Riot locks nearly 300,000 ranked accounts: Vanguard has crossed into a new territory
**Câu trả lời cốt lõi**: Riot Games đã khóa hoặc xử lý gần 300.000 tài khoản League of Legends và VALORANT vì gian lận xếp hạng, sau khi tích hợp Vanguard vào tháng 9 năm 2025; kế hoạch tiếp theo gồm xác thực đa yếu tố, TPM 2.0 và yêu cầu xác minh khác nhau theo bậc xếp hạng. **Dữ kiện chính**: - Gần 300.000 tài khoản bị xử lý, tương đương khoảng 0,2% trong ước tính 140 triệu người chơi hoạt động hàng tháng. - Vanguard, phần mềm chống gian lận tầng kernel của VALORANT, được tích hợp vào League of Legends từ tháng 9 năm 2025. - Riot dự kiến bổ sung xác thực đa yếu tố, TPM 2.0 và xác thực phần cứng; yêu cầu có thể khác nhau theo bậc xếp hạng. - Người chơi xếp cùng tài khoản đang được boosting có thể mất điểm xếp hạng dù chỉ dùng tài khoản của chính mình. - Phillip 'mirageofpenguins' Koskinas của Riot Games cho biết chơi tài khoản phụ không tự động bị coi là gian lận; tám trường hợp sử dụng hợp lệ được liệt kê. **Nguồn**: Riot Games, công bố tháng 9 năm 2025, không kèm kiểm toán độc lập | Cross-checked: VuaBong.vn **Hỏi đáp liên quan**: - Q: Vì sao tỷ lệ 0,2% quan trọng hơn con số 300.000? A: Vì tỷ lệ đó cho thấy quy mô tương đối của đợt xử lý nhỏ hơn nhiều so với ấn tượng mà tiêu đề tạo ra. - Q: Khi nào người chơi thấy thay đổi thực tế? A: Khi TPM 2.0 và xác minh theo bậc xếp hạng được triển khai ngoài phạm vi thử nghiệm theo kế hoạch đã công bố. - Q: Thị trường boosting có biến mất không? A: Theo chỉ số theo dõi thị trường xám của VangBong.vn, nhiều khả năng giá boosting tăng và hoạt động dịch chuyển sang các tựa game ít bị kiểm soát hơn.
A percentage buried at the end of the post
At eleven at night in Busan, I reopened Riot Games' official support post and stopped at the last line: nearly 300,000 League of Legends and VALORANT accounts had been locked or actioned for ranked cheating. Immediately below it, the post supplied its own division — roughly 0.2 per cent of monthly active players. I read that figure three times, because I knew what would survive once the story spread: "Riot banned three hundred thousand accounts" travels well, while "0.2 per cent" is almost never quoted.
Three years ago, on a night like this one, I sat in Hanoi recording an episode on Vanguard when it was still a VALORANT-only story: a kernel-level anti-cheat with deep operating-system access and a promise to clean up ranked. I said, half joking, that if Riot ever dared bring Vanguard into League of Legends, it would be the biggest change to the game since the old Elo system was retired. In September 2026, they did it.

What I did not anticipate was not the integration itself. It was what Riot chose to use Vanguard for once it was inside.
Riot has moved beyond catching cheat software
In VALORANT, Vanguard hunts cheat software: aimbots, wallhacks, scripts, hardware interference. Moving into League of Legends, its remit widened considerably — into behaviour inside the ranked ladder. This is the shift I consider the most consequential part of the story, and the headline about three hundred thousand accounts hides it: Vanguard is no longer purely an anti-cheat tool; it is being elevated into platform-level behavioural enforcement infrastructure, where client software acts as investigator and court at the same time.

Definitions matter here. Boosting is a service in which a highly skilled player logs into someone else's account to raise that account's rank. Hitchhiker is Riot's term for players who use their own accounts but queue alongside an account being boosted. Smurfing is playing on a secondary account below one's true skill level. Seen from a distance the three look similar, but Riot treats them very differently, and that difference deserves separate analysis.
