To protect competitive integrity from a lucrative illicit industry, Riot Games and its head of anti-cheat, Phillip Koskinas, are employing deep kernel-level technology, undercover community operations, and aggressive hardware tracking to drive cheater presence in Valorant competitive matches below 1% globally as of early 2025.
What began as a hobby for tinkerers finding vulnerabilities in early games has evolved into a full-fledged commercial market. Today, cheat developers build and sell software designed to grant paying players an unfair edge. In response, game studios have significantly bolstered their anti-cheat units. These specialized teams are tasked with banning offenders, disabling illicit software, and taking legal or technical action against cheat developers. To stay ahead, an increasing number of studios are adopting the somewhat controversial practice of deploying kernel-level security tools, granting their software top-tier administrative rights to monitor machine activity during gameplay.
One of the industry’s most prominent deep-level security systems is Vanguard, created by Riot Games—the studio behind massive online hit League of Legends and competitive shooter Valorant.
Vanguard operates by fundamentally forcing unauthorized code to reveal itself, according to Phillip Koskinas, Riot’s director of anti-cheat. Koskinas, who refers to himself on LinkedIn as “an anti-cheat artisan,” views his role as a singular mission to eradicate cheating from online games.
Through Vanguard and Koskinas’s specialized division, Riot issues thousands of account bans daily in Valorant.

Data indicates these anti-cheat strategies are delivering results. According to Riot, fewer than 1% of ranked competitive matches in Valorant globally contain active cheaters as of early 2025.
In a technical breakdown, Koskinas outlined the defense mechanisms Riot utilizes: leveraging built-in Windows security protocols, uniquely identifying cheater hardware, infiltrating underground hacking networks, and deploying psychological pressure to undermine cheat creators.
Enforcing Windows Security at the System Core
A core foundation of Vanguard’s effectiveness lies in its deep operating system privileges, enabling it to mandate essential native Windows security protections.
Vanguard strictly enforces features like the Trusted Platform Module (TPM)—a dedicated hardware cryptoprocessor—and Secure Boot. These functions verify that system files and hardware have not been tampered with prior to launching the operating system. Furthermore, Vanguard verifies that all system hardware drivers are fully updated to prevent exploit injections, while systematically blocking unauthorized code execution within kernel memory.
Koskinas noted that Vanguard relies heavily on standard security protocols established by Microsoft and hardware manufacturers, using them to guarantee a secure, controlled execution environment before the game runs.
Undercover Infiltration and Psychological Tactics
Riot’s anti-cheat initiative extends beyond technical defenses into operational intelligence and counter-intelligence tactics.
The team maintains a dedicated intelligence unit responsible for monitoring emerging threats and acquiring cheat software. Team members utilize undercover personas that spend years embedded within hacking networks and developer communities.
To maintain cover, investigators sometimes share technical anti-cheat insights disguised as reverse-engineered research. Once embedded, the team monitors cheating software throughout its development lifecycle, allowing developers to build a user base before executing a mass ban on all active customers upon release.
To avoid detection by undercover agents, some cheat developers market high-priced “premium” tools limited to a restricted customer pool. These software packages can cost thousands of dollars, targeting users who are cautious to avoid obvious cheating behavior.
Because these vendors rely heavily on their reputation for remaining undetected, Riot active counters them by publicly exposing their operations—executing sweeping bans on their clients or publishing internal screenshots taken from private developer Discord servers to publicly undermine their credibility.
Strategic timing is also crucial. Instead of issuing instant bans upon detecting a cheat, Riot frequently delays enforcement actions. Ban waves executed on a controlled schedule prevent cheat creators from easily identifying which specific detection mechanism caught them, slowing down software iteration.
For persistent offenders, Vanguard collects unique hardware profiles—commonly known as “hardware fingerprinting”—to prevent banned players from simply creating a new account on the same machine. On social media, Koskinas and team members regularly mock repeat offenders publicly, labeling them as “a brainless pathogen” lacking the fundamental skill to play legitimately.
Categorizing the Modern Cheater’s Toolkit
Riot’s security intelligence divides the cheating demographic into two distinct groups based on software sophistication and hardware requirements.
The primary group consists of low-tier “rage cheaters” using widely accessible, inexpensive scripts that Vanguard catches quickly—a category Riot developers privately label “download-a-ban.” Many of these users are younger players drawn to short-term power power fantasy dynamics, frequently repeating a cycle of getting banned and acquiring temporary accounts until they eventually stop playing.
The second, more sophisticated group relies on hardware-assisted “external” cheats designed to bypass standard software scanning mechanisms.

Hardware Attacks: DMA Cards and HDMI Fusers
A primary method of external cheating involves Direct Memory Access (DMA) attacks. Players install custom hardware—such as modified PCI Express cards—that reads Valorant memory and streams it directly to a secondary computer running outside Vanguard’s reach.
The secondary system parses in-game coordinates, mapping player positions, geometry, and hidden targets onto a separate monitor radar screen. Advanced setups incorporate HDMI fusers, which project this parsed secondary data directly over the user’s primary monitor display, enabling functional wallhacks and Extra-Sensory Perception (ESP) visuals in real time.
Computer Vision and Hardware Aimbots
Another hardware method involves screen-reading technology. In these configurations, a video capture device routes the main display output into a second PC, which utilizes visual detection algorithms to identify target hitboxes—such as opponent head outlines. The second PC then sends physical input commands to a microcontroller (like an Arduino) wired directly into the player’s mouse, enabling automated targeting assistance known as an aimbot.
While effective, these systems require a powerful dual-PC setup with dedicated GPU processing to analyze frames without latency. Furthermore, behavioral detection systems eventually flag mouse movements that exceed human reaction thresholds, forcing cheat developers to reduce targeting speeds to the point where competitive advantage becomes minimal.
Emerging AI Threats and the Need for System Transparency
Looking forward, anti-cheat engineers are increasingly focused on computer vision models trained on real-time screen data to replicate human input patterns automatically.
In games like Valorant, where character models feature high-contrast color outlines, basic pixel-recognition scripts can already trigger automated firing mechanisms based on specific color densities within target zones.
Despite broader industry debates regarding user privacy and system access, Riot maintains that kernel-level architecture remains essential for competitive PC titles like Valorant. Disabling ring-0 level protections would leave operating systems vulnerable to unmonitored kernel exploits.
To address privacy concerns associated with persistent system access, Riot has committed to regularly updating players through official engineering dev blogs and retrospectives detailing how system permissions are managed behind the scenes.













Leave a Reply