Why Getting Banned Without Cheating Is Harder Than It Sounds

▶ Watch (0:28)

The University of Birmingham team wanted to study anti-cheat by experiencing bans firsthand, without using actual cheats. Three obstacles complicated this. First, modern anti-cheat often detects and crashes cheat tools before any ban is issued. Second, games run ban waves, so players rarely know when a ban landed or what triggered it. Third, identifying the specific cause requires isolated testing. The team ran multiple machines attempting different techniques simultaneously before they could trace which action actually earned a ban.

Techniques That Crash Games but Earn No Ban

▶ Watch (3:44)

The first attempts all failed to produce a ban. Cheat Engine crashed Valorant and gave them an early-leave penalty. Renaming Notepad to match a known cheat tool name kicked them from Fortnite but left the account intact. User-mode calls to kernel API functions crashed the game. Vulnerable signed Intel drivers (the same technique real malware uses) were blocked by anti-cheat kernel code that hooks DLL load functions. Running the game inside a hypervisor to place cheat code above the anti-cheat layer caused EasyAntiCheat, BattlEye, and Vanguard to each deliberately blue screen the machine.

First Bans: Manual Mapping and Simulated Inputs

▶ Watch (10:36)

Overwatch 2 runs its anti-cheat at user level. Standard injection via LoadLibrary is caught immediately. The team built manual mapping: allocating executable memory in the target process, copying PE sections, resolving imports, and calling the DLL entry point directly, bypassing all monitored API calls. Overwatch 2 banned them for unauthorized cheat programs or hacks. No cheat ran. For Apex Legends, Sam connected a musical keyboard to simulate game inputs, then updated the software to auto-fire on a held key. EasyAntiCheat flagged the inhuman click timing and synthetic inputs and issued a ban.

Overlay Bans and Timing the Driver Load

▶ Watch (17:55)

Fortnite banned an account after a custom animated crosshair overlay ran on screen. EasyAntiCheat and BattlEye whitelist overlays from Steam and Discord. A moving non-whitelisted overlay triggers a ban. For Rainbow Six Siege, the team reversed the BYOVD order: load the vulnerable Intel driver before the game starts, write cheat code into kernel memory, unload the driver, then launch the game. BattlEye cannot block the driver load because the game is not yet running. It detects the modified kernel state on launch and issues a ban.

Hardware ID Bans and Physical Chip Modification

▶ Watch (26:12)

Anti-cheat systems build hardware fingerprints from RAM serials, motherboard IDs, GPU serials, and network card identifiers. A ban on that fingerprint survives any account change. Sam tried four motherboard ID methods: AMI EFI firmware (volatile, breaks secure boot), AFUDOS BIOS reflash (write-protected on most boards), SPI chip clip access with FlashROM (CPU power sharing corrupts reads on large boards), and desoldering the chip entirely to flash on a separate adapter. For RAM, a Raspberry Pi Pico talking SPD and a 7-volt pulse to clear write protection let them rewrite the serials.

Cloning Hardware IDs to Ban Someone Else

▶ Watch (32:05)

Sam obtained Tom’s hardware IDs from a live CD boot while Tom was away from his office. He spoofed those IDs on his own machine, performed the ban-triggering techniques, then restored his original hardware IDs. When Tom logged into Valorant the next morning on his unmodified machine, Vanguard matched the hardware fingerprint to a previously banned device and banned his account. Tom’s machine was clean. His account was clean. His bootloader was unlocked. Shipping pre-banned hardware to a target, or writing banned IDs to a machine via malware, achieves the same result.

Notable Quotes

an advanced form of disrespect Sam Collins · ▶ 31:51

This is on a completely clean machine. Tom Chothia · ▶ 33:00

no one locks their bootloader Tom Chothia · ▶ 33:16

it also could make mailware way worse. Marius Muench · ▶ 34:14

Key Takeaways

  • Manual memory mapping bypasses LoadLibrary monitoring and earns bans in user-mode anti-cheat games like Overwatch 2.
  • Anti-cheat systems deliberately blue screen machines running hypervisors rather than simply blocking or banning them.
  • Hardware ID bans survive account resets; desoldering and reflashing chips removes the fingerprint entirely.
  • Stolen hardware IDs applied to a separate machine cause innocent players to receive hardware bans without notice.
  • Any anti-cheat relying on hardware banning is vulnerable to pre-banned components shipped directly to a target.

About the Speaker(s)

Sam Collins is a PhD research student at the University of Birmingham, UK, focused on attacks and defenses in man-at-the-end scenarios found in anti-cheat systems. He teaches reverse engineering and binary analysis through game hacking and developed a multiplayer game that undergraduate students must hack as coursework.

Marius Muench is an assistant professor at the University of Birmingham. His research covers security of embedded systems, binary and microarchitectural exploitation, and defenses. He obtained his PhD from Sorbonne University in cooperation with EURECOM and worked as a postdoctoral researcher at the Vrije Universiteit Amsterdam. He created avatar2 and FirmWire, frameworks for analyzing embedded systems firmware and cellular basebands, and has presented at Black Hat, Reverse.io, REcon, and Hardwear.io.

Tom Chothia is a Professor of Cyber Security at the University of Birmingham, UK. His research develops mathematical analysis techniques and applies them to real-world security problems. Past work on the security of EMV, Apple Pay, banking apps, pacemakers, and video game cheats has received widespread media coverage.