Engineering & reverse engineering · 2024–2025
Dark Seal
Exalted, a League of Legends skin hack: from transforming game resources to a desktop system with asset delivery and synchronized parties.
- Period
- 2024–2025
- My role
- Creator & owner of Dark Seal; creator of Exalted
- Product
- Desktop & services
- Status
- Closed; historical archive
- reported site visits
- 1.2M
- lol-skins stars
- 942
- lol-skins forks
- 227
Historical traffic reported by Dark Seal, without an independent audit. Stars and forks recorded on 9 September 2026; GitHub counts change. Context and sources
A skin hack, from catalog to game
I’m Bruno Bezerra Trigueiro. I created and owned Dark Seal, a software engineering and reverse-engineering project that operated primarily in 2024–2025. I also created Exalted, a League of Legends skin hack, developed with a team of contributors.
A user chose skins from a desktop catalog. Behind that selection, Exalted downloaded packages, processed local files and coordinated native modding tools to prepare resources for the game. Authentication, licensing, updates and party mode were part of the system. Each client downloaded and prepared assets locally; Party synchronized the participants’ selections.
What I built
My work crossed those component boundaries: Exalted client development, authentication and persisted sessions, moving catalogs behind APIs, and integrating the client with party services. In Navori, I worked on the backend and extracted party functionality into a separate service.
I also worked on the lol-skins collection, including asset-behavior fixes and the packaging change from Fantome to ZIP. I built Shadowflame, the Python layer for batch package repair, with WAD extraction, resource-definition edits, and parallel conversion and repacking. Its README credits me as koobzaar.
From selection to native process
The Electron client used React and TypeScript for its interface. The renderer sent requests through the preload and IPC to the main process, which handled sessions, networking, files and native processes. That was the boundary between the interface and operations on the user’s machine.
- SelectCatalog and party selections
- PrepareDownload packages and import mods
- BuildConstruct the overlay with CSLOL
- RunStart the native overlay process
The overlay assembled replacement resources into a profile for the game. Exalted coordinated import, construction and execution through CSLOL tools, including retries and timeouts for import and construction. The native loader came from that external project.
- Navori
- A Node/Next.js backend with MongoDB state for accounts, licensing, catalogs, assets and updates. It distinguished user identity, entitlement and generated access keys. The client persisted its session locally and revalidated it with the server.
- Party
- A separate Node/Express service: HTTP for joining, leaving and changing selections; WebSockets for broadcasting full party state. MongoDB stored membership and selections, while connections and live presence stayed in process memory. The service had its own Docker/Compose configuration.
Delivering metadata and packages
Catalogs used ETags to recognize unchanged data, deltas to describe changes, and chunks identified by hash. The client checked newly downloaded chunks against the manifest before storing them and could reuse cached data after ordinary network failures. These checks maintained consistency with the supplied catalog.
Navori also generated the metadata consumed by electron-updater. Later development added temporary signed URLs for S3-compatible object storage to asset delivery. This separated authorization to download from transferring the package itself.
Understanding the resource underneath
Asset work meant dealing with League’s proprietary resource conventions. BIN files described resources and their references; WAD archives grouped game data. A correct filename was insufficient: internal identifiers also had to match the slot being replaced.
CDragonSkinExtractor, credited to jinjutwo and nylish, shows that transformation. It fetched definitions from CommunityDragon, converted BIN to JSON through ritobin, changed the skin and ResourceResolver identifiers to the base Skin0 slot, then rebuilt BIN, WAD and ZIP output. This routine prepared replacement definitions; it did not collect every texture and model dependency.
In my Shadowflame work, the path started with existing packages: extract WAD, convert BIN to text, repair references with regular expressions, and repack. Its output was specialized for skin0.bin. Parallel extraction, conversion and packing made the same repair applicable across batches.
This was engineering around reverse-engineered resource semantics: understanding which references to change and connecting that knowledge to a repeatable workflow. Binary conversion belonged to moonshadow565’s ritobin; native WAD and overlay tools came from LoL-Fantome’s CSLOL. CommunityDragon supplied data and hashes used by the tooling.
Responsibilities move out of the client
The system changed as it grew. The party and catalog migrations show how the client came to delegate work to services.
- November 2024: client-hosted parties. Kohelet introduced the PeerJS implementation. A host client distributed state over peer data connections.
- March 2025: service integration. I moved party integration into Exalted’s main process over HTTP/WebSocket. Party functionality briefly lived in Navori before WebSocket separation and removal of the party routes in late March.
- Catalogs move to the backend. The March migration replaced local repository readers and catalog generation with API retrieval, caching and response handling in the client. Navori took on catalog generation from repository data.
Later in 2025, still using Electron, Exalted gained IPC integration with the League Client’s local HTTPS API for summoner and champion-select data, alongside temporary asset URLs. These additions belong to the November development branch; they do not describe all features of June’s 1.6.3 client or establish a release date.
A collection maintained by a community
lol-skins organized packages by champion, skin and chroma. The recorded tree contained 10,811 entries, including directories and documentation. The repository had 942 stars and 227 forks in the 9 September 2026 record; those counts are neither Exalted users nor figures from shutdown.
The Dark Seal retrospective reports approximately 1.2 million total site visits and about 570,000 views in one 14-day period. These are historical statistics reported by the organization, without independent measurement.
Creating the project did not mean writing every subsystem alone. Alongside Kohelet’s PeerJS work, nylish contributed the earlier Flask server, private artifact access and later integrations. jinjutwo, CresianaRVN, nylish, kyewyve, DarkSeaI and others maintained the asset collection with me. CDragonSkinExtractor credits jinjutwo and nylish; my publication of the Party archive does not make every line of the service mine.
What remains
Dark Seal closed in November 2025. Its public account reports a legal notice received on 14 November 2025, followed by the end of development, distribution and services. The repositories below are historical archives without maintenance or support. The full Exalted client and Navori source are not in these public repositories.
- ShadowflameBatch repair, conversion and repacking; credit to koobzaar.
- PartyHTTP/WebSocket service, state and Docker configuration. Development history squashed before publication.
- CDragonSkinExtractorBIN identifier transformation and WAD packaging.
- lol-skinsPackage collection and community maintenance history.
- Dark Seal organization archiveProject account, reported traffic and closure.