Nearly 300,000 League of Legends and VALORANT Accounts Locked: When Vanguard Crosses the Anti-Cheat Boundary
Core answer: Riot Games đã xử lý gần 300.000 tài khoản League of Legends và VALORANT vì gian lận xếp hạng, sau khi tích hợp Vanguard vào League of Legends từ tháng 9 năm 2025. Tỉ lệ tương đương khoảng 0,2% tổng người chơi ước tính, kèm kế hoạch xác minh bằng phần cứng. Key facts: - Riot Games xử lý gần 300.000 tài khoản trên League of Legends và VALORANT vì gian lận xếp hạng. - Vanguard được tích hợp vào League of Legends từ tháng 9 năm 2025, sau khi triển khai trên VALORANT. - Tỉ lệ tài khoản bị khóa xấp xỉ 0,2% trên tổng ước tính khoảng 140 triệu người chơi hai tựa game. - Riot lên kế hoạch triển khai MFA, TPM 2.0, và yêu cầu xác minh khác nhau theo bậc xếp hạng. - Smurf không tự động bị coi là gian lận; người xếp hàng cùng tài khoản cày thuê có thể bị thu hồi điểm xếp hạng. Source attribution: Riot Games, công bố sau ngày 1 tháng 9 năm 2025 | Cross-checked: VuaBong.vn Related Q&A: Q: Vanguard là gì? A: Vanguard là phần mềm chống gian lận cấp nhân của Riot Games, ban đầu dành cho VALORANT và được tích hợp vào League of Legends từ tháng 9 năm 2025. Q: Hitchhiker nghĩa là gì? A: Hitchhiker là thuật ngữ Riot Games dùng để chỉ người chơi dùng tài khoản của mình nhưng xếp hàng cùng một tài khoản đang bị cày thuê, có thể bị thu hồi điểm xếp hạng. | Dữ liệu tham chiếu: VangBong.vn Player Depth Index Q: Riot Games có kế hoạch xác minh tài khoản ra sao? A: Riot Games dự kiến triển khai MFA, TPM 2.0 và yêu cầu xác minh khác nhau theo bậc xếp hạng nhằm hạn chế tạo tài khoản dùng một lần.
In September 2026, the anti-cheat software Vanguard — until then exclusive to the VALORANT client — was formally integrated into the League of Legends client. A few quarters later, Riot Games announced it had actioned nearly 300,000 accounts across both titles for ranked cheating. For a data writer like me, this is the kind of story most worth dissecting: a large number, a strong claim, and very few public variables to cross-check.
Three hundred thousand accounts. The sound of it fills every headline. But when I pull that number out of the noise and place it beside a few other variables, it shrinks considerably. The most interesting part of the story is not the account count — it is the new rules Riot is trying to build.

The match is over, but the data remains.
SETTING THE FRAME
Riot Games runs two distinct ranked ecosystems: League of Legends and VALORANT. For League of Legends, the ranked ladder is the backbone of the entire talent pipeline — from amateur to academy, to tier-2, to pro. Scouts use rank as an initial filter before moving to scrim and tournament evaluation. VALORANT has a similar structure but is younger.
Before September 2026, Vanguard protected only VALORANT. Grafting it into League of Legends is not a champion balance patch. It is a system-level change: software running at the kernel level of the operating system, directly intervening in how the game client behaves on a player's machine. This characteristic has drawn privacy and system-access controversy since Vanguard launched on VALORANT — an angle the new announcement does not address.
My analytical weight goes to three groups: rules and governance, risk profile, and industry transmission. This is a story about competitive integrity and platform governance. Reading a "meta shift" into it is fabricating data.
THREE POLICY LAYERS AND A NEW DOCTRINE
Riot announced a three-layer policy package. The first layer is direct action against cheating accounts. The second is League Points (LP) protection: players do not lose points when a match contains a detected cheater or a leaver. This is a calculated expected-value change — it reduces the penalty for bad-luck games, compresses variance, and over large samples makes LP a marginally more accurate skill signal.
The third layer is the important one: a roadmap for account identity verification, including multi-factor authentication (MFA), Trusted Platform Module 2.0 (TPM 2.0), and verification requirements that differ by rank. This is a two-tier governance model: the higher the rank, the stricter the verification. Structurally, it mirrors tiered compliance regimes in traditional sport, where whereabouts rules apply more heavily to elite athletes.
Two terms Riot added to its formal vocabulary are worth keeping. "Boosting" is a highly skilled player logging into another person's account to raise its rank. "Hitchhiker" is Riot's new term for a player using their own account but queuing alongside an account being boosted.
The "hitchhiker" doctrine is the most contestable rule change. Riot asserts the authority to revoke ranked points from players who used their own legitimate accounts, played by the rules, and violated no software rule — simply because they queued with a flagged account. This is expanded liability-by-association, and it raises false-positive exposure for innocent players who happened to duo with a boosted friend.
For repeat boosters, the heaviest penalty includes account locks, main-account suspension, and loss of earned ranked points. Once the hardware verification roadmap completes, such a penalty approaches a platform-level lifetime ban, because TPM 2.0 and hardware identity make recreating an account far more costly.
Yet the smurf policy moves in the opposite direction. Riot states clearly: smurfing is not automatically cheating. It enumerates legitimate uses, including protecting one's highest achievement on a main account, or practicing champions and agents. The enforcement boundary therefore rests on intent and behavior, not account count. A soft line like that is hard to apply consistently — and this is the point the community will contest most, because it shows Riot is not doing what a large share of players demand.
