A code watermark helps prove a stolen or reskinned Unity game was built from your original project when filing a claim on major app stores.
By Tim UhlottFounder|Last updated: September 6, 2026|18 minutes read
cybersecurityobfuscationwatermark
In the new age of AI, proof of game ownership is becoming more and more important. Game clones and flips are being created faster than ever.Your Android APK or Windows build can be taken, the icon changed, a few textures swapped, the store listing renamed, and then uploaded as someone else's game. Stores will not always catch this on their own, unfortunately. You need proof that the game or app is yours.A code watermark can provide that proof. It does not stop the theft. What it does is let you go to Google Play (opens in a new tab), Steam (opens in a new tab), or another DMCA form and show that the clone was built from your game or app.This is for game developers who ship Unity titles and want something stronger than "it looks like our game."
The problem is real
But clone and flip can mean different things.Stolen game. An attacker dumps your APK or game folder. They replace the package name, ad SDK, icon, and some art, then republish it. They did not remake your game, they just took the copy you already shipped. This is called repackaging, and it is the case a watermark is built to fight.Asset flip. A studio buys the assets from the Unity Asset Store as you and ships a junk title. That is shovelware, and it is usually not your game.Gameplay clone. A publisher copies the idea of a hit like Flappy Bird, Fall Guys, or an idle shooter. Game mechanics are hard to copyright but your art, audio, and compiled code can be.A watermark is built for the first case. That case is common enough that researchers have measured it for more than ten years.Here is the picture, one store at a time.
Android is the biggest target
On Google Play, Bitdefender (opens in a new tab) scanned 420,646 apps and found 5,077 of them, about 1.2%, that were full copies of other developers' work. Once shared libraries were set aside, more than 90% of each copy was identical. They watched one paid game pick up four free copies in a single week. Columbia's PlayDrone (opens in a new tab) crawl found that about 25% of Play content was duplicate, though most of that was same-developer rebrands and spam. Of the similar free apps they labeled, 42,308 were clones by different authors.Off the official store, it gets worse. A tool called APPraiser (opens in a new tab) checked more than 1.3 million apps and found that only about 6% of Google Play apps looked similar to another app, and most of those were a studio reusing its own work. On the Chinese third-party store Anzhi, about 26% looked similar, and roughly half of those were true clones. Other studies of third-party Android markets agree: Zhou et al. (opens in a new tab) measured 5% to 13% repackaged, a study of Chinese markets (opens in a new tab) found about 20% clones with Google Play as the main source, and a 2024 sample of "original" games (opens in a new tab) found 93 of 196 (47%) were repackaged clones of Play titles.Those copies are not harmless. Of the clones that moved from Google Play onto third-party stores, APPraiser found 76% carried malware. It is an old trick: Zhou and Jiang (opens in a new tab) showed that 1,083 of 1,260 Android malware samples (86%) were real apps with an added payload, so someone steals the game, injects ads or spyware, then redistributes it. AdRob (opens in a new tab) estimated that cloned developers lost about 14% of ad impressions and 10% of users to the copies.
iOS looks safer than it is
Apple says less about clones, but its store is not clean. Apple puts out a yearly fraud report (opens in a new tab), and in 2025 it turned away more than 371,000 app submissions for being spam, copycats, or misleading, and it stopped nearly 7,800 apps it judged deceptive from ever showing up in search. Researchers have studied this side too. One project trained a tool on 10,100 iOS action games (opens in a new tab) over five years just to tell copycats apart from originals. So on iPhone the problem is real and measured, even though Apple never prints a single "percent stolen" number. "It is on the App Store" does not mean anyone checked whether it is yours.
Steam and the PC stores
Windows is a different market. There is no matching study on how much of Steam is stolen Unity executables. Selling someone else's finished .exe under a new Steam page is a worse business than dumping a crack on a download site. What Steam does have is a lot of shovelware. In 2017 Valve removed 173 titles (opens in a new tab) from one operator who had been mass-shipping nearly identical products (opens in a new tab). The flood is easy to see today. In 2024 about 19,000 games launched on Steam (opens in a new tab), and roughly 79% of them were tagged "Limited," a status Valve gives titles that have not sold or been played enough. Valve treats it as its main filter against shovelware, scams, and asset flips. It also runs cleanup waves, like a 2023 sweep (opens in a new tab) that pulled about 90 asset-flip and bootleg games and banned the accounts behind them. Those cases are flips and clutter, not stolen copies of one indie game. If you ship on Steam, expect piracy first. If you ship a Unity game on Android, expect someone to try the APK.
