Riot Locks Nearly 300,000 League of Legends and VALORANT Accounts: The Real Fall Point Sits in Hardware Identity Verification
**Câu trả lời cốt lõi:** Riot Games đã khóa gần 300.000 tài khoản League of Legends và VALORANT vì gian lận xếp hạng, tương đương khoảng 0,2% tổng người chơi hoạt động hàng tháng. Trọng tâm thật sự nằm ở kế hoạch xác thực danh tính phần cứng TPM 2.0 và học thuyết trách nhiệm liên đới với hitchhiker. **Dữ kiện chính:** - Vanguard được tích hợp vào League of Legends từ tháng 9 năm 2025, sau VALORANT. - Gần 300.000 tài khoản bị xử lý, khoảng 0,2% trên tổng 140 triệu người chơi ước tính mỗi tháng. - Riot tuyên bố smurfing không tự động là gian lận, liệt kê tám tình huống sử dụng chính đáng. - Hitchhiker có thể bị thu hồi điểm xếp hạng dù chơi trên tài khoản của chính mình. - Kế hoạch tương lai gồm MFA, TPM 2.0, xác thực phần cứng, yêu cầu phân tầng theo hạng. **Nguồn:** Báo cáo tin tức esports về chiến dịch xử lý tài khoản của Riot Games; mốc tích hợp Vanguard tháng 9 năm 2025; các cam kết xác thực MFA và TPM 2.0. **Hỏi đáp liên quan:** - Hỏi: Điểm xếp hạng có được bảo vệ khi gặp người gian lận không? Đáp: Có, Riot cho biết người chơi được bảo vệ điểm khi phát hiện gian lận hoặc người rời trận. - Hỏi: Smurfing có bị khóa tài khoản không? Đáp: Không tự động, vì Riot nêu tám tình huống sử dụng tài khoản phụ được xem là chính đáng. - Hỏi: Điều gì thay đổi lớn nhất trong tương lai? Đáp: Xác thực phần cứng TPM 2.0 và MFA, khiến tài khoản dùng một lần khó tạo hơn.
I still keep the habit of stopping the clock every time I rewatch a match recording. The craft of documentary screenwriting taught me that the feel of a game is always skewed, while numbers cannot lie. So when news broke that Riot Games had locked nearly 300,000 League of Legends and VALORANT accounts over ranked cheating, my first reflex was to hunt for the denominator. An absolute number standing alone is just noise. Place it against a whole, and it becomes a signal.
The denominator sat inside the original information itself: roughly 140 million monthly active players across the two titles, about 120 million for League of Legends and 20 million for VALORANT. Nearly 300,000 divided by 140 million comes to about 0.2 percent. Placed beside a track-and-field split table, that sits inside the measurement-noise threshold. But precisely because it is small, it matters: this is not an eradication campaign, it is a step in building governance infrastructure.
Context: from anti-cheat software to a behavioral governance system
Vanguard is a kernel-level anti-cheat client, rolled out by Riot for VALORANT first and then integrated into League of Legends in September 2026. A tool expanding from one title to a second is not a champion-balance or a patch-strength story. It is a change at the client-system level, meaning it changes how the software behaves on a user's machine.
To read the 300,000 figure, one must separate four concept groups that Riot folds into a single campaign. The first is boosting — a highly skilled player logs into someone else's account to climb on the owner's behalf, usually a paid service relationship. The second is smurfing — playing on a secondary account, typically below one's true skill level. The third is the hitchhiker — Riot's term for a player using their own account while queuing alongside an account being boosted. The fourth is pure software cheating.
Here is the line worth locking in: Riot states that smurfing is not automatically considered cheating, and enumerates eight legitimate secondary-account use cases, including protecting one's highest achievement on a main account. This is a boundary drawn on intent and behavior, not on account count. It is soft, and because it is soft, it is very hard to enforce consistently.
Alongside that sits a set of forward-looking commitments: multi-factor authentication, the TPM 2.0 trusted platform standard, hardware authentication, and verification requirements that may be applied differently depending on player rank. The stated goal is to make "one-time" accounts harder to create. One smaller change with high experiential value: protecting ranked points when a cheater or a leaver is detected in a match.