WHERE THE DATA TALKS BACK TO THE HEADLINE
At first, I asked what the real effect of this enforcement action is — not the scale of the action, but its impact. With League of Legends estimated at around 120 million players and VALORANT at around 20 million, the ratio of locked accounts is roughly 0.2%. That 0.2% is small enough to turn the "great purge" headline into a platform-governance story, where the main effect is not eliminating cheating but repricing a behavior.
But one caveat about that 0.2% itself must be stated immediately. The two player figures, 120 million and 20 million, are attributed to no specific source. And a more important question: over what period did the 300,000 account actions occur — three months, six months, a year? There is no timeline, no prior-period comparison, no breakdown by title. If September 2026 is the start point, the figure most likely represents one quarter or less, not a full year. That changes the intensity reading — the annualized run-rate would be substantially higher.
I write my blog from a rented room in Nha Trang; now probability takes me everywhere. Across seasons of tracking, I learned one thing: numbers from an enforcing party are never neutral data. Every quantitative claim in this announcement originates from a single source — Riot Games, simultaneously the rule-maker, the enforcer, the data source, and the commercial beneficiary of enforcement. There is no independent arbitration layer, no false-positive rate, no described appeals process. This transparency gap is large relative to the scale of action: 300,000 accounts actioned with no published verification mechanism.
Another variable is also overlooked: regional separation. League of Legends and VALORANT in mainland China operate under Tencent's ecosystem, with localized anti-cheat and account verification infrastructure distinct from the global Vanguard rollout. Whether the 300,000 figure includes, excludes, or can be separated from the China servers — the announcement does not answer. If the figure is global-ex-China, then the effective coverage ratio against total players is misjudged, since a large share of League of Legends' monthly actives sits in the China ecosystem.
And then there is the most overlooked part: the future verification roadmap. If MFA, TPM 2.0, and rank-tiered requirements deploy as announced, this will be a far bigger structural change than locking 300,000 accounts, because it binds account identity to physical hardware. For players on shared machines, internet cafés, or old computers, hardware attestation creates a structurally disadvantaged player group — one the announcement never mentions. Riot is building a two-tier citizenship model, and that is where questions belong, not the 300,000 number.
THE GRAY MARKET REPRICES, IT DOES NOT VANISH
Look directly at the economic driver. Why does boosting exist? Because there is demand — players want prestige rank, seasonal rewards, ego satisfaction. And because there is supply — highly skilled players at the lower tiers of the esports labor pyramid need extra income. In many regions, tier-2 and tier-3 players are poorly paid, making paid boosting an economically rational supplementary income, even though it violates the terms of service.
Enforcement on one side without touching the other only raises prices. When the supply of cheap boosted accounts shrinks, the price per transaction rises — and the per-transaction revenue of remaining operators can increase. This is the standard outcome of supply-side enforcement in gray markets: the market reprices rather than disappears. Another systemic risk: if verification levels differ across servers, boosting demand may migrate to softer-enforcement servers, much as account-trading activity concentrates in low-enforcement regions.
TRANSMISSION TO THE INDUSTRY AND THE TALENT PIPELINE
The most underrated transmission channel is the amateur pipeline. If ranked integrity improves, ladder-derived scouting signals become more trustworthy — a positive for academy recruitment and tier-2 development across regions. Conversely, if enforcement is uneven by region, talent-identification quality diverges by server. Scouting departments that use rank as a screening filter may need to re-weight their criteria toward scrim and tournament evidence.
Riot is establishing anti-cheat as cross-title infrastructure. Extending Vanguard from VALORANT to League of Legends turns a single-title tool into a platform-level governance layer, and expanding its remit from software-cheat combat to ranked-system behavior control raises the bar for other publishers. Riot now holds patch control, tournament control, client-level system access, and hardware-level identity verification — the most complete vertical governance stack in esports, while narrowing the already-thin space for independent oversight.
At the same time, one risk area is rarely discussed: professional and semi-pro alt accounts. These players maintain practice accounts, and some sit near the enforcement boundary. Ambiguous cases — a pro queuing with a flagged account — could create headline risk for clubs. Teams should likely standardize account declaration and duo-queue hygiene policies.
WHAT TO TRACK
An empty stadium does not need an audience; it needs an analyst willing to look. And what is worth looking at here is not how many accounts Riot locked, but whether the ranked signal becomes more trustworthy as a result. If yes, that is good news for the entire talent pipeline. If no, we have just witnessed a repricing of the gray market under the cover of a moral statement.
Four signals to track over the next six to eighteen months. First, the cadence of Riot's enforcement data disclosure — periodic with trend lines could establish an industry-wide integrity reporting standard; a one-off then silence means the 300,000 should be read as a directional probe, not verified evidence. Second, the actual rollout of MFA and TPM 2.0. Third, the number of "hitchhiker"-type false positives surfacing in the community — any wrongful LP revocation will trigger a fierce due-process backlash. Fourth, whether the high-rank distribution shifts anomalously after enforcement — if enforcement concentrates at the top, the visible high-elo population could temporarily contract, distorting percentiles and MMR calibration.
Three hundred thousand locked accounts is a real number. But the probability I assign to this action genuinely cleaning the ladder sits at medium. What is more certain: Riot is testing a new identity-governance model, and that model will shape how esports players are identified for years. The match is over, but the data remains — and this time, the data worth tracking is not in the accounts that vanished, but in the accounts about to prove who they are.
