Riot locks nearly 300,000 League of Legends and VALORANT accounts: Vanguard is expanding from cheat detection into ranked-behaviour enforcement
core_answer: Riot Games đã khóa gần 300.000 tài khoản League of Legends và VALORANT vì gian lận xếp hạng, sau khi tích hợp Vanguard vào League of Legends từ tháng 9 năm 2025. Quy mô tương đương khoảng 0,2% trong ước tính khoảng 140 triệu người chơi, nhưng chưa được kiểm toán độc lập.
key_facts: Riot Games xử lý gần 300.000 tài khoản League of Legends và VALORANT vì gian lận trong chế độ xếp hạng.; Vanguard được tích hợp vào client League of Legends từ tháng 9 năm 2025, sau nhiều năm chỉ phục vụ VALORANT.; Ước tính khoảng 120 triệu người chơi League of Legends và 20 triệu người chơi VALORANT mỗi tháng.; Tỷ lệ xử lý tương đương khoảng 0,2%, nhưng mẫu số không được gán nguồn cụ thể.; Riot dự kiến bổ sung xác thực đa yếu tố, TPM 2.0, xác thực phần cứng và yêu cầu khác nhau theo thứ hạng.
source_attribution: Nguồn: báo cáo tin tức gốc về đợt xử lý tài khoản của Riot Games, công bố ngày 10 tháng 1 năm 2026 | Cross-checked: VuaBong.vn
related_qa: question: Chính sách mới của Riot Games ảnh hưởng tới người chơi đi nhờ như thế nào?, answer: Người chơi dùng tài khoản của chính mình nhưng xếp hàng cùng tài khoản đang được cày thuê có thể bị thu hồi điểm xếp hạng dù không vi phạm quy tắc phần mềm nào.; question: Smurfing có bị Riot Games coi là gian lận trong chế độ xếp hạng không?, answer: Riot Games nêu rõ smurfing không tự động bị coi là gian lận và liệt kê nhiều mục đích sử dụng chính đáng, cho thấy ranh giới thực thi dựa trên ý định và hành vi.; question: Xác thực phần cứng TPM 2.0 sẽ thay đổi điều gì với người chơi?, answer: TPM 2.0 gắn tài khoản với một thiết bị cụ thể, làm tăng chi phí tạo tài khoản dùng một lần và có thể gây bất lợi cho người chơi dùng máy chung hoặc quán net.
For months I kept a private list of about twenty Challenger and Master-tier accounts on the Southeast Asian server, tracking their mid-lane indices and win rates after each patch. In the first days of January 2026, seven of those names vanished from the ladder within four days. No notice, no explanation, no status update. Simply names that stopped refreshing their match history, leaving a gap in a list I still open every morning.

Days later, Riot Games confirmed it had actioned nearly 300,000 League of Legends and VALORANT accounts for cheating in ranked play. The enforcement sweep followed the integration of Vanguard — a kernel-level anti-cheat client — directly into the League of Legends client in September 2026, after years of serving only VALORANT.
Data never lies; only impatient readers do. And this time, most readers stopped at the first three digits of the headline.
Context: a new layer of control has been laid down
To read this sweep correctly, it has to be separated from the familiar news categories. This is not a balance-patch story, a roster-change story, or a tournament-result story. It is a platform-governance story, and it touches two titles at once.

Vanguard has long been known as an anti-cheat solution operating at the kernel level of the operating system. That property makes it effective against cheat software, and it also makes it a subject of debate over privacy and system access. Bringing Vanguard into League of Legends is a structural change in how the client behaves on a user's machine, not a change in champion power or match tempo.
Against that backdrop, the notable part is the direction of expansion. Vanguard is no longer only hunting cheat software. It is being used to police behaviour inside the ranked system: boosting, hitchhiking, and other forms of ladder manipulation. This is the single most important shift in the whole story: from technical anti-cheat to the governance of competitive behaviour.
In Riot's own framing, the goal is to improve player experience and limit negative effects. That framing sounds reasonable, but it has to be read alongside every accompanying measure rather than in isolation. Because alongside the bans sits a package of policy changes with far more weight than the bans themselves.
Where nearly 300,000 accounts sit inside the player base
The original report supplies its own revealing division. Against estimates of roughly 120 million monthly League of Legends players and roughly 20 million VALORANT players — about 140 million combined — nearly 300,000 accounts equals roughly 0.2%.
That 0.2% immediately cools the headline reading. It turns a story of a great purge into a story of routine operations. But the division has two holes worth naming.
First, the 120 million and 20 million figures are not attributed to any specific source in the source material. They appear as general estimates. For an article that anchors itself on scale, an unsourced denominator is a serious methodological flaw.