The smaller stores lean on you
The smaller stores have the least public data and the lightest screening, so there the work falls even more on you. Epic's store bans scams and impersonation (opens in a new tab) in its rules, and it does act. A crypto game called Paradise (opens in a new tab) faked an Epic partnership and reused Grand Theft Auto assets, Epic delisted it, and it came back under a new name. On itch.io there are no clean numbers at all, only a steady run of reports from developers whose games, and even profile pictures, were re-uploaded by fake accounts to spread malware (opens in a new tab). Itch's own staff say they mostly act once someone reports the page. On stores like these, the report you file, with proof attached, is the whole enforcement system.
Even well-funded games are wide open
None of this needs a skilled hacker. Promon's 2023 game security report (opens in a new tab) tested 357 high-revenue mobile titles. Only 15.7% had any repackaging detection, and the testers could repackage about 85% of them. This is not only a game problem: in a separate test Promon repackaged 61% of the banking and trading apps (opens in a new tab) it looked at, and those are supposed to be the careful ones. If the top-grossing studios ship builds this open, an indie title is an easy target.
A real Unity case
In 2020 a Unity developer posted that someone had stolen their Play APK (opens in a new tab). The thief replaced the bundle identifier and ad units, added location, calendar, and phone permissions, and published it on another account. It was not a remake, it was a full copy of files matched an older version by name and size. The developer's company name was still sitting in globalgamemanagers.Google did not catch it on upload. The first DMCA reply was "are you the authorized copyright agent?" That is a paperwork problem, not a technical one, but it is also why the leftover strings and matching file sizes mattered. The store does not know the clone is yours until you can show it.That leftover string worked as an accidental watermark, but you should not rely on accidents.
The stores remove millions and still miss yours
The big stores are not sitting still. In 2024 Google blocked about 2.36 million apps (opens in a new tab) that broke its rules and banned 158,000 developer accounts. In 2025 it blocked another 1.75 million (opens in a new tab) and banned 80,000 more. Apple turned away over 371,000 (opens in a new tab) copycat, spam, or misleading submissions in 2025.Those are huge numbers, and none of them are your clone. Those systems hunt for malware, spam, and rule-breaking across millions of apps at once. They do not know that one reskin, with a new name and new ads, was built from your code. Making that link is the one part of the job only you can do, and only if you saved something to compare against before the theft. The watermark is that something.
Why the store name will not save you
Unity writes the product name (opens in a new tab) and application identifier (opens in a new tab) into the player. Both can be read at runtime and they are useful for your UI, deep links, and telling which build a normal user has installed.But they are useless as proof of ownership against a copy cat.Application.productName is just a display string, and the clone will have a new one. Application.identifier is the Android package name or the bundle id you typed in Player Settings. The package name is the first thing a republisher changes, because they cannot sign and upload a second listing without changing it. On a normal Windows game there is no store-enforced package identity at all.So a runtime check that says "the package name must be com.studio.mygame" fails the moment the APK is re-signed. And a listing that uses their name proves nothing about whose code is inside.Platforms act on your rights, not on a similar title. Google Play keeps impersonation (opens in a new tab) (the listing misleads users) separate from copyright and trademark (opens in a new tab) (they copied your work). Pick the wrong form and the case stalls. A practical takedown guide (opens in a new tab) and DMCA templates for game developers (opens in a new tab) all come back to the same point: you have to show that the content is yours."It looks like our game" is a start. But "the binary is ours" is what gives you legal standing.
What a code watermark actually is
A watermark is a secret you pick at build time, turn into a signature, and hide inside the game or app.You choose a phrase that only your team knows. Then place it in locations only you know, or in completely random places.That is the whole idea. The signature is not a license check, it is just a fingerprint you can identify later.Open or download the suspect game or app, and look for that fingerprint. A match tells you this game or app went through your watermark pass, with your text, for that build. It is much stronger than "this skins looks like ours." It says "this is our code."
