Web3 Casino Intraverse Allegedly Exposed by a Keyless Firebase Database, Including Its Own House Bot Stack
A forum user posting as exfilar has published what they describe as the full production Realtime Database behind intraverse.io, the Intraverse/Gamifi web3 gambling platform, totalling 16,898,017 database leaves across roughly 518MB of JSON. The seller states the database required no authentication, no token, and no referer check, and that it was located through a bulk sweep of more than twenty thousand Firebase project identifiers rather than a targeted intrusion. Beyond player records, the material reportedly includes the platform's automated gambling bot configuration, its funding wallets, and a working RPC provider key. The actor states no private keys or seed phrases are present. The claim is unverified.
▣Post details
!Allegedly included
- Player wallet addresses
- Usernames and win history
- Bet and payout amounts
- USD denominated values
- 16.1M notification events
- Client IP references
- Push device tokens
- Bot orchestration configs
- 48 instance wallet records
- Manager funding wallets
- Live RPC provider key
- Discord operator identifiers
- Admin account identifiers
- Fairness circuit artifacts
◱Screenshots
⚠Potential impact
The seller states plainly that no private keys, seed phrases, or contract paths are present, so there is no direct route to draining the exposed wallets, and write access to the database was reportedly rejected. What remains is still consequential. Every win record is said to tie a real wallet address to a username, bet size, payout, and timestamp, which turns pseudonymous on-chain activity into an attributable gambling history and makes high-value players easy to identify and target for phishing. The working RPC provider key is a live third-party credential that can be abused against the account it belongs to until it is revoked. The most awkward exposure is the operator's own: bot configurations, funding wallet balances, and betting parameters would reveal how the house automation is run, which invites both scrutiny of game fairness and adversarial play against a system whose strategy is now public.
iStatus
UnverifiedThe listing includes an access check dated the day of posting showing read access still open and write attempts refused, which if accurate means the exposure was live at publication. Counts, balances, and the claimed on-chain reconciliation are the actor's own figures and are not independently confirmed. Dark Web Informer is not reproducing the download route, the RPC key, wallet addresses, or the Discord and admin identifiers named in the post. The actor describes this as one of several results from an automated sweep and says further releases will follow, so other projects with the same misconfiguration are likely in the same queue. The same account is separately advertising paid intrusion services. The claim is unverified and the operator has not publicly addressed it.
DARK WEB INFORMER - THREAT INTELLIGENCE