Riot's stated rationale is compact: improve player experience and limit negative effects. Attached to it is a technical change the coverage largely skipped. When the system detects a cheater or a leaver in a match, the remaining players are protected from losing ranked points for a game that was bent out of shape before it began. To me, that is the most practically valuable detail in the entire announcement. It generates no headlines, but it changes what grinding the ladder feels like every night.
Three account categories and the economics underneath
The enforcement splits into three behavioural groups. The first is accounts boosted directly — owners who paid or arranged for someone else to climb for them. The second is hitchhikers, players keeping their own accounts but queueing alongside a boosted one. The third is repeat multi-account offenders, who face the heaviest penalty: beyond the secondary account, the main account can also be suspended.
That Riot explicitly mentions main accounts is a significant signal. It pushes the cost of running a boosting service from "lose a throwaway account" to "lose your playing identity". For anyone earning money from this, that is a change to the risk model, not to the size of the fine.
Based on my experience tracking ranked matches and account-trading communities over several years, the economic driver has to be stated plainly: boosting exists because pay at the bottom of the professional pyramid is too low, while demand for a prestigious rank never disappears. A semi-professional player at a high rank has genuine skill, but income from small tournaments will not cover rent, so taking boost orders becomes supplementary income. An office player who wants a Diamond border to show off in a group chat will pay. The two sides meet, and a market exists.
Supply-side enforcement does not delete a market, it reprices it. As Vanguard tightens across League of Legends and VALORANT, the risk cost for sellers rises, and in a gray market with fixed demand, that increase is almost certain to be passed into the price. Locking three hundred thousand accounts is a heavy blow, but it does not answer why people still want to buy, or why others still need to sell.
The 140 million denominator and an unmentioned blind spot
Every figure in the announcement comes from one side. Roughly 120 million monthly League of Legends players, roughly 20 million for VALORANT, about 140 million in total — all phrased as "estimates show", with no independent verification attached. Three hundred thousand divided by 140 million is 0.2 per cent. The arithmetic is correct, but the denominator has a hole in it.
In mainland China, League of Legends and VALORANT operate inside Tencent's ecosystem, with anti-cheat and account verification infrastructure deployed separately and not necessarily sharing the global Vanguard mechanism. The announcement never says whether the three hundred thousand includes, excludes, or can be separated from Chinese servers. If it is a global-excluding-China figure while the 140 million denominator includes Chinese players, the 0.2 per cent understates the problem and real coverage is even thinner. If the three hundred thousand already includes China, then enforcement intensity on smaller servers is being flattered.

I raise this not to nitpick a calculation, but to point out that the entire quantitative backbone of this story originates from the enforcing party itself — with no third-party audit, no false-positive rate, and no appeals mechanism described. For a campaign touching three hundred thousand accounts, that transparency gap is larger than the cheating it targets.
The time window matters too. Vanguard was integrated into League of Legends in September 2026, so the three hundred thousand is most likely a cumulative tally over a quarter or less, not an annual figure. If so, the annualised rate is materially higher than the round number suggests. I flag that as inference rather than fact, but it is enough to stop me reading three hundred thousand as final.
The hitchhiker doctrine and the limits of evidence
The most contestable element sits in the second group. Hitchhikers use their own accounts, install no cheat software, and never log into someone else's account, yet they may lose ranked points they earned simply because they once queued with an account being boosted. Technically, they broke no rule. Systemically, they are folded into the same case file.
This is an expansion of liability by association, and it differs in kind from locking a cheating account. A boosted account leaves clear traces: changing login addresses, sudden jumps in performance, behaviour patterns deviating from history. A hitchhiker leaves no trace of their own, because they played normally. The only thing placing them in scope is who they queued with.
That means the evidentiary threshold here is far lower than for an account ban, while the consequence lands on a legitimate player. I do not object to reclaiming points earned in corrupted matches — those points never reflected real skill. I object to doing so without publishing the classification standard, without stating a false-positive rate, and without any appeal step described in the announcement.
Meanwhile Riot's answer on smurfing is far softer than community expectations. A Riot representative, Phillip 'mirageofpenguins' Koskinas, is quoted to the effect that playing a secondary account is not automatically cheating, and the publisher enumerates eight legitimate use cases for alternate accounts — including protecting the highest achievement on a main account. In other words, Riot draws the line by intent and behaviour, not by how many accounts someone owns.
