Blackwhole
The journal

Blackwhole Journal

A build is not
a source project.

What changes when a game ships—and what doesn't.

By Blackwhole

Shipping a game and sharing its production files are different acts. A build is prepared to run. A project is prepared to be edited. Confusing the two makes it harder to say what a protection system should do.

Code and content are different.

Compiling code changes how it is represented. Unity's IL2CPP, for example, converts intermediate code to C++ and compiles it into a native binary. That is a build choice, not evidence that the artwork in the game cannot be recovered. Unity's IL2CPP documentation describes the process.

A shipped game also needs resources: images, models, sound, and the data that gives the world its shape. Valuable material can remain valuable even if its original directory structure, names, or editing history are gone. Recovery need not produce an exact source project to matter to the person who made the work.

Packaging is part of the question.

Engines have different packaging choices. Unreal documents encryption for packages and assets; Godot's versioned PCK guide describes a configuration that requires custom export templates. Those capabilities deserve an accurate account. Their presence alone does not establish the result of an extraction test. Unreal's settings · Godot's 4.0 guide.

The existence of tools such as AssetRipper, which describes exporting Unity assets into an editor-usable form, helps explain the developer's concern. It does not tell us that every build has the same exposure, or that a proposed alternative has solved it.

A protection claim needs a defined task and an observed result.

Ask a more useful question.

“Is this secure?” is too broad. A better question identifies the material, the access, and the action: can someone with a released build recover reusable art? Can they reconstruct a scene? Can a recovered asset be attributed reliably? What happens to legitimate play when the protection fails?

Access control, extraction resistance, attribution, and records of creation each answer a different part of the problem. They should be tested separately. Native compilation is not a substitute for an asset test. A signature is not a substitute for an attribution error rate. An incident report is not a substitute for a finished game.

The engine we want to build.

Blackwhole starts from the work itself: an original game, made through choices that deserve care. The aim is to make ripping and unauthorized reuse harder, while preserving the director's control over what the game becomes.

The engine is in development. Its specific protections and their limits should be described through demonstrations, rather than an absolute promise that nothing can ever be taken.

The starting point

Blackwhole.
The engine for auteurs.

The work we're building