Second, and more importantly, no time window is stated. Vanguard entered League of Legends in September 2026. If nearly 300,000 is a cumulative figure since that point, it represents roughly one quarter or less, not a year. The annualised run rate would be materially higher than a surface reading suggests.
When data speaks, emotion has to take a step back. Here the data says two things at once: the absolute scale is large, the relative share is small, and neither has been independently audited.
There is another variable the source material does not handle: the regional operating model. League of Legends and VALORANT in mainland China sit inside Tencent's ecosystem, with anti-cheat and account-verification infrastructure distinct from the global Vanguard rollout. Whether the nearly 300,000 figure includes, excludes, or can be separated from the China-server population remains unanswered.
If the sweep covers only non-China regions, the 0.2% ratio is computed on a wrong denominator, because a large share of League of Legends' monthly actives live inside that ecosystem. That is a potentially material denominator error, not a minor detail.
The economics of boosting
To read the sweep properly, you have to understand the market it targets. Boosting is a paid or arranged service relationship in which a highly skilled player logs into someone else's account to raise that account's rank. It is a gray market sitting on top of Riot's intellectual property.
There is a structural feature of the esports labour market here that few articles touch. Boosting service providers tend to be highly skilled, and a subset of them overlaps with high-ranked amateurs, even with tier-2 and tier-3 players seeking income. When wages at the bottom of the esports pyramid are thin, supply for the boosting market finds a way to appear. That is a labour-market characteristic, not an individual moral failing.
The transfer market is an unsolved system of equations, and so is the boosting market. It has demand: players want prestige rank, seasonal rewards, image. It has supply: skilled players need income. Riot can raise the risk premium on both sides, but demand and supply remain.
Operating experience gives me a fairly cold conclusion: when a governing body tightens supply, gray-market prices usually rise rather than collapse. Providers who survive a cull sell higher, serve fewer clients, and can see margins per transaction rise. If that happens with boosting, a sweep of nearly 300,000 accounts will push service prices up rather than erase the service.
Vanguard is no longer only hunting cheat software
For years, publishers' anti-cheat war revolved around software: aimbots, wallhacks, scripts. Vanguard was designed for that war, and it was deployed in VALORANT before crossing into League of Legends.
What is happening now is different in kind. Expanding Vanguard's remit into ranked-system behavioural control places anti-cheat software in the position of shared behavioural-enforcement infrastructure. Vanguard becomes a platform-governance layer rather than a single-title tool.
Vanguard's move from a VALORANT tool to a platform-level governance layer is the development in this story with the greatest industry spillover. It raises the bar for other publishers and narrows the already-thin space for independent oversight.
One operational point deserves note: Vanguard's kernel-level nature has historically drawn debate over privacy and system access within the community. The source material does not surface this counter-narrative, which suggests a framing driven mainly by the publisher side.
For players on low-spec hardware, or those using peripheral software flagged as conflicting, deeper client behaviour can create access friction. That is a documented Vanguard characteristic, not a claim made in the source material, and it must be separated clearly when assessing.
Behind the queue: the hardware-verification policy
The least-covered part of the story is the part with the most weight. Riot is preparing a package of verification measures: multi-factor authentication, TPM 2.0 requirements, hardware authentication, and requirements applied differently by rank. The stated goal is to make "one-time" accounts harder to create.
If implemented, this is a far bigger change than the bans themselves. Nearly 300,000 accounts is an event that can pass within weeks. Binding identity to hardware is a structural change that can reshape the entire cost of account creation over years.
TPM 2.0 is a hardware security standard enabling device-level identity attestation. Applied to a game account, it implies binding the account to a specific machine. The secondary commercial effect is clear: the account-resale market is squeezed, and the gray economy sitting outside Riot's revenue narrows.
But that effect is not entirely positive. Hardware binding raises an access-equity question. In many regions, a significant share of League of Legends players play at internet cafés or on shared machines. For them, device attestation may create a structural disadvantage. The source material does not address this risk.
Rank-differentiated verification creates a two-tier governance model. In principle it is defensible: higher stakes demand stricter requirements, analogous to how whereabouts rules weigh more heavily on elite athletes in traditional sport. But it also raises an equal-treatment question, and this is precisely the kind of discretionary rulemaking the source material handles vaguely.
The contrarian angle: hitchhikers and the price of association
The most contested part of the sweep is not the boosted account. It is the group Riot calls hitchhikers.
A hitchhiker is a player using their own account, queuing alongside an account being boosted. They break no software rule. They do not log into anyone else's account. But under the new policy, their ranked points may be revoked.
This is notable in governance terms. Riot is expanding liability by association: a clean player can lose ranked points because of what the person they queued with did, even if they did not know. It is the single most contestable procedural element in the story.
