Riot locks nearly 300,000 League of Legends and VALORANT accounts: the new line is drawn in hardware
**Câu trả lời cốt lõi**: Riot Games đã xử lý gần 300.000 tài khoản League of Legends và VALORANT vì thao túng thứ hạng, tương đương khoảng 0,2% trong ước tính 140 triệu người chơi hoạt động hàng tháng. Thay đổi có sức nặng hơn nằm ở lộ trình xác thực đa yếu tố và gắn tài khoản với phần cứng qua TPM 2.0. **Dữ kiện chính**: - Vanguard được nhúng vào League of Legends tháng 9 năm 2025, sau nhiều năm chỉ phục vụ VALORANT. - Riot xác định ba nhóm vi phạm: cày thuê, tài khoản phụ, và người đi nhờ xếp hàng cùng tài khoản bị cày. - Người đi nhờ dùng tài khoản riêng vẫn có thể bị thu hồi điểm xếp hạng đã kiếm được. - Chơi tài khoản phụ không tự động bị coi là gian lận; Riot liệt kê nhiều mục đích chính đáng. - Kế hoạch tương lai gồm xác thực đa yếu tố, TPM 2.0 và yêu cầu xác minh theo bậc xếp hạng. **Nguồn**: Riot Games, công bố chính thức tháng 9 năm 2025 | Cross-checked: VuaBong.vn **Hỏi đáp liên quan**: - Hỏi: 300.000 tài khoản chiếm bao nhiêu phần trăm người chơi? Đáp: Khoảng 0,2% trên ước tính 140 triệu người chơi hoạt động hàng tháng của hai tựa game. - Hỏi: Chơi tài khoản phụ có bị khóa không? Đáp: Không tự động; Riot chỉ xử lý khi hành vi nhằm thao túng thứ hạng. - Hỏi: Người đi nhờ bị xử lý thế nào? Đáp: Họ có thể mất điểm xếp hạng kiếm được trong các trận bị ảnh hưởng dù dùng tài khoản của chính mình.
Riot locks nearly 300,000 League of Legends and VALORANT accounts: the new line is drawn in hardware
What happened in a single quarter
In September 2026, Vanguard, the kernel-level anti-cheat client that had until then served only VALORANT, was embedded directly into the League of Legends client. Roughly a quarter later, Riot Games announced it had locked or actioned nearly 300,000 accounts across the two titles for organised ranked manipulation. It was the first time the American publisher bundled League of Legends and VALORANT into a single enforcement figure, and the first time it said plainly that the target was no longer cheat software alone.
In the same announcement, Riot published a ratio of its own: roughly 0.2 percent of an estimated 140 million combined monthly players across both titles. On one side, 300,000 sounds enormous. On the other, 0.2 percent sounds trivial. Both figures come from the same source, and neither has been audited by a third party.
I read that announcement three times, and each time I stopped at the same place. Most readers will remember the 300,000. The thing that actually changes how an entire ecosystem operates sits near the end, where Riot talks about multi-factor authentication, about TPM 2.0, and about verification requirements that differ by rank tier.
Context: from cheat detection to behaviour governance
Vanguard is not a new product. It launched with VALORANT and became known for running at the operating-system kernel level, meaning it holds deeper access than almost any ordinary software on a user's machine. As VALORANT grew, Vanguard became the primary shield against hacks, aimbots and technical cheating.

Embedding Vanguard into League of Legends is a different kind of step. League of Legends was never a title where technical cheating was the dominant threat at every rank. Its more painful problem lives at the behavioural layer: boosting, secondary accounts, and groups of players coordinating to push a specific account upward.
Riot groups those behaviours under the term ranked manipulation. Inside that term sit three very different tiers of responsibility, and how Riot handles those three tiers is the most analytically significant part of the story.
Based on my experience tracking Riot's matches and enforcement cycles over several years, the shift is fairly clear. The publisher is turning an anti-cheat tool from a technical shield into a shared behaviour-governance layer across multiple titles. That has not happened at this scale in the industry before.
Three tiers of responsibility, three levels of punishment
The first tier is boosting in the classic sense: a highly skilled player logs into someone else's account to raise its rank. This is a behaviour with contracts, prices and customers. Riot actions both the boosted account and the boosting account, and for repeat offenders it can suspend the offender's main account as well.
The second tier is the secondary account. This is the most contested point. Riot states clearly that playing on a secondary account is not automatically considered cheating. It lists a series of legitimate uses, including protecting the highest achievement on a main account, or practising a specific champion without affecting personal rating. Phillip Koskinas, a Riot representative, responded directly on this issue in the announcement.
