HWID Spoofer does not crack TPM 2.0 directly: it wins a race to rewrite the disk, network and motherboard serial numbers before Windows 11 protections and the game's anti-cheat get a chance to read them. That moment is called the boot order race: kernel drivers in Windows initialize in a strict order, and the outcome depends on whose driver loads first, the spoofer's or the protection's. The gap is measured in fractions of a second, but it decides whether the protection sees the real hardware or values that are already spoofed.
We tested this mechanism on live products from our HWID Spoofer catalog: PERMANENT and UBGG are verified on GIGABYTE, ASUS, MSI, ASRock, Acer and Lenovo motherboards, while SMG additionally cleans BattlEye log traces after every launch. Below we walk through what happens between powering on a machine and starting a game, and why TPM 2.0 remains the one place where spoofer engineering runs into chip physics instead of code. This is not abstract theory: understanding this mechanism directly decides which catalog product fits your motherboard and your game.
Boot order race: how HWID Spoofer technically gets past TPM 2.0 and Secure Boot
UEFI, Secure Boot and driver load order
A machine starts with the UEFI firmware, which checks the digital signature of the Windows bootloader against a list of trusted keys burned in by the motherboard maker. Secure Boot halts loading of any component without a valid signature, so the Windows bootloader passes the check and hands control to the kernel. The kernel then brings up drivers by priority: storage and filesystem first, then networking, then kernel-level protection and anti-cheat drivers, and only after that does the user session start, where the game itself launches. Each stage takes a fraction of a second, and that narrow window decides which hardware data the system hands further down the chain. Some protections keep running a short background hardware check even after the game starts, so a spoofer needs to do more than win the first round of the race, it has to keep the rewritten values stable for the whole session.
Why driver signing decides who wins the boot order race
A spoofer driver must either carry a valid digital signature or initialize before Secure Boot policy starts blocking unsigned components, otherwise Windows 11 simply refuses to load it. That is what the boot order race comes down to: if the protection driver initializes before the spoofer, it reads the real disk, motherboard and network serial numbers before they get rewritten, and the whole operation becomes pointless. That is exactly why ANCIENT and SMG list a full set of parameters rewritten together, disk, RAM, monitor, S.M.A.R.T, network, registry, GPU and motherboard, rather than a single value on its own. The more parameters get rewritten in sync during one pass, the smaller the chance the protection catches even one untouched identifier. Anti-cheat updates often shift the exact moment their driver joins the initialization queue, so spoofer developers have to recalculate that timing after almost every major protection patch.
TPM 2.0 and the Endorsement Key: where engineering ends and chip physics begins
TPM 2.0 stores the Endorsement Key, a unique cryptographic key the manufacturer burns in physically at the factory, never meant to be rewritten in software. Windows 11 requires TPM 2.0 and Secure Boot together precisely because both mechanisms confirm hardware authenticity cryptