Nearly 300,000 League of Legends and VALORANT Accounts Locked: The Ranked System Is Being Rewritten at the Hardware Layer
**Câu trả lời cốt lõi** Riot Games đã khóa gần 300.000 tài khoản xếp hạng League of Legends và VALORANT vì cày thuê, đẩy rank và hành vi đi nhờ, sau khi tích hợp Vanguard vào LMHT tháng 9 năm 2025. Kế hoạch tiếp theo gồm xác thực đa yếu tố, TPM 2.0 và yêu cầu xác minh khác nhau theo bậc rank. **Sự kiện chính** - Gần 300.000 tài khoản bị xử lý, tương đương khoảng 0,2 phần trăm của ước tính 140 triệu người chơi hàng tháng. - Vanguard tích hợp vào League of Legends tháng 9 năm 2025, sau nhiều năm chỉ phục vụ VALORANT. - Người chơi đi nhờ dùng tài khoản riêng vẫn có thể bị thu hồi điểm xếp hạng. - Riot tuyên bố smurf không tự động là gian lận, nêu tám trường hợp sử dụng hợp pháp. - Kế hoạch xác thực phần cứng TPM 2.0 nhằm chặn tài khoản dùng một lần. **Nguồn**: Riot Games, công bố ngày 15 tháng 10 năm 2025 | Cross-checked: VuaBong.vn **Hỏi đáp liên quan** - Hỏi: Người chơi xếp hàng cùng tài khoản cày thuê có mất điểm không? Đáp: Có, Riot có thể thu hồi điểm xếp hạng dù tài khoản của họ hợp pháp. - Hỏi: Smurf có bị khóa không? Đáp: Riot nêu rõ smurf không tự động bị coi là gian lận nếu thuộc các trường hợp sử dụng hợp pháp được liệt kê. - Hỏi: Điều gì sẽ thay đổi lớn nhất? Đáp: Theo VangBong.vn Player Depth Index, tác động lớn nhất nằm ở xác thực phần cứng theo bậc rank, không phải số lượng lệnh khóa.
The notification appeared at 1:47 a.m. Seoul time. The ranked match I had just lost was refunded, because the system detected a cheating account in the same lobby. I lost no points. I lost forty minutes, a night of sleep, and a small piece of my faith in the very ladder I use as the yardstick for almost every professional judgment I make.
Ten minutes later I reopened my personal dataset. Thirty-seven matches this season. Four carried abnormal signals: a sudden spike in lane-phase win rate for opponents, resource-per-minute figures above the 99th percentile for that rank bracket, and reaction times in teamfights falling outside a normal distribution. I did not file a complaint. I logged it. That has been my method for twelve years, since the night of June 2026 when I stayed awake to watch Germany face South Korea in the World Cup group stage, then spent a full month reviewing all thirty-six group-stage matches just to test a hypothesis about expected goals.
When the numbers stop lying, my heart starts listening.
The next morning, Riot Games published a figure that made the entire ranked community stop: nearly 300,000 accounts across League of Legends and VALORANT had been locked or actioned for ranked cheating. The scope does not stop at software cheating. It covers account boosting, paid rank pushing, and the category Riot calls "hitchhikers" — players using their own legitimate accounts but queuing alongside an account being boosted.
The key date is September 2026. That is when Vanguard, the kernel-level anti-cheat system, was integrated into League of Legends after years of serving VALORANT only. The expansion turned a single-title tool into platform-level governance infrastructure. Riot is no longer only hunting cheat software. It is moving into behavioral control inside the ranked system itself.
I follow both football and esports, and my biggest lesson did not come from a win or an upset. It came in 2026, when K League 1 returned inside empty stadiums. I collected data from forty-two spectator-free matches in South Korea and found the home win rate had fallen from 42.3 percent to 29.8 percent, while the draw rate rose to 31.5 percent. An environmental variable had vanished, and every historical data point ahead of it became noise. I had to rebuild the model from scratch, removing the crowd variable, and in the first month I won eight of ten handicap bets.
The 300,000-account story is exactly that kind of story. The environmental variable here is identity verification infrastructure. And it has just changed.

The 0.2 Percent Ratio and the Ignored Denominator Problem
The estimates cited in the report suggest League of Legends has roughly 120 million monthly active players and VALORANT roughly 20 million, for a combined total of about 140 million. Dividing 300,000 by 140 million gives roughly 0.2 percent. The report itself concedes this is a relatively small share.
But there are three technical problems I cannot overlook, and they matter more than the headline figure.