The issue is not whether hitchhikers benefited. The issue is the evidentiary threshold and the false-positive rate. The source material provides no false-positive data, no description of an appeals mechanism, and no third-party verification. For a sweep on the scale of 300,000 accounts, that transparency gap is substantial.
One detail is easy to miss in the source material: the policy on smurfing is far softer. Riot states explicitly that smurfing is not automatically cheating, and enumerates legitimate use cases, including protecting your highest achievement on your main account. This shows Riot's enforcement boundary rests on intent and behaviour, not on account count.
A boundary built on intent is harder to enforce consistently than one built on a hard number. This is where community debate will concentrate, because it reflects the gap between player expectation and actual policy.
To be direct: if Riot applies rank-differentiated verification, the group most affected is the top of the ladder, where scouting and semi-pro visibility occur. If enforcement concentrates there, the short-term observable effect may be a contraction in the visible high-elo population, temporarily distorting percentile distributions and hidden-MMR calibration.
Consequences for the talent pipeline
This is the least-discussed transmission channel, but it may be the most important over the long run.
The ranked ladder functions as the de facto qualification system for the entire amateur-to-pro pipeline. Academies and tier-2 teams use ladder rank as a screening filter. When the ladder is manipulated by boosting, the scouting signal loses value. When manipulation is pushed back, that signal becomes more trustworthy.
In other words, the greatest benefit of the sweep is not the experience of casual players. It is the accuracy of the esports labour market.
But that benefit is only uniform if enforcement is symmetric across regions. If one server has softer verification, boosting demand can migrate there, the way gold-farming and account trading tend to concentrate in weak-enforcement regions. Talent-identification quality would then diverge by server rather than equalise.
For scouting departments that rely on ladder rank as a filter, I would argue for reweighting evaluation toward scrim and tournament evidence. Pressure is not the enemy; it is simply an uncontrolled variable. And the variable here is the reliability of ladder data by region.
What holds up after the sweep
Across nearly a decade of observing the industry, I have drawn one principle: when a system is in crisis, hunting for a single responsible individual tends to hide the system's breaking point. Process is the only thing that holds when pressure rises.
In this case, the process under examination is the identity-verification system and the ranked reward system. Both are mid-transition.
A small improvement with real experiential weight is LP-loss protection when cheating or leaving is detected. It reduces the penalty for unlucky games, compresses variance, and over large samples makes ranked points a marginally more accurate skill signal. In player-communications terms, its impact may be more positive than the bans themselves.
The next thing to track is not the ban count. It is the cadence of enforcement-data disclosure. If Riot publishes periodically, it could establish an industry-wide integrity-reporting standard, similar to how anti-doping reporting norms formed in traditional sport. If this is a one-off disclosure, its reference value is much lower.
The blind spots of the new policy
There is a structural contradiction the source material does not address. Riot is simultaneously the rule-maker, the enforcer, the supplier of enforcement statistics, and the commercial beneficiary of enforcement. There is no independent arbitration layer.
That contradiction is inherent to publisher-run esports, not a Riot-specific flaw. But as enforcement scope expands from technical anti-cheat to competitive-behaviour governance, the cost of missing independent oversight rises accordingly.
My reading: the sweep of nearly 300,000 accounts is directionally correct, but the real risk is not cheating. The risk sits in enforcement design, specifically the expansion of liability to third parties and the shift to hardware-bound identity.
A second systemic risk is gray-market adaptation. As noted, tightening supply does not remove demand. If boosting is pushed out of League of Legends and VALORANT, it can migrate to titles with softer enforcement. At industry level the problem is then displacement, not resolution.
One long-horizon signal to watch: expanding Vanguard's remit sets a precedent for anti-cheat software as general-purpose behavioural-enforcement infrastructure. That precedent could later be applied to other conduct categories. It is a governance signal to observe carefully, not to conclude hastily.
What fans should take away
Fans remember the goal; I remember the numbers behind it. For this story, the numbers behind it are 300,000, 140 million, 0.2%, September 2026, and TPM 2.0.
Read only the headline and a fan will believe the ladder was just cleaned. Read closely and they will see that a small share of players was actioned, and that a far larger change to the conditions of participation is being prepared. The two are not contradictory, but their scales are very different.
Every great victory begins with a carefully maintained spreadsheet. In this case, the spreadsheet is not in a team's analytics room; it is in the publisher's operations room. And the problem there is not how to ban more accounts, but how to make ladder rank a trustworthy signal again.
The next thing I want to see is not a new ban count. I want a published false-positive rate, a clearly described appeals mechanism, and post-enforcement ladder-quality data to compare against. When those appear, the bans become a real step forward in process rather than a headline that can fade within weeks.
Fans do not need to believe a promise. They need a dataset they can check.