The contrast is striking. Within one policy, Riot is generous toward legitimate alternate-account users while being harsh enough to sweep bystanders into enforcement. An intent-based standard is the hardest to apply consistently; a queue-relationship standard is easy to apply and easy to get wrong. When both run in parallel inside the same system, players cannot know where they stand.
TPM 2.0, PC cafes and second-class citizenship
The least discussed but heaviest element is the forward plan: multi-factor authentication, TPM 2.0, hardware authentication, and verification requirements that may differ by rank. The stated goal is to make "one-time" accounts much harder to create.
TPM 2.0 is a hardware security standard enabling device-level identity attestation. Applied to game accounts, it makes the machine part of the identity: an account bound to a specific board. For anti-cheat purposes this is a major step, because it cuts the path back after a ban. For accessibility, it creates a very real problem.
I live in Busan, where PC cafe culture runs in the veins of esports. Many Korean players do not own a machine capable of running League of Legends or VALORANT and play on shared, hourly-rented hardware. If accounts are bound to hardware identity, shared-machine players are structurally disadvantaged: every machine change becomes a risk of being flagged, every shared rig a potential conflict point.
Rank-differentiated verification establishes two tiers of citizenship inside one game: high-rank players face heavier checks, low-rank players lighter ones. Competitively this makes sense — a high-rank account is worth more and deserves more scrutiny. On fairness, it opens an awkward question: if I have played legitimately for six years and climbed high, why do I face controls a new player does not?
There is also a structural point worth naming. In this story, Riot is simultaneously rule-maker, enforcement body, source of its own enforcement statistics, and commercial beneficiary when players leave because they were cheated. There is no independent arbitration layer. That is inherent to publisher-run esports, and the announcement does not mention it once.
Where I could be wrong
I have been wrong often enough to interrogate myself before interrogating anyone else. I fail publicly so I can learn quietly.
First, I may be over-reading the hitchhiker doctrine. If only a few thousand of the three hundred thousand lost points on this basis, it is a small legal footnote rather than the spine of the story. I have no category-level breakdown, so I am judging policy design rather than volume.
Second, TPM 2.0 may never ship at scale. Large publishers have a track record of announcing technical plans and quietly postponing them after community backlash or cost reviews. If that happens, the part I call most important becomes a footnote in development history.
Third, and this is the one I weigh most: the ranked ladder may never have been a good enough scouting signal for cleaning it to deliver the value I attribute to it. Boosting corrupts ladder data, true — but academies and tier-two teams have long used scrims and youth tournaments as their primary yardstick rather than waiting on a leaderboard. If so, the benefit I assign to this campaign is inflated.
Fourth, I am reading a publisher-originated announcement and inferring motive. It is possible Riot is simply doing the right thing with no deeper layer. Enforcers do not always carry a hidden agenda.
I am not a prophet. I just read probabilities faster than you read emotions.
What I will track
Over the next twelve months I will watch four verifiable signals. First, whether Riot publishes enforcement data periodically with trend lines, or whether three hundred thousand was a one-off framing number. Second, whether TPM 2.0 and hardware verification genuinely leave test scope, and if so, which rollout sequence Korea gets — the PC cafe market here is the harshest possible test. Third, whether clearly wrongful point revocations surface in the community with enough documentation to force a Riot response. Fourth, whether gray-market boosting prices rise after the ban wave.
If boosting prices rise, my thesis is confirmed: good enforcement shrinks supply while demand persists, and money simply flows toward less-policed titles — possibly ones without Vanguard. If prices hold or fall, I am wrong, and I will say so.
Legends do not die from mistakes. Legends die because the data knows how to count.
What I actually want is not a number larger than three hundred thousand, but a dataset with a complete denominator, a false-positive rate, and an appeals path. A platform willing to publish the part it got wrong earns more trust than one that only publishes what it caught. For an ecosystem where the entire tier-two talent pipeline stands on the credibility of the ranked ladder, that is a minimum standard, not an ideal one.
