Inside Riot Games’ High-Stakes War Against Game Cheaters

Modern competitive gaming has shifted from a hobbyist pastime into a massive industry, turning the development of software cheats into a lucrative, high-stakes business. To defend the integrity of titles like Valorant and League of Legends, Riot Games has adopted an aggressive, kernel-level approach to security that grants its anti-cheat software, Vanguard, deep access to the host operating system.

Phillip Koskinas, director and head of anti-cheat at Riot, describes his role as an “anti-cheat artisan” dedicated to a single goal: purging cheaters from their servers. By leveraging deep system permissions, Vanguard forces unauthorized software to reveal itself, allowing the studio to ban thousands of players daily.

a graph showing the number of cheaters banned by day and the type of bans,
A chart showing the number of cheaters banned per day, and the type of bans, on riot games’ first-person shooter valorant.

Security Through System Enforcement

Vanguard functions by locking down the environment in which the game runs. Koskinas explains that the software mandates the use of Windows security features like Trusted Platform Module (TPM) and Secure Boot. These protocols verify that the system has not been compromised by low-level malware or unauthorized modifications.

Beyond hardware verification, the team employs a “reconnaissance arm” that operates undercover. By infiltrating cheat-development communities, Riot staffers can monitor upcoming threats, feed misinformation to developers to establish credibility, and eventually orchestrate massive ban waves once a cheat is launched.

Psychological Warfare and Discrediting Developers

Riot’s strategy extends to public humiliation to disrupt the business models of “premium” cheat sellers. By leaking screenshots of Discord conversations or publicly banning entire user bases, the team aims to strip these developers of their most valuable asset: the reputation of being “undetected.”

The team also utilizes several distinct tactics to keep the landscape difficult for hackers:

  • Fingerprinting: Uniquely identifying hardware to prevent repeat offenders from returning with new accounts.
  • Slow Banning: Intentionally delaying bans to prevent cheat developers from quickly identifying which parts of their software were flagged.
  • Public Trolling: Using social media to mock the efficacy and maturity of those attempting to bypass security.

The Evolution of External Hacks

While “rage cheaters” often rely on cheap, easily detectable tools, sophisticated players use hardware-based exploits. These include Direct Memory Access (DMA) attacks, which involve specialized PCI Express cards that pull game data to a secondary computer, bypassing Vanguard entirely.

a screenshot showing a schematic revealing how direct access memory cheats work
A schematic showing how DMA cheats work (Image: Riot Games)

These systems often utilize HDMI fusers to overlay “wallhacks” or use screen-reading AI to power “aimbots.” Koskinas admits that while this is an iterative arms race, the goal is to force cheaters to “humanize” their software so significantly that the advantage becomes negligible.

Looking ahead, Riot remains committed to its kernel-level approach. Koskinas emphasizes that transparency is the best policy when operating such an intrusive tool, noting that while the technical inner workings remain protected, the studio intends to keep the community informed on how these privileges are used to maintain competitive fairness.

Deixe um comentário

O seu endereço de e-mail não será publicado. Campos obrigatórios são marcados com *