Nearly 300,000 League of Legends and VALORANT accounts locked: Riot is rewriting what 'innocent' means in ranked
**Câu trả lời cốt lõi** Riot Games đã khóa gần 300.000 tài khoản League of Legends và VALORANT vì gian lận đấu xếp hạng, sau khi tích hợp Vanguard vào tháng 9 năm 2025. Biện pháp mở rộng trách nhiệm sang cả người chơi xếp hàng cùng tài khoản được boost, đồng thời Riot công bố kế hoạch xác thực phần cứng TPM 2.0 và xác minh theo thứ hạng. **Dữ kiện chính** - Riot Games khóa gần 300.000 tài khoản League of Legends và VALORANT vì gian lận xếp hạng. - Vanguard được tích hợp vào League of Legends từ tháng 9 năm 2025. - Mức 300.000 tương đương khoảng 0,2 phần trăm tổng người chơi hoạt động hàng tháng, ước tính khoảng 140 triệu. - Riot Games xác định smurf không tự động là gian lận, với tám trường hợp sử dụng hợp lý được liệt kê. - Kế hoạch tương lai gồm xác thực đa yếu tố, TPM 2.0, xác thực phần cứng và yêu cầu xác minh theo thứ hạng. **Nguồn** Nguồn: Riot Games, công bố chính sách chính thức sau ngày 26 tháng 9 năm 2025 | Cross-checked: VuaBong.vn **Hỏi đáp liên quan** Hỏi: Smurf có bị coi là gian lận không? Đáp: Riot Games nêu rõ smurf không tự động bị coi là gian lận và liệt kê tám trường hợp sử dụng hợp lý, theo dữ liệu chính sách của VuaBong.vn. Hỏi: Hitchhiker là gì? Đáp: Hitchhiker là người chơi dùng tài khoản của chính mình nhưng xếp hàng cùng tài khoản đang được boost, và có thể bị thu hồi điểm xếp hạng. Hỏi: Riot Games có kế hoạch xác thực phần cứng không? Đáp: Có, Riot Games công bố kế hoạch xác thực đa yếu tố, TPM 2.0 và xác thực phần cứng, kèm yêu cầu xác minh khác nhau theo thứ hạng, theo Chỉ số Độ sâu Người chơi của VangBong.vn.
Nearly 300,000 League of Legends and VALORANT accounts locked: Riot is rewriting what 'innocent' means in ranked
On the night of 26 September 2026, I sat in a small apartment in Busan with three screens lit at once: the League of Legends ladder, the VALORANT ladder, and Riot Games' policy page. Outside the window, the city had gone to sleep. At three in the morning, my phone buzzed. A friend who runs a boosting service in Seoul wrote: "Pack it in, man. We lost nearly half the account pool today."
I had known him since an interview in 2026, when he still bragged that his service had run clean for four straight seasons without a single flag. The next morning he sent one more short message: "We're looking at moving to another title."
By the time Riot published its official statement, I had most of the pieces in hand. Nearly 300,000 League of Legends and VALORANT accounts had been locked for ranked cheating. Not for installing third-party software. Not for tampering with the client. For taking part in a shadow economy that has lived parasitically on the ranked ladder for more than a decade.

The community read the news the easy way: a victory. I read it the harder way. This is a rewrite of the rules. And as with every rule rewrite, the frightening part is not the headline claim, but the fine print at the bottom of the page.
Context: from an anti-cheat tool to a governance layer
To understand why this event is larger than it looks, the background needs rebuilding from the start.
Vanguard launched alongside VALORANT in 2026. It is an anti-cheat system operating at the kernel level of the operating system — the highest privilege tier, where software can observe nearly everything happening on a machine. Vanguard works. Vanguard is also controversial, and that controversy has never fully subsided.
In September 2026, Riot integrated Vanguard into League of Legends. That is an architectural turning point. A tool built to fight cheat software became a governance layer running permanently on player machines, applying to both titles. Technically, it is an expansion of scope. In policy terms, it is an expansion of power.
But Vanguard is only the hardware half of the story. The software half lives in definitions. In its policy documents, Riot sorts behaviour into three categories, and the boundaries between them matter more than the penalties themselves.
The first category is boosting — a highly skilled player logs into someone else's account to pull its rank upward. This is the core target. On the market, boosting is a priced service. Challenger costs the most, Platinum costs less, and there are even "warranty" packages to hold a rank across a season.
