Blog

Which Anti-Cheats Can an HWID Spoofer Not Beat in 2026?

Which Anti-Cheats Can an HWID Spoofer Not Beat in 2026?

An HWID spoofer runs out of options once the anti-cheat ties its checks to TPM 2.0 and Secure Boot through the chip's factory-burned Endorsement Key - that is exactly why Riot Vanguard in Valorant and League of Legends stays the hardest case on the market, with Call of Duty's Ricochet close behind in difficulty. For the other kernel-level anti-cheats the picture is different: EasyAntiCheat, BattlEye, ACE and FACEIT do not require that kind of hardware binding, so spoofing the hardware profile there stays stable and gets updated fast after every protection patch.

At ForgeCheats we keep 9 live HWID spoofers in our catalog, and we regularly check with support which exact anti-cheat each product actually covers, because whether a spoofer will work for your game depends on the protection, not the brand of the cheat. This article is not about one product or one anti-cheat - below we break down each protection separately and show where an HWID spoofer keeps an undetected status reliably, and where you should weigh the risk before paying for a subscription. For example, this week a buyer asked in support whether SMG covers the current BattlEye patch in Escape from Tarkov, and we checked the answer against the product's official supported list instead of a generic marketing line. That approach saves time for both us and the buyer, because the decision is based on documentation rather than a guess.

Anti-cheat by anti-cheat: where an HWID spoofer holds up and where it struggles

Riot Vanguard in Valorant and League of Legends - the hardest ceiling for any spoofer

Vanguard does not stop at reading the disk and registry, it ties its checks to Secure Boot and TPM 2.0, specifically to the Endorsement Key - a key the manufacturer burns into the chip at the factory and that was never meant to be rewritten. That makes a proper spoof at the TPM level a much deeper engineering problem than a routine swap of disk, network or monitor serials, which is exactly why such solutions stay rare even among sellers who confidently cover EasyAntiCheat and BattlEye. Riot extended Vanguard to League of Legends too, so the limitation applies to both games at once: working solutions are noticeably fewer, cost more and get updated less often than spoofers built for other protections. In practice this means even experienced spoofer developers tend to cover EasyAntiCheat and BattlEye first, and only add Vanguard support last, if they add it at all. The price of such rare solutions is often two to three times higher than equivalents built for EasyAntiCheat, purely because of the amount of engineering work required on the TPM side. A detailed technical breakdown of the HWID ban and the role of TPM in Valorant lives in a separate article on our blog, so here we do not repeat it in full and move straight into comparing it with other anti-cheats.

Call of Duty and Ricochet - an aggressive combination of a kernel driver and server-side ML detection

Ricochet is built differently from Vanguard, but that does not make it easier: on top of the kernel driver it runs server-side ML detection that cross-references hardware and account behavior patterns after the match, not only at launch. A spoofer can honestly swap the HWID at boot and the account can still get caught in a retroactive review a few days later based on accumulated data. From what we see in conversations with buyers, claims like "works with Call of Duty" deserve separate verification - ask the seller which game build and Ricochet patch the specific spoofer was tested against before you commit to a subscription, and do not treat the word "universal" as a guarantee. We notice that some sellers avoid loud claims about Call of Duty altogether because of this delayed review, preferring to write "under testing" honestly instead of "fully undetected".

EasyAntiCheat and BattlEye - territory where a spoofer behaves predictably

Unlike Vanguard, neither EasyAntiCheat nor BattlEye ties its checks to a hardware TPM Endorsement Key, so swapping disk, network, registry and monitor serials stays stable and predictable from patch to patch. This is where most of our catalog lives: ANCIENT and SMG rewrite the full serial set down to the BIOS, CPU and motherboard, PERMANENT and UBGG add a one-time install with no ongoing subscription for the life of the machine, and BC keeps a static mode built specifically for games running BE and EAC, where holding the same spoofed profile between sessions matters. Developers of these products ship updates faster after protection patches precisely because the protection itself reacts to changes more predictably than Vanguard with its hardware binding. In our experience this group of products triggers the fewest support complaints about getting detected after a patch, which indirectly confirms how predictable EasyAntiCheat and BattlEye really are.

ACE and FACEIT with ESEA - also strict kernel-level, but without the TPM tie-in

Arena Breakout runs on ACE, and competitive platforms like FACEIT and ESEA maintain their own client-side kernel module - both are strict, but like EasyAntiCheat and BattlEye they do not require a hardware TPM key to verify hardware, so spoofing them stays an engineering task within reach. For Arena Breakout the catalog has a dedicated ARENA BREAKOUT SPOOFER from Crooked Arms with temporary logic, which needs to be launched after the cheat and requires a system reboot before first use or the profile will not apply. For sessions where you need to change the hardware fingerprint quickly without reinstalling Windows, REPORTED works as a seed system: the same fake profile gets reused with one click, resets on PC reboot and supports over 25 games, including titles with FACEIT-compatible anti-cheat checks. The same logic applies to other competitive clients with a similar protection architecture, where the deciding factor is not the platform's brand but the specific implementation of the hardware check.

