Virtual Gifting & Coin Economy Architecture: DB Design & Anti-Fraud Guide

The video stream is the entertainment, but the coin economy is the business. Here is how to design a fault-tolerant virtual gifting ledger, verify Apple and Google IAP server-side, render full-screen SVGA animations without frame drops, and prevent coin duplication exploits.

Soban Rashid Qazi15 min read

In any live streaming or voice chat application, the video and audio streams are just the customer acquisition hook. The financial ledger is the actual business. If your video stutters for a second, a user might refresh; but if a user pays $100 for coins and they do not appear, or if a bug allows malicious users to duplicate coins and cash out real diamonds, your platform can be bankrupted in a single weekend.

Building a virtual gifting economy is closer to building a digital banking ledger than building a social network. You need ACID-compliant transactions, double-entry bookkeeping, cryptographic receipt validation for Apple and Google stores, and high-throughput Redis state locks for gift storms.

Rule #1: Treat In-App Coins Like a Double-Entry Bank Ledger

Amateur developers store user balances as a single integer column in a database: "UPDATE users SET coins = coins - 100 WHERE id = 1". This is an invitation to financial catastrophe. Any network timeout, race condition, or unhandled promise rejection desynchronizes the database.

A production gifting engine must implement double-entry bookkeeping with immutable transaction logs:

Ledger EntryDebit AccountCredit AccountPurpose
Coin PurchasePlatform Payment Gateway EscrowUser Coin WalletUser buys 1,000 coins via Apple StoreKit or Google Play Billing.
Gift DeductionUser Coin WalletPlatform Escrow BalanceUser sends a 500-coin Lion gift in Room #102.
Diamond PayoutPlatform Escrow BalanceHost Diamond BalanceHost receives 70% share (350 diamonds) credited to withdrawable balance.
Platform CommissionPlatform Escrow BalancePlatform Revenue AccountPlatform retains 30% gross profit margin on the transaction.
Agency SplitPlatform Revenue AccountAgency Wallet BalanceAgency manager receives 5% commission for managing the host.
Virtual Gifting Double-Entry Ledger Schema

Because every coin movement is logged as an immutable credit and debit pair, the sum of all platform accounts must equal zero at all times. Automated hourly reconciliation scripts catch discrepancies immediately.

Handling 500 Gifts/Second with Redis Lua Scripting

During high-stakes PK battles, thousands of users hit the gift button simultaneously ("gift spamming"). If every gift triggered five SQL queries inside a transaction, your relational database would deadlock within seconds.

To handle thousands of gifts per second with zero lag, we split the architecture into an In-Memory Hot Path and an Asynchronous Persistence Queue:

  1. Redis Lua Script (Hot Path): The user balance check, gift validation, and balance deduction occur inside a single atomic Redis Lua script. Lua scripts run atomically in single-threaded Redis, guaranteeing zero race conditions without slow database locks.
  2. Instant Socket.IO Broadcast: Once the Lua script decrements the Redis balance, the server instantly emits the gift event to the room via WebSockets with sub-30ms latency.
  3. Asynchronous BullMQ Pipeline: The completed gift payload is pushed into a Redis queue (BullMQ). Background worker microservices pull transactions from the queue and write permanent double-entry logs to MariaDB in bulk batches.

Bulletproof StoreKit 2 & Google Play Billing Validation

Fraudulent in-app purchases are the number one cause of revenue loss for new streaming apps. Scammers use modified APKs, fake receipt generators, and man-in-the-middle proxies to trick apps into awarding coins.

  • Never Validate Receipts on the Client: The mobile client must NEVER directly award coins. The mobile client simply receives a signed transaction token from the App Store and sends it to your backend.
  • Apple StoreKit 2 JWS Verification: We use Apple’s modern StoreKit 2 server APIs to verify cryptographically signed JSON Web Signatures (JWS) directly with Apple servers.
  • Google Play Developer API: Server-side validation against Google’s androidpublisher v3 API, checking purchaseState === 0 and verifying that the orderId has never been processed previously.
  • Idempotency Keys: Every receipt is hashed and recorded. If a duplicate receipt arrives, the server rejects it as a replay attack.

Rendering 3D SVGA Animations Without Lag

Bigo-style gifts (flying sports cars, dragons breathing fire, fairy castles) are complex animations with audio effects. If you render them as uncompressed MP4 videos or heavy GIF files, the mobile app will stutter and drop stream frames.

We use the SVGA (Scalable Vector Graphics Animation) format. SVGA files compile vector graphics and compressed image sprites into tiny binary packages (usually 200KB to 1.5MB) that render smoothly on mobile GPU threads with full alpha-channel transparency.

Virtual GiftingDatabase DesignIn-App PurchaseSecurityFintechSVGA

Frequently asked questions

What is the standard diamond-to-coin conversion ratio?

Most commercial apps (like Bigo Live and Tango) use a 1:1 or 2:1 coin-to-diamond model, where 100 coins sent by a viewer yield 70 to 80 diamonds for the streamer, leaving 20% to 30% gross platform margin before payment gateway fees.

What happens if a user requests a refund from Apple or Google after sending gifts?

Apple and Google provide real-time server notification webhooks for refunds and chargebacks. Our backend automatically listens for these notifications, identifies the offending user, freezes their account, and deducts the corresponding coin balance to prevent triangular fraud.

Can we support custom 3D gifts designed by our own 3D artists?

Yes. Our apps support the open SVGA specification. Your 3D designers can create animations in Adobe After Effects or Blender and export them directly to SVGA format using standard plugins.

How do you handle payouts and withdrawals for streamers?

Streamers can bind their local bank accounts, PayPal, or crypto wallets in their profile. When they reach the minimum threshold, they submit a withdrawal request which admins approve via the master admin panel.

Can gift prices be adjusted dynamically without releasing an app update?

Yes. All gift metadata (name, coin cost, SVGA download URL, sound effect URL, category) is fetched dynamically from the backend API, allowing you to add holiday gifts and adjust prices on the fly without waiting for App Store review.

Paying too much for streaming minutes?

Send us your participant-minutes, average room size and peak concurrency. We will tell you what migrating would actually save — including when it would not be worth it.

Related services

More from the blog