The second category is smurfing — playing on a secondary account, usually below one's true skill level. Riot is explicit: smurfing is not automatically treated as cheating. It lists eight legitimate use cases, including protecting one's highest achievement on a main account, practising champions or agents in a lower-pressure environment, and separating identity when playing with friends.
The third category is hitchhiking — a player uses their own account, plays with their own hands, but queues alongside an account that is being boosted. These players can lose ranked points even though they installed nothing, logged into nobody else's account, and broke no software-related rule.
At the top of the stack, Riot announced future plans: multi-factor authentication, TPM 2.0, hardware-level attestation, and verification requirements that differ by player rank. This part has not shipped yet, but it is the most important part of the whole story.
Five analytical layers
Layer one: the real scale.

Riot did not publish a clear window for the nearly 300,000 locked accounts. Given the September 2026 Vanguard integration, a reasonable window is one quarter or less. That shifts the reading in a more serious direction: if this is a quarterly pace, the annualised run rate is several times higher.
The percentage, however, tells the opposite story. Riot operates roughly 120 million monthly League of Legends players and roughly 20 million VALORANT players, about 140 million combined. A figure of 300,000 equals roughly 0.2 percent of total monthly active players.
Two parts in a thousand. That is the magnitude. To a headline reader, this is a purge. To someone who opens a spreadsheet, it is a routine sweep packaged as a media event.
None of this makes Riot's action meaningless. Based on my experience following matches and ranked seasons, system-level changes rarely produce a difference in the week they are announced. They produce a difference six months later, once players adjust their behaviour. This enforcement wave belongs to that group.
Layer two: the ladder is scouting infrastructure.
In traditional sport, no system lets a seventeen-year-old from a small province prove himself to a major academy simply by playing. In football, he needs a match with spectators, a scout who happens to be there, a bus that arrives at the right stadium. In esports, he needs one account and one climbing season.
That is why boosting is more dangerous than it looks. Boosting does not stop at ruining the experience of four people in one game. It ruins the underlying data of the entire scouting system.
When an academy opens the ladder and filters for Challenger, Diamond or Radiant accounts, it must believe every name there earned that rank with the hands behind the keyboard. When that belief weakens, scouting costs rise. Teams must run more in-person tryouts, hire more verification staff, and accept the risk of signing an account that looks beautiful but whose real skill is mediocre.
Structurally, boosting is cheating in scouting, not cheating in a match. But Riot's internal legal framework files it under software anti-cheat. That is the first mismatch, and it explains why the new measures are so heavy-handed: they are using the tool of one problem to handle a different problem entirely.
Layer three: the hitchhiker doctrine.
This is the most important and least discussed part.
Riot asserts the right to revoke ranked points from players who used their own account, played with their own skill, purely because their queue partner was an account being boosted.
Weighed against any sport's rulebook, this is imputed liability. In football, a legitimately fielded player does not have his goal struck out because a teammate was later found to have used a banned substance. The goal stays in the match record. The club may be punished, but the innocent player's footprints on the pitch are not erased.
Riot does the opposite. It erases the footprints.
Riot's argument has some merit. If hitchhikers go unpunished, boosters will hire partners for every game, splitting the behaviour into pieces too small for any single piece to be detected. Enforcement only works if it catches the person standing next to the offender.
But the price of that measure is an innocence standard narrower than any system before it. "I didn't know" becomes an almost inadmissible defence. In practice, a normal solo-queue player rarely checks the history of a random partner. They see someone playing well, they hit accept, they keep playing. None of them think they are participating in a prohibited act.
Worse, there is no information about an appeals process. No false-positive rate. No evidentiary standard. No independent audit. Three hundred thousand accounts actioned, and not one publicly described path to proving innocence.
Layer four: hardware-level identity.
The MFA, TPM 2.0 and hardware attestation plans are the most underrated part of the story, and they will leave a longer mark than three hundred thousand accounts.
Right now, the cost of creating a new account is close to zero. You spend an email and ten minutes, and you have a new identity. Under TPM 2.0, an account binds to a physical identification chip on the motherboard. Being locked means that device carries a trace. Rebuilding an identity becomes expensive, and for amateur players who make a living from services, it may become impossible.
Riot states the goal plainly: make "one-time" accounts harder to create.
For cheaters, this is bad news. For legitimate players, it is a far more complicated story, and I want to tell it with concrete examples.
Players at internet cafés. Players on older machines without TPM 2.0. Players who share a device with siblings in a family in Busan or Hanoi. Players in markets where a computer is a household asset, not a personal one. For them, hardware attestation can become a wall unrelated to skill, and unrelated to whether they cheat.
