Almedia** - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Principal Product Manager, Enterprise Commerce Platform](https://www.wearedevelopers.com/jobs/ext/1390094-principal-product-manager-enterprise-commerce-platform) at **Twilio**