The Project DayZ 704 Gbps DDoS Attack: 2023 Case Study

Our 2023 report on The Project DayZ recorded 704 Gbps, 68.0 Mpps and about five minutes of attack traffic, with no reported lag, crash or downtime.

VYKIX's archived report lists peaks of 704 Gbps and 68 Mpps, with an attack date of 15 April 2023 and a duration of about five minutes
Figures from VYKIX's archived report of the 15 April 2023 incident; not independently verified telemetry.
On this page

On Saturday, 15 April 2023, The Project DayZ received an attack that our incident report put at 704.0 Gbps and 68.0 million packets per second. It lasted about five minutes.

Five minutes is a short network incident. It is still long enough for a community’s evening to turn into reconnect attempts and support messages if the attack reaches the game. Our report, published the next day, said players experienced “no lag or DayZ crash/downtime.”

That remains our reported outcome. The archived account preserves the figures and the wording, but the raw telemetry and game-session records are no longer available alongside it.

Incident record: what VYKIX reported in 2023

Field Historical report
Target The Project DayZ
Attack date 15 April 2023
Report publication date 16 April 2023
Peak bandwidth 704.0 Gbps
Peak packet rate 68.0 Mpps
Reported duration About five minutes
Reported player impact No lag, DayZ crash, or downtime
Evidence available for this restoration Two archived VYKIX pages and their surviving text
Evidence not available Raw telemetry, packet captures, server logs, and independent uptime monitoring

The first archived VYKIX report and its September 2023 case-study revision carry the same figures and outcome.

The Project DayZ’s official website now describes a PvP-focused community with European servers. Its current setup should not be read back into the April 2023 incident.

What the archived evidence can prove

The surviving text is a record of what we published in 2023: the two peaks, the approximate duration and the player-facing outcome we reported.

The old page also referenced a network-panel image, The-Project-DDoS-attack.webp, which is no longer retrievable from the available Wayback capture. We have therefore kept the figures attributed to the report.

The attack vector was not specified. The record does not tell us its protocol mix, destination ports, source networks or botnet.

Why 704 Gbps and 68.0 Mpps are separate measurements

Bandwidth describes how much data arrives each second. Packet rate describes how many packets the protection layer has to process. A server owner needs both: a network can have room for more traffic while packet processing faces a different limit.

Our report included both peaks, but not the sampling interval or full time series. They describe the scale we reported, not a constant traffic level across five minutes.

For future incidents, keep the whole timeline. It lets an admin distinguish a short spike from a sustained flood and line up traffic changes with the response.

What VYKIX said protected the DayZ server

We called the service our “DayZ filter.” The 2023 report described stateful mitigation for TCP and UDP, eBPF/XDP packet processing at line rate and upstream distribution through an Anycast network.

Those were the design details we published at the time. The operational aim was to handle attack traffic before it interrupted the game. Our report said that aim was met for The Project DayZ; the available record is the historical account, not an independent availability measurement.

For an owner choosing protection now, the question is more specific than whether a service supports TCP and UDP: which checks are active on the game and query paths, and what happens when those checks reject traffic?

What this incident says about DayZ DDoS protection

The Project report put network scale and the player outcome in the same account. To make that account easier to verify, retain four kinds of record:

  1. Peak bandwidth and packet rate. Gbps and Mpps describe different limits.
  2. The full event timeline. Show how long the traffic lasted and where the peaks occurred.
  3. Attack classification. Keep the protocol, destination and filter counters behind the vector description.
  4. Application evidence. Preserve game logs, player-session data and independent uptime monitoring.

Our surviving 2023 archive lacks much of that underlying detail. The lesson for incident reporting is to keep the records behind the headline while they are available.

For the current protection model, read the DayZ DDoS protection guide and the VxShield DayZ firewall documentation. The 2.56 Tbps Ground Zero report shows a later incident with a more detailed network record.

Common questions

How large was the DDoS attack against The Project DayZ?

Our original report recorded peaks of 704.0 Gbps and 68.0 million packets per second on 15 April 2023. It put the event duration at about five minutes.

Did the Project DayZ server go offline during the attack?

Our 2023 report said there was no lag, DayZ crash or downtime. That is the reported outcome; raw network telemetry, game-server logs and independent uptime records are not retained with the archived account.

What type of DDoS attack hit The Project DayZ?

The report did not identify the vector or protocol mix. Its description of a filter covering TCP and UDP tells us about the service, not which traffic made up this attack.

What should DayZ DDoS protection report during an attack?

Ask for bandwidth in Gbps, packet rate in Mpps, the full event timeline and application records. Together, they show the network load and whether players could reach and use the game server.

Protect the DayZ traffic path

Check the upstream link, the game traffic path and the server-browser query path. Ask what the provider measures during mitigation and what records you can review afterward.

See DayZ server hosting plans | Read the DayZ DDoS protection guide

Game-aware DDoS protection for your server.

Run your game server with VxShield included. Ask about free migration and seven days free for eligible customers switching hosts. VYKIX confirms the scope, timing, and terms before the move.

Continue with