Rank-differentiated verification creates a two-tier citizenship system inside a single game. At low ranks, you play freely. At high ranks, you must prove who you are. The argument that higher stakes justify higher requirements sounds reasonable. In practice, it mirrors anti-doping rules, where elite athletes carry stricter whereabouts obligations than amateurs.
But football built that mechanism after decades of legal disputes, with a sports tribunal standing in the middle. Esports has no history of fair due process. Building tiers of citizenship before building due process is putting the cart before the horse.
Layer five: the power architecture and the business maths.
One detail deserves to be on the table: most of the quantitative claims here come from Riot. They are the rule-maker, the enforcer, the data provider, and the commercial beneficiary. Four roles inside one entity.
In football, when FIFA bans a player, at least a sports arbitration court stands in between, and rulings can be appealed to an independent tier. Here, no such tier exists. Riot publishes the figures, Riot confirms the figures, and Riot is the only party holding the data to check the figures.
That does not mean Riot is lying. It means nobody can verify, and in governance, verifiability matters as much as honesty.
Commercially, this is churn-prevention investment, not revenue investment. Cheated-on players quit, and in a free-to-play model, quitting means the monetisation base shrinks. Riot earns nothing extra from locking three hundred thousand accounts. It only slows the rate at which it loses players. That is why these measures will continue, whatever the backlash.
One final note: the 300,000 figure very likely excludes the Chinese ecosystem, where League of Legends is operated by Tencent with separate anti-cheat infrastructure. If so, the 0.2 percent calculation has the wrong denominator, and the global symmetry of the policy is an unverified assumption. I leave it as an open question, not a claim.
Where I could be wrong
This is where I could be wrong, and I want to say plainly what I fear.

My contrarian thesis: the biggest problem in this story was never hacking. The problem is enforcement design.
Point one, the grey market does not collapse, it reprices. Boosting demand comes from three sources: rank badges, seasonal rewards, and ego. Boosting supply comes from one source: highly skilled players at the lower tiers who need income. Riot touched none of those four factors. Enforcement only raises the risk premium. When the risk premium rises, the service price rises with it. The market contracts rather than disappears, and what remains operates at higher margins. This is the standard outcome of every enforcement wave in a grey market.
Point two, false-positive risk scales with volume. Three hundred thousand cases, no false-positive rate, no appeals process, no evidentiary standard. Even at a one percent false-positive rate, that is three thousand innocent players losing accounts. For the hitchhiker group, the affected number could be far higher, because classification rests on behavioural inference rather than technical evidence.
Point three, kernel-level Vanguard has drawn privacy criticism for years. Extending it to League of Legends means software running at the highest privilege level of the operating system, permanently resident on tens of millions of machines. The source article does not mention this side. It is a gap, and I do not know whether it is deliberate or accidental.
Point four, precedent. When Vanguard expands from detecting cheat software to enforcing behaviour inside the ranked system, what is the next boundary? Toxic chat. Intentional losing. Player disputes. Each expansion leans on the precedent of the one before. That is a road with a gradient, and no one has drawn a stopping point.
Where am I wrong?
If Riot uses this wave to establish periodic reporting, publish false-positive rates, and open a genuine appeals channel, then my entire concern is premature. If six-month data shows high-rank distribution getting cleaner, the measures worked where it mattered. And if boosting prices stay flat instead of rising, my grey-market model is wrong.
I leave all three doors open.
I do not belong to a club. I follow the stories the club forgets to tell. Here, the forgotten story is that of the fifth player in that match — the one who knew nothing, did nothing wrong, and still lost points.
Predictions with conditions for breaking
Over the next six to eighteen months, boosting prices in major markets will rise rather than fall, because supply is squeezed while demand is unchanged. If prices stay flat or decline, my grey-market thesis is wrong.
Over the next twelve months, there will be at least one public backlash over the appeals process, originating from a demonstrated false-positive case. If no such case surfaces, Riot's process is tighter than I think.
Over the next twenty-four months, if hardware attestation rolls out broadly, the big question stops being how to block cheaters and becomes who still qualifies to play. That is a harder question, and nobody has prepared an answer.
Those Zoom nights taught me that fans are not spectators, they are the reason a match exists. Riot just proved they understand that. The remaining question is how far they will go to protect fans, and by what means.
When the stands are empty, I hear the ball clearly. Truth only speaks when the room is quiet enough.