The third tier is the newest and most notable: the hitchhiker. A hitchhiker uses their own account, installs no software, breaks no technical rule, but queues alongside an account that is being boosted. Riot states it may revoke ranked points earned by this group in affected games.
Placed side by side, these three tiers reveal a clear logic: Riot is expanding the concept of responsibility from individual behaviour to the relationship between accounts. That is a far bigger change than locking 300,000 accounts.
The forgotten denominator
Riot estimates League of Legends has roughly 120 million monthly active players and VALORANT roughly 20 million. Together that makes 140 million, and 300,000 divided by 140 million gives roughly 0.2 percent.
The problem is that neither the 120 million nor the 20 million figure is attached to any specific source. Both appear as general estimates, with no independent research behind them. For a ratio used to frame the entire story, that is a serious weakness.
There is a bigger question about the denominator. League of Legends and VALORANT in mainland China operate inside Tencent's ecosystem, with separate anti-cheat and account-verification infrastructure that does not follow the global Vanguard rollout. The announcement does not say whether the 300,000 figure includes Chinese servers.
If it is global excluding China, then the 0.2 percent ratio was calculated on an inflated denominator, because a large share of League of Legends monthly actives sit in the Chinese ecosystem. If it includes China, then applying a tool like Vanguard inside a differently operated ecosystem within the same window is hard to imagine. Both possibilities lead to the same conclusion: 0.2 percent should be read as a direction, not a measurement.
From a spreadsheet in 2026, I learned to read markets the way you read a novel. But a novel is only trustworthy when the author is willing to say which chapter is fiction.
The economics of boosting
Boosting exists because there is both supply and demand, and both have concrete economic reasons.
On the demand side, buyers pay for something that cannot be bought directly with in-game currency: prestige. A high rank bracket is a social signal inside a community, a condition for joining certain playgroups, and for some younger players, a doorway to attention on streaming platforms. Seasonal rewards and limited frames increase the value of reaching a specific tier before a season closes.
On the supply side, boosting is real income. Those who do it are usually high-ranked players with superior skill who are not on a professional roster. In esports' labour structure, most tier-two and tier-three players earn very little or nothing at all. Boosting fills that gap: high skill, flexible hours, no contract, no agent.
When a publisher escalates enforcement, it acts on supply, not demand. Risk cost rises, so operators must charge more to offset the chance of losing accounts. But demand for prestige rank and seasonal rewards does not fall, because it is tied to psychology and to deadlines the publisher itself sets.
The familiar outcome of one-sided enforcement like this is a market that reprices and migrates toward lower-enforcement venues rather than disappearing. That lesson has played out in many digital service markets, from game accounts to in-game currencies.
Who gains, who loses
The clearest beneficiary is the honest ranked player. They are not named in Riot's announcement, but they gain directly: fewer boosted accounts in their games, fewer undeserved losses.
The losers are boosting service operators, plus a segment of players whose side income depends on the activity. This group has no voice in the announcement and no channel for rebuttal.
In the middle sits the largest and most vulnerable group: the ordinary secondary player. They queue with friends, do not know what state that friend's account is in, and can lose points for behaviour they did not commit. This is the group the announcement does not mention, even though the impact on them is real.
The cheapest gift: loss protection
Among the measures announced, one detail gets little attention yet delivers the largest felt impact for ordinary players: protection from rank-point loss when the system detects a cheater or a leaver.
This mechanic locks no accounts and requires no new identification infrastructure, but it fixes one very specific pain point: a hard-working player losing points in a game they could not control. Mathematically, it reduces the variance of a match sequence, making rank a marginally more accurate skill signal over sufficiently large samples.
For a publisher, this is the investment with the highest communications return in the entire package. It generates no big headline, but it touches millions of players every day.
People in this trade have no secrets, only timing that has not arrived yet. Riot launching loss protection alongside the 300,000 figure is not coincidence. One side is force, the other is goodwill. Every communications package needs both.
The verification roadmap: binding accounts to hardware
The most important part of the announcement is what Riot says it will do, not what it has done.
The plan includes multi-factor authentication at login, verification requirements that vary by rank tier, and, over the longer term, binding accounts to hardware through TPM 2.0, a hardware-level security standard enabling device identity attestation. The stated goal is blunt: make one-time accounts harder to create.

