Riot Games · 2 supported games · All anti-cheats
Riot Vanguard protects Valorant and League of Legends on Windows through a client, platform service, and the `vgk.sys` kernel driver. Its defining design has been establishing trust before user-space cheat software can load, rather than waiting until the game process starts.
Riot now supports an on-demand path for sufficiently secured PCs that pass Vanguard Pre-Check. Other configurations retain the startup-driver trust model. Secure Boot, TPM-backed measurements, and Windows driver attestation are therefore central to Vanguard's story even when `vgk.sys` does not need to remain loaded from every boot.
TraceX Spoofer rewrites supported identifiers without disabling Riot's required security features. TraceX runs once after the one-time setup and can be deleted; it is not a Valorant or League session mask.
Vanguard's kernel trust boundary lets it validate memory and system state before or during the protected session. For machine identity, the concrete Windows surfaces include the SMBIOS Type 2 baseboard serial through `Win32_BaseBoard`, `Win32_DiskDrive`, `IOCTL_STORAGE_QUERY_PROPERTY`, and `Win32_PhysicalMemory`. Riot does not publish a complete HWID field list or weight table.
The OS layer includes `MachineGuid` at `HKLM\SOFTWARE\Microsoft\Cryptography`, installation and volume identifiers, and MAC enumeration. Those values recur when the same Riot account is replaced or when Valorant is reinstalled. League and Valorant can encounter the same machine inside Riot's ecosystem, but their account actions should not be reduced to an automatic two-game ban claim.
TPM 2.0 and Secure Boot are more than generic buzzwords here. Riot describes TPM-backed runtime driver attestation and pre-boot security as ways to verify which drivers entered the system. The TBS API exposes the TPM 2.0 endorsement key and related operations, but Riot's public Vanguard material focuses on trust measurements rather than saying it stores that key as a universal HWID.
Composite or fuzzy matching can combine durable board, storage, OS, network, and attestation signals. The same inputs may reappear in Valorant and League of Legends, creating cross-title re-flagging exposure under one publisher. Riot still controls the enforcement scope, and Vanguard data is not claimed to propagate to EAC, BattlEye, or RICOCHET.
TraceX rewrites supported SMBIOS, storage, memory, Windows, and network identifiers consistently across the values Windows exposes. The workflow changes the machine profile without patching `vgk.sys`, the Riot Client, or either game's memory.
Complete the one-time setup, run TraceX once, and delete the tool. The supported rewrites persist without a resident process. Keep TPM 2.0, Secure Boot, and Vanguard Pre-Check requirements configured as Riot directs.
Vanguard can change its startup and on-demand modes independently of Valorant or League releases. Use the timestamped Working result after a Riot update instead of treating the historic boot-time architecture as a future-proof compatibility claim.
Vanguard historically used the startup driver to establish trust before user space. Riot now offers an on-demand mode for sufficiently secured PCs that pass Vanguard Pre-Check, while other systems retain the startup model. The exact path depends on current Riot requirements and the PC's security configuration.
TPM-backed measurements can support boot and runtime driver attestation, helping Vanguard verify the system's trust history. Windows exposes TPM services through TBS. Riot's public material emphasizes integrity measurements and driver evidence; it does not establish that the TPM endorsement key is stored as one universal Vanguard HWID.
Do not assume an automatic two-game ban. Valorant and League can present the same machine values to Vanguard inside Riot's ecosystem, so cross-title re-flagging exposure exists. Riot administers the games and decides enforcement scope; the recurring fingerprint is the mechanism, not proof of simultaneous bans.
A game reinstall does not change SMBIOS Type 2, physical-disk descriptors, memory data, `MachineGuid`, or MAC addresses. A Windows reinstall changes some OS values but normally preserves firmware and storage inputs. Composite matching can therefore retain the device relationship.
Riot Vanguard compatibility depends on the boot-time vgk driver and the separate Valorant or League of Legends release using it. Consult the detection-status page after Riot updates Vanguard; Working is a display label, not a future-proof guarantee.
No. TraceX rewrites its supported identifiers without disabling TPM 2.0, Secure Boot, or Riot's attestation requirements. Complete the one-time setup, run it once, and delete the tool. Keep the platform settings Vanguard currently requires and verify the timestamped Working result.
Background on how Vanguard builds a hardware profile, what enforcement looks like afterwards, and how TraceX rewrites the identifiers behind it.
Kernel level anti cheat explained: what Ring 0 access really gives Vanguard, EAC and BattlEye, when their drivers load, and what it means after a ban
TPM anti cheat and Secure Boot checks now gate Black Ops 7, Battlefield 6 and Fortnite tournaments. Here is what they measure and what they cannot rewrite
How HWID bans work, step by step: what anti-cheats collect, how the fingerprint is hashed and stored, and what happens the moment you launch the game again
Just got HWID banned? Start here: what to stop doing right now, how to confirm it is hardware and not your account, and the 8 steps that actually get you back
Compatibility changes over time. Review the current timestamped result for Vanguard before downloading or running TraceX.
Download TraceX