Anti-cheatGames (example)Spoofing difficultyWhat to check in the ForgeCheats catalog
Riot VanguardValorant, League of LegendsMaximum, tied to TPM 2.0 and the Endorsement KeyLimited, read the product page and ask support
RicochetCall of DutyHigh, kernel driver plus server-side ML detectionCase by case, ask about the current game build
EasyAntiCheatFortnite and other titlesStandard, no TPM tie-inANCIENT, SMG, PERMANENT, UBGG
BattlEyeTarkov, Rust, PUBGStandardSMG, BC, REPORTED
ACEArena BreakoutStandard, updates ship oftenARENA BREAKOUT SPOOFER from Crooked Arms
FACEIT and ESEACS2 and tournament platformsStandard, sensitive to repeated patternsREPORTED, seed system with profile rotation

How to check that an HWID spoofer actually covers your game before you pay

The phrase "universal spoofer" in a product description almost never means the product covers Vanguard as confidently as EasyAntiCheat - every product in our catalog has a specific list of supported protections, and we recommend checking it line by line rather than trusting the headline claim. It takes five minutes, but it saves money if it turns out the protection you actually need is simply not on the list. We regularly cross-check these lists with the development team ourselves when preparing product pages for publication.

  • Open the product page and find the list of supported anti-cheats - for ANCIENT, SMG, PERMANENT, UBGG and BC it is listed as a separate block, not a generic "works with every protection" line.
  • If you play Valorant, League of Legends or Call of Duty, message support before paying and ask them to confirm the status specifically for the current patch of that game, not the product's general undetected status.
  • Match the protection type to your task: the PERMANENT approach used by ANCIENT and SMG suits a one-time full hardware reset, the REPORTED seed system suits frequent session changes, and the temporary logic used by Crooked Arms for Arena Breakout and Delta Force needs a relaunch after every PC reboot.
  • Check the hardware requirements and launch order - PERMANENT and UBGG claim compatibility without RAID0 on GIGABYTE, ASUS, MSI, ASRock, Acer and Lenovo motherboards, while Crooked Arms spoofers require launching the cheat first and the spoofer only after.
  • Keep in mind that no spoofer lifts an account ban issued for player reports - it only clears the hardware-level block, so if the suspension is account-based you need a different fix entirely.

What to do next

If your game runs on EasyAntiCheat, BattlEye, ACE or FACEIT, the whole current ForgeCheats HWID spoofer catalog fits without major caveats - choose between the PERMANENT approach of ANCIENT and SMG, the one-time install of PERMANENT and UBGG, the static mode of BC or the seed system of REPORTED for frequent session changes. If the limitation you are hitting is Vanguard specifically, read our article on how a spoofer technically works with TPM 2.0 and Secure Boot first - it explains in depth the mechanism we mentioned above but did not break down in detail in this piece. We try to keep these lists current after every major protection update, but the final check before you buy is still on you.

Still have questions about a specific game - ask in Telegram (200+ members) or Discord (637+ members), our support there can tell you whether a specific product covers your protection right now, before you commit to a payment.

Questions about when an HWID spoofer does not work

Is there a spoofer that stays undetected specifically against Riot Vanguard?

Working options against Vanguard exist, but there are noticeably fewer of them and they cost more because of the protection's tie to TPM 2.0 and the Endorsement Key the manufacturer burns into the chip at the factory. We do not currently carry a guaranteed product specifically for Valorant and League of Legends, so always confirm the current status with support before paying for anything aimed at these games.

Why is Call of Duty's Ricochet harder than EasyAntiCheat or BattlEye?

Ricochet combines a kernel driver with server-side ML detection that analyzes data after the match, not only at launch, and can retroactively revisit a decision days later. EasyAntiCheat and BattlEye check hardware mostly locally and predictably, without that delayed review, so HWID spoofing there behaves more stably and keeps an undetected status longer. That does not mean Ricochet is unbeatable, but a claimed undetected status there is worth rechecking more often than for other protections.

Does an HWID spoofer lift an account ban issued for player reports?

No, a spoofer only changes the digital hardware fingerprint, such as disk, network and registry serials, not the status of the account itself in the game's database. An account suspension from other players' reports gets lifted through different means and has nothing to do with an HWID ban, so a spoofer will not help here regardless of which anti-cheat the game runs.

Why do free spoofers get a detected status so fast?

Anti-cheats scan the driver binary itself by signature, and once a single copy of a public spoofer lands in the detection database, every user running that exact build gets flagged along with it. Private builds from our HWID spoofer catalog get updated selectively and do not circulate widely in the open, so on average they hold an undetected status noticeably longer than public alternatives. That is why even a single leak of a build into the open usually marks the end of its life as an undetected product.

Which catalog product should I pick if my game runs ACE or FACEIT?

For Arena Breakout under ACE, the ARENA BREAKOUT SPOOFER from Crooked Arms with its temporary logic and launch-after-the-cheat order is the fit. For platforms like FACEIT and ESEA, REPORTED with its seed system and support for over 25 games without reinstalling Windows is the more convenient choice.