Do not want to build this yourself? Use the GuardingPearSoftware Obfuscator
You do not have to write any of this. The GuardingPearSoftware Obfuscator brings with the release 2026.6.0 a feature called Assembly Watermark. You turn it on enter a custom phrase and when you build, it writes a unique fingerprint into every assembly (compatible with Mono/CoreCLR and IL2CPP). Every module gets the same mark, tied to your app and your secret. Players never see it, and nothing runs while the game is playing. The created fingerprint then gets printed in the Unity console, for an easy copy and paste for later proof usage.If you suspect a clone, you can open the suspect game or app and look for that fingerprint. A match tells you this game or app went through your watermark pass, with your text, for that build.
How you use it against a platform
When you find a listing that is your game with a new coat of paint:
Download their package. Save any relevant infos. Screenshot the store page and the developer account.
Show the match. Point at the same fingerprint in their binary that only your watermark pass would have written. Putting it side by side with your own build is stronger than a screenshot of gameplay.
File the right claim, on the store's own form. Each store has its own official page. Send the same evidence pack to whichever one hosts the clone.
Say who you are. The Unity thread above stalled first on "authorized copyright agent," not on any technical doubt. File as the rights holder, or attach the assignment.
Stores are not courts, this is important to know. They want a short, plain packet: you own it (with your proof), here is the clone, here is the overlap, take it down. A watermark turns "we think they stole it" into "here is a signature we put in before they ever saw the APK."
What a watermark is not
It will not stop the dump. Promon's numbers are clear that most commercial mobile games can be repackaged. IL2CPP makes code theft harder, but it does not hide your textures.It will not survive someone who strips the unused metadata and rewrites the whole IL. Few people do that much work. Plenty of people do "new package name, new ads, old levels."It is not a runtime Application.identifier check. Those APIs describe the install you are running right now, and the thief already changed them.It is not legal advice, and it is not a replacement for registering copyright where that helps you. It is evidence you can attach to the process platforms already run.
What to do on your next build
Add a watermark or fingerprint to every next build you ship.
Make sure to keep a reference build, and the watermark.
When you find a clone, collect the package first, then file for copyright.
If you have to file a claim to a store that has no custom form, feel free to use this template:
Subject: DMCA Takedown Notice - [YOUR GAME NAME] - [INFRINGING LISTING NAME]
To the Designated Copyright Agent of [STORE / HOST NAME],
This is a notice of copyright infringement under the Digital Millennium
Copyright Act, 17 U.S.C. § 512(c), or the equivalent provisions of your
local law.
1. The copyrighted work
I am [YOUR NAME], [YOUR ROLE] at [YOUR COMPANY NAME], the owner of the
copyright in the game "[YOUR GAME NAME]", a [GENRE] game for [PLATFORMS].
The work includes its compiled code, artwork, animations, audio, level
data, and characters. It was first published on [DATE] and is available
here: [URL TO YOUR OFFICIAL STORE LISTING]
2. The infringing material
The following listing is a repackaged copy of our build, republished under
a different name, icon, and developer account:
[URL TO THE INFRINGING APP / GAME]
Developer account: [INFRINGING DEVELOPER NAME]
Package or app ID: [INFRINGING PACKAGE NAME / APP ID], if known
3. Evidence
Our build carries a private code watermark that we embedded before release.
The same fingerprint is present in the infringing binary:
- Watermark: [THE WATERMARK PROOF]
- Location in the infringing file: [FILE NAME AND WHERE THE MATCH WAS FOUND]
Additional evidence is attached: [LIST OF ATTACHMENTS, e.g. side-by-side
screenshots, matching file names and sizes, hash of the downloaded package,
date of download]
The infringing listing profits from our work through [ADVERTISEMENTS /
IN-APP PURCHASES / PAID DOWNLOAD].
4. Statements
I have a good-faith belief that the use of the material described above is
not authorized by the copyright owner, its agent, or the law.
I swear, under penalty of perjury, that the information in this notice is
accurate and that I am the copyright owner or am authorized to act on the
owner's behalf.
5. Request
Please remove or disable access to the infringing listing and let me know
once this has been done. If I do not hear back within [10] business days,
I will take further steps to protect our rights.
6. Contact and signature
[FULL LEGAL NAME]
[ROLE], [YOUR COMPANY NAME]
[STREET ADDRESS]
[CITY, POSTAL CODE, COUNTRY]
[PHONE NUMBER]
[EMAIL ADDRESS]
Signed: [FULL LEGAL NAME] (typed name counts as an electronic signature)
Date: [DATE]