If that roadmap is fully deployed, the cost of creating a new account rises sharply. For cheaters, that is a cost. For ordinary players, it is also a cost, and this is the point the announcement does not address.
Hardware-level verification raises problems for users of public machines, internet cafés, or shared family computers. In some markets, internet cafés remain the primary place a meaningful share of League of Legends players play. An account bound to one device creates a substantial barrier for that group, and the barrier could be larger than the harm it prevents.
Beyond that, linking player identity to a hardware identifier raises privacy questions in markets with strict personal-data protection rules. The announcement does not touch this, and it is a gap worth tracking once the roadmap enters testing.
Impact on scouting and the amateur ladder
For professional-team fans, this story may look like it sits outside the arena. But the ranked ladder is the informal qualification system for the entire amateur-to-pro pipeline.
Academies and tier-two teams use ladder rank as their first filter. A young player who has never played a tournament can still be noticed by climbing high enough. When boosting dilutes that signal, the damage is not to the casual experience but to the accuracy of talent identification.
That is why concentrating verification at high ranks is strategically meaningful. Enforcement cost is pushed toward exactly where scouting and community attention occur.
In exchange, there is a short-term consequence worth tracking. If a large number of boosted accounts vanish from high elo, the percentile distribution in that zone will shift for a period, and hidden MMR calibration will have to readjust. For teams using rank as a filter, that means ladder data over the coming months should be cross-checked against scrim and youth-tournament results before recruitment decisions are made.
The blind spot: when the rulemaker also publishes the numbers
In this story, Riot Games plays four roles at once. It writes the rules. It enforces them. It is the sole source publishing enforcement statistics. And it is the direct commercial beneficiary of enforcement, because players who get cheated leave the game, and players who leave do not spend on skins or events.
There is no independent arbitration layer in that structure. This is an inherent feature of publisher-run esports, not a Riot-specific anomaly. But precisely because it is inherent, readers should remember that every figure in the announcement comes from a party with an interest in those figures looking impressive.
The more telling issue lies in specifics. The announcement provides no false-positive rate. It describes no appeals process. No third party audits the 300,000 figure. For an action touching 300,000 accounts, the absence of all three is a transparency gap larger than the scale of the action demands.
More serious in principle is the liability-by-association rule for hitchhikers. A player uses their own account, installs no software, breaks no technical rule, and can still lose ranked points simply for queuing with a friend the system has identified as being boosted.
In practice, hitchhikers usually do not know they are queuing with a boosted account. An ordinary player accepts an invite from a friend on their list, plays a few games, then loses points for behaviour they did not commit and did not know about. This is the most procedurally sensitive point in the entire story.
Alongside that, rank-differentiated verification requirements create two classes of citizenship inside one game. From a governance standpoint this has a basis: the higher the rank, the greater the value of cheating, so verification cost should be pushed there. But it also opens a question of equal treatment among players who all pay for the same product.
And one conceptual detail deserves a straight look. While Riot expands punishment to hitchhikers, it deliberately holds the line on secondary accounts. The list of legitimate uses shows the enforcement boundary is based on intent and behaviour, not on how many accounts a person owns. A soft boundary like that is extremely hard to enforce consistently across 140 million users.
This is the central paradox of the whole enforcement wave: Riot tightens where machine data makes proof easy, and loosens where judgement about intent is required.

What to track over the next two seasons
Four signals will determine where this story goes.
First, the cadence of data disclosure. If Riot repeats periodic reporting with trend lines, it will inadvertently establish an integrity-reporting standard for the industry, similar to how anti-doping reporting norms formed in traditional sport.
Second, how real the verification roadmap becomes. The moment requirements move beyond test scope is when the privacy debate erupts.
Third, the volume of hitchhiker cases actioned, and whether any publicly reported wrongful point revocation appears.
Fourth, the price of boosting services. If prices spike, it confirms the market repriced rather than disappeared.
The next domino
The answer to whether 300,000 accounts clean up the ladder will not come from another announcement. It will come from high-elo rank distribution over the next two seasons, from academy scouting data, and from boosting prices if anyone bothers to track them.
Crises pass, but the financial map stays. For youth teams, standardising account declarations for players and tightening discipline around queuing with strangers is no longer a minor matter. For other publishers, Riot turning anti-cheat into shared behaviour-governance infrastructure across multiple titles sets a new benchmark they will have to answer.
I do not trust hunches, I trust phone calls at two in the morning. The 300,000 figure sounds loud. But the thing that will still be discussed two years from now is TPM 2.0, not the number of locked accounts.
