Goated Denies RichMarketingHQ 'Critical Vulnerability' Claim
The man who sells Goated's rivals their UGC and influencer services just announced a 'critical vulnerability' in Goated's financial system. No technical details, naturally.

Goated, a crypto casino, received its first public security scare over the weekend from the least likely auditor on the platform: a man who calls himself a 'previous CMO' and now runs an iGaming marketing agency that counts two of Goated's rivals among the brands it works with. On Saturday, @RichMarketingHQ announced that he had found 'a critical security vulnerability affecting @goatedcom financial system,' declined to share technical details 'for obvious reasons,' and tagged four Goated staffers to demand eyes on it 'ASAP.' By Sunday morning Goated had replied that no vulnerability was identified and that the balance in the attached screenshot 'is not real.'
The least qualified bug bounty
The advisory had the shape of a responsible disclosure and the soul of a hype tweet. 'Found a critical security vulnerability affecting @goatedcom financial system,' Mr. Rich wrote, punctuating the alarm with a siren emoji. He added that he was not sharing technical details publicly 'for obvious reasons,' so the useful parts stayed off the timeline. A real disclosure goes to the vendor with steps to reproduce. This one went to the timeline and pulled nearly 23,000 impressions, roughly sixteen times his follower count. The only thing patched so far is the optics.

What qualifies Mr. Rich to sound the alarm is the fun part, because his own website does not list the job. RichMarketing.app describes the operation as 'a premium iGaming marketing agency' peddling UGC, short form edits, social media management, influencer brokering, paid ads, analytics and 'compliance advisory.' Pen testing, security audits and incident response are nowhere on the menu. The closest entry, compliance advisory, is about license conditions and responsible-gaming messaging, not packet captures. The brand wall names Stake, Kick, Rainbet, Roobet, PackDraw, Rollbit, Gamdom, Duelbits and Shuffle, among others. Goated is not on it.
His bio adds 'PREV CMO & SMM' without naming which casino, a title doing a lot of credential lifting for a security claim. The blue checkmark, as always, certifies a subscription, not a skill set.
Incident response, in public
Goated's reply landed Sunday morning and read like a help desk ticket with a press office attached. No vulnerability had been identified, the casino said, and the balance in the screenshot was 'not real.' It added that a full response and report had already been sent to Mr. Rich's email. That is the entire public incident response: the absence of a bug has been documented in your inbox, the balance in the picture is fiction, and everyone should please direct their attention back to the slots.
Roughly an hour later, Goated returned to the content calendar with a 22 second hype clip captioned, 'This is what it feels like when you start playing on Goated btw.' For a casino that had just been told its financial system had a critical flaw, the energy was closer to 'and now a word from our sponsor' than 'we have locked down the funds.'
Proof, still pending
To be clear, the claim is unsupported. A screenshot of a balance the casino calls fake, plus a promise to walk someone through the rest 'responsibly,' is not a vulnerability disclosure; it is an allegation with an emoji attached. If you have found a hole in someone's financial system, you do not need a siren. You need steps to reproduce.
The denial deserves the same skepticism. 'No vulnerability has been identified' arrived with no audit, no third party and no timeline, just an assurance that a full report went to the claimant's email. A casino has every incentive to wave off a security claim in public, and this one has extra reason to wave off this particular claimant: Goated dunked on Rainbet last week, and Mr. Rich's bio lists Rainbet and Roobet among the brands he works with. A marketing background does not automatically make a technical observation false, but it also does not make a denial true.
So there it is, the industry's first public bug bounty: a marketer filing a security advisory like a press release, a casino doing incident response in public while the real answer sat in an inbox, and roughly zero proof in either direction. The only thing both sides managed to patch was their own posture.
Comments
Loading comments…



