An algorithm that allowed the generation of working Microsoft point codes resulted in the unauthorized acquisition of what some claim could be as high as $1.2 million in virtual currency. Microsoft tells Kotaku that they looking into punishing those that took advantage.
Microsoft points might not be real money but they are purchased with real money, at least thatâs normally the way itâs done. Two days ago an exploit was released onto the internet that allowed users to generate countless codes good towards the redemption of 160 Microsoft points by using an algorithm that generated new numbers based on used codes.
https://lastchance.cc/exploit-results-in-theft-of-1-2-million-in-xbox-live-5780421%3C/a%3E%3C/p%3E
Microsoft discovered the exploit within hours, but not before a substantial number of codes were generated.
âWe are aware of the situation and have taken steps to invalidate the codes obtained illegitimately,â Microsoft told Kotaku in an official statement this afternoon.
With Microsoft able to track the generated codes, that means they can also track accounts that cashed in the generated codes for points.
And since they can track the damage, they are qualified to tell us that the $1.2 million figure being thrown about is far from the actual number. âWe canât share specific numbers, but the figure is nowhere near the amount that has been reported.â
Still, those that partook could soon face the swift arm of Microsoft justice.
âWe take safety and security very seriously and require that Xbox LIVE members use the service in compliance with applicable laws and specifically prohibit people from engaging in illegal activity as a part of our Terms of Use and Code of Conduct,â the statement continued. Our Policy and Enforcement team is evaluating whether or not certain individuals have violated the Terms of Use for Xbox LIVE and will take the appropriate enforcement on an individual basis.â
If you happen to be one of the folks that got your hands on the unauthorized codes, Iâd strongly suggest not attempting to cash them in.
Microsoft says that users of legitimately obtained Microsoft point codes have nothing to worry about.