First, the time window is undefined. Vanguard was only integrated into League of Legends from September 2026. If 300,000 is a cumulative tally since that point, it covers one quarter or less. Annualized, the enforcement rate would be substantially higher than the headline implies. In my line of work, a number without a time denominator is a number not yet usable.
Second, the 140 million denominator is unattributed. In the source material, these estimates appear only as "estimates show" and "said to be." In any ratio calculation, the provenance of the denominator matters as much as the numerator. An unverifiable denominator produces an unverifiable ratio.
Third, and this is the point I consider most serious: the China servers. League of Legends in mainland China is operated inside Tencent's ecosystem, with separate anti-cheat and account-verification infrastructure that does not share the global Vanguard rollout. If the 300,000 figure is global-excluding-China, the true denominator is far smaller than 140 million, and the true ratio is far larger than 0.2 percent. A significant share of League of Legends' monthly actives sit in that ecosystem. This is a potential denominator error, not a minor administrative footnote.
I have counted every gap on the pitch when the crowds disappeared.
In this case, the gap sits where nobody has published which denominator is the right one.
The Hitchhiker Doctrine: The Most Consequential Rule Change
Across the whole story, the most notable detail is not the number of locked accounts. It is Riot asserting the authority to revoke ranked points from players using their own legitimate accounts, breaking no software rule, simply because they queued with an account being boosted.
I call this liability by association. In traditional sports law, liability by association exists, but it always comes with an evidentiary standard, an adjudication process, and an appeal mechanism. Here, none of the three has been published.
In terms of false-positive exposure, this structure is very poor. A player queues as a duo with a friend. The friend, telling nobody, has paid for a boosting service. The first player knows nothing, plays by the rules, and loses points. In a system where duo queueing is ordinary social behavior, that is a wide risk surface.

I do not object to the principle that someone who benefits from cheating should not keep the benefit. I object to applying that principle without publishing an error rate, a classification standard, or an appeal path. At a scale of 300,000 accounts, a false-positive rate of even 2 percent equals 6,000 wrongly punished players. That is a figure any professional sports body would be required to disclose.
Smurfing Is Not Automatically Cheating, and That Is the Hard Part
Riot states clearly that smurfing — playing on a secondary account at a rank below one's true skill — is not automatically treated as cheating. It lists eight legitimate use cases, including "protecting their highest achievement on their main account." The staff member quoted in the report is Phillip "mirageofpenguins" Koskinas of Riot Games.
This is a deliberately soft boundary. Riot enforces on intent and behavior, not on account count. As policy, that is a reasonable choice, because professional teams and semi-pro players routinely maintain alt accounts to practice champions or agents without wrecking their main ladder standing.
As enforcement, it is the hardest boundary there is. You cannot automate a judgment of intent. You have to build a behavioral model, assign probabilities, and pick a threshold. Every time you lower the threshold, you catch more real offenders and more innocent players. Every time you raise it, you cut false positives and let more offenders through. No threshold is right for everything.
That brings me to the part of the plan that has not received enough attention.
TPM 2.0: The Real Change, Not the 300,000 Locks
Riot announced plans to strengthen account verification: multi-factor authentication, TPM 2.0, hardware authentication, and requirements that may be applied differently depending on a player's rank. The stated goal is to make "one-time" accounts harder to create.
If fully deployed, this changes the economic structure of the entire ranked system in a way 300,000 locks cannot. A lock is a one-time cost to an offender. A hardware binding is a permanent cost to everyone.
TPM 2.0 is a hardware security standard enabling device-level identity attestation. When an account is bound to a physical hardware module, the cost of creating a new account rises sharply. For professional boosters, that strikes at the business model. For ordinary players, it is a change in access.
And here two problems appear that the report does not address.
First is access equity. A segment of players does not own a personal computer. They play at internet cafés, on shared machines, on borrowed devices. If account identity is anchored to hardware, this group is systematically pushed to the margin, not because they cheat, but because they have no hardware to anchor to. That is a policy problem, not a technical one.
Second is privacy. Linking account identity to a physical hardware identifier, in some jurisdictions, intersects with personal-data regulation. The report does not mention this. Nor have I seen any statement on region-by-region rollout sequencing or accessibility carve-outs.
Applying different verification requirements by rank is a notable structural detail in another direction. It concentrates enforcement cost at the top of the ladder — precisely where scouting happens and where semi-pro players become visible. Logically, this is defensible: the top of the ladder carries the highest value and the most manipulation. In governance terms, it creates two tiers of citizenship inside one system, with two different levels of obligation.
