1. Our Security Commitment
NEXA Network is committed to maintaining a safe, secure, and competitive survival environment for all players. We employ a layered defense model spanning edge network DDoS mitigation, hardened server containerization, heuristic anti-cheat algorithms, and cryptographic credential storage.
2. Network & Infrastructure Defenses
Our production server architecture utilizes enterprise-grade defense layers to ensure continuous availability and low latency:
- TCPShield DDoS Mitigation: Layer 4 and Layer 7 protection that filters volumetric attacks before they reach backend game instances.
- Brute-Force Attack Prevention: Web and administrative interfaces enforce strict rate limits and automated IP firewalls that isolate malicious IPs after repeated failed attempts.
- TLS / SSL Encryption: All web portal traffic, API calls, and session cookies are encrypted in transit using industry-standard TLS 1.3 cryptography.
3. In-Game Anti-Cheat & Anti-Exploit Engines
Fair play is the foundational pillar of NEXA SMP. We do not tolerate unauthorized client modifications that provide unfair tactical or economic advantages:
- AntiXray Mode 2: Real-time chunk block obfuscation that prevents X-ray texture packs, Freecam, and Baritone mining bots from locating valuable ores before blocks are legitimately exposed.
- Combat & Movement Heuristics: Continuous packet analysis detecting impossible reach, click automation, flight, speed hacks, and killaura behaviors.
- Inventory & World Rollback: Granular block manipulation and transaction logging enabling administrators to restore griefed claims and rollback illegitimate item duplications within minutes.
4. Account Security Best Practices
Players are responsible for maintaining the security of their own credentials. To keep your account safe:
- Never share your portal password or Minecraft login credentials with anyone, including individuals claiming to be staff. Official NEXA staff will never ask for your password.
- Enable WhatsApp OTP login integration for two-factor authentication on our web portal.
- Always connect through our official domain:
spysmp.live(Java) and147.185.221.213:2902(Bedrock). Beware of fraudulent phishing copies.
5. Responsible Vulnerability Disclosure (Bug Bounty)
We welcome responsible security researchers and community members who identify potential vulnerabilities in our website, API endpoints, or in-game plugins.
If you discover an exploit or security flaw:
- Privately submit a report through our Contact Portal under the "Bug Bounty / Exploit" category or message Jinshi directly on WhatsApp at
+91 9947438051. - Do not exploit the vulnerability to gain in-game items, disrupt server operations, or compromise player privacy.
- Allow our technical team reasonable time to patch the issue before disclosing it publicly.
Legitimate, responsibly reported vulnerabilities are rewarded with in-game currency, exclusive titles, and store credits proportional to the severity of the finding.