Core analysis: when the ranked ladder becomes a scouting pipeline
I do not view the ranked ladder as a casual playground. For someone in the observation trade, it is the de facto scouting system for the entire amateur-to-professional pipeline. Academies and tier-2 teams still use ladder rank as their first screening filter. When boosting corrupts that signal, the damage is not in the feelings of the average player, but in the quality of talent identification.
I begin with a self-counted data table, because memory does not know how to yield to error. Over years of note-keeping, I have found that small biases accumulating over large samples always fool perception. A player who climbs three tiers thanks to a boosted account is, in the eyes of the scouting system, an identical profile to a player who climbed three tiers on their own. This is the worst kind of measurement failure: not random error, but systematic error, always leaning one way.
Structurally, this campaign has three clear layers of impact.
The first layer is signal cleaning. If boosting is pushed back, ladder rank gains credibility, and scouting departments gain grounds to trust tier data when combined with scrim and tournament evidence.
The second layer is gray-market repricing. Boosting exists because there is demand — rank prestige, seasonal rewards, ego — and supply — skilled players needing income, especially at the bottom of the esports labor pyramid. Tightening does not remove demand or supply. It raises the risk premium. By ordinary gray-market economics, the most predictable outcome is a rise in boosting prices, not the disappearance of the service.
The third layer, and the least discussed, is geographic displacement. If enforcement density differs across servers, demand flow seeks the lower fence. I have seen this model in sports with uneven rules across federations: violations do not fall, they change address.
One technical detail deserves a pause: verification requirements may be applied differently by rank. This is a tiered governance model, with precedent in traditional sport when whereabouts obligations apply more heavily to elite athletes. As a design, it is reasonable, because risk concentrates at the top of the ladder. As a matter of fairness, it creates two tiers of "citizenship" within one player base. That is not wrong, but it needs to be said out loud rather than deployed quietly.
On verifiability, there is a structural issue worth stating plainly: Riot is simultaneously the rule-maker, the enforcing body, the supplier of enforcement statistics, and the commercial beneficiary of that enforcement. There is no independent arbitration layer in between. The 300,000 figure comes from a single source, and that source has a direct interest. Even the 0.2 percent ratio rests on a 140 million denominator with no attributed source. These numbers should be treated as directional claims, not audited data.
The contrarian angle: the fall point is not the ban count
Most readers stop at the 300,000 headline. I would argue the more important part lies in two design choices buried fairly deep in the original information.
The first is the hitchhiker doctrine. Riot is extending liability to a third party: a player using their own account, breaking no software rule, can still lose ranked points if they ever queued with an account that was being boosted. This is a standard of associative liability, and it is the most contestable element procedurally. The false-positive risk here is very real: an ordinary player queuing with a friend who, unknown to them, was being boosted.
The second is hardware authentication via TPM 2.0. If deployed, accounts become bound to physical devices. This fundamentally changes the economics of account creation: the cost of spinning up a new identity spikes. But it also raises questions for players on shared machines or internet-cafe machines, a non-trivial group in some regions. Nothing in the source material addresses this group.
0.8 seconds is never just 0.8 seconds; it is where the trajectory breaks. Here, roughly 0.2 percent is a small ratio, but the two design choices attached to it are where the trajectory turns. The ban count is a countable event and will fade. Hardware-bound identity infrastructure is a structural change and will stay.
One further observation: the time window for the 300,000 figure is not stated, but coupled with the September 2026 Vanguard integration, it is most likely a cumulative tally over roughly one quarter or less. Annualized, the real intensity is far higher than first impressions suggest. This is why I always demand the denominator and the time window before accepting any number.
Takeaway: a self-counted table, and an open question
Every match is a countable bet. You only need to be willing to look closely. This campaign does not end at 300,000 accounts. It merely opens a long-term negotiation between publisher and players over who owns identity in the digital world.
What I want to see in the next six to eighteen months is a published false-positive rate, a transparent appeals mechanism, and rank-distribution data after the crackdown. When the ranked ladder becomes trustworthy again, the biggest beneficiary is not Riot, but the seventeen-year-old climbing solo at two in the morning, believing that the number on the screen is telling the truth about them.