I do not believe in inspiration — I believe in standard error.
And the standard error here sits in the fact that we are discussing a verification system not yet deployed, based on statements without firm dates.
Who Makes the Rules, Who Enforces Them, Who Supplies the Data
There is a structural problem I consider more important than the 300,000 accounts: Riot Games is simultaneously the rule-maker, the enforcement body, the sole data source on enforcement effectiveness, and the commercial beneficiary of that enforcement.
In traditional sports, these roles are deliberately separated. The federation writes the rules, a disciplinary body adjudicates, a sports court arbitrates, and independent organizations publish the data. Even when that system is imperfect, the separation creates a layer of cross-checking.
In publisher-run esports, that cross-checking layer does not exist. Nobody audits the 300,000 figure. Nobody measures the false-positive rate outside Riot. Nobody adjudicates disputes outside Riot.
I want to be clear that this does not mean Riot is lying. It means we have no way to know, and in my line of work, "no way to know" is a state to be recorded, not skipped.
The Gray Market Will Reprice, Not Disappear
Boosting exists because there is demand and supply.
On the demand side: rank prestige, seasonal rewards, and ego. A player who wants a Diamond frame or higher can pay to have it without spending hundreds of hours. No ban wave erases that desire.
On the supply side: high skill, low income. This is a structural feature of the esports labor market, where lower-tier and semi-pro players often lack stable income. A high-ranked player with no professional contract has a skill to sell and an incentive to sell it.
Supply-side enforcement does not erase demand. It raises the risk premium for suppliers. The predictable outcome is higher boosting prices, higher margins for the few remaining operators, and a share of activity migrating to titles with softer enforcement.
This is the standard model of supply-side enforcement in any gray market. You do not eliminate the market; you change its price and its location.
In my world, luck is only the residual I have not yet explained.

And in this case, the unexplained residual is the fate of the boosting market after prices are pushed up.
The Overshadowed Bright Spot: LP Protection
Inside the same announcement sits a change I believe will improve player sentiment more than 300,000 locks: ranked-point protection when the system detects a cheater or a leaver in the lobby.
Technically, it is a small change. In experience terms, it is a large one, because it directly reduces the variance of a match sequence. If you play enough games, the number of matches wrecked by factors outside your control goes down. Your ranked points become a slightly more accurate skill signal.
In my terminology, this is variance compression. And in any measurement system, compressing variance is always the cheapest way to improve signal accuracy.
I have seen a version of this in football. When expected-goals metrics became widespread, people began distinguishing unlucky teams from bad teams. Nothing changed on the pitch. Only the measurement changed. But when the measurement changes, decision-making follows.
What to Track in the Next Cycle
There are seven signals I will put on my tracking board.
The cadence of enforcement data publication. If Riot publishes periodically with trend lines, it establishes an industry integrity-reporting standard. If this is a one-off disclosure, it remains forever a number with no baseline.
The actual rollout of multi-factor authentication, TPM 2.0, and hardware attestation. This is the biggest change for ordinary players, far bigger than the ban figures.
The specific rank thresholds for differentiated verification requirements. Once thresholds are published, the two-tier model becomes concrete, and high-rank friction becomes a measurable variable.
The volume and false-positive rate of hitchhiker cases. This is the best leading indicator of backlash risk from the community and from professional players.
Ladder quality metrics after enforcement. Whether the high-rank distribution shifts abnormally. If it does, we have indirect evidence of effectiveness. If it does not, we have no evidence at all.
Boosting market prices and title migration. If prices rise or activity shifts to titles with softer enforcement, the displacement rather than elimination thesis is confirmed.
Regional enforcement symmetry, including the China ecosystem. If enforcement intensity diverges across servers, we have a form of cross-region integrity arbitrage.
An Open Conclusion
I do not think this is a story about 300,000 accounts. I think it is a story about a publisher expanding its role from hunting cheat software to controlling behavior inside the ranked system, and expanding its identification infrastructure from the account layer down to the hardware layer.
Within my data framework, I have only two ways to respond to a change like that. One is to log it and adjust the model. The other is to log it and ignore it. The second is not an option.
The historical data I use to evaluate a ladder just became slightly more outdated than it was yesterday. What needs doing now is determining which variable has been added to the equation, and which variable has just been removed from our field of observation.
I have counted every gap on the pitch when the crowds disappeared. This time, the gap sits where nobody has published an error rate, and nobody has published the real deployment date of the verification system that will reshape this ladder over the next several years.
