Hacker Exploited Call of Duty Anti-Cheat to Ban Thousands
Thousands of Call of Duty players were wrongfully banned due to a security flaw in Activision’s Ricochet anti-cheat system. A hacker, who identifies as “Vizor,” claims to have exploited this vulnerability for months, effectively framing innocent users as cheaters.

While Activision acknowledged in October that a bug had impacted a “small number of legitimate player accounts,” the scope of the exploit appears far greater. Vizor, who was introduced to the situation by a cheat developer known as Zebleer, stated that they were able to ban “thousands upon thousands” of players, noting that the process was “funny to abuse.”
The Mechanism Behind the Exploit
The Ricochet anti-cheat system, introduced in 2021, operates at the kernel level to detect unauthorized software. However, Vizor discovered that the system relied on scanning for specific hardcoded text strings in memory to identify malicious activity. One such signature was the term “Trigger Bot,” a common cheat that automatically fires weapons.
By sending these specific keywords through in-game private messages—known as “whispers”—the hacker could trigger an automatic ban for the recipient. Vizor explained that the game was scanning memory for these strings without sufficient context, making the system prone to false positives.
- Automated Banning: Vizor developed a script that would automatically join matches, send targeted messages, and leave, allowing the exploitation to continue even while the hacker was away.
- Targeting Streamers: Beyond random users, the hacker also targeted well-known players, some of whom publicly shared their unexpected bans and subsequent unbans on social media.
- Cat-and-Mouse Game: Whenever Activision updated its signature list, Vizor would identify the new terms and resume the attacks, feeding off the company’s attempts to catch real cheaters.
Industry Criticism of Ricochet
The vulnerability has drawn sharp criticism from industry insiders. A former Activision employee familiar with the company’s security operations described the reliance on simple memory scans for signatures as “amateur hour.” They noted that failing to protect these signatures allowed the anti-cheat system to be weaponized against the very players it was designed to protect.
The exploitation only ceased after Zebleer publicized the details of the flaw on X, forcing Activision to address the issue. Following the fix, many affected players saw their accounts restored. Reflecting on the months-long disruption, Vizor remarked, “It was nice to see it get fixed and see unbans. I had my fun.”
Activision did not respond to requests for comment regarding the extent of the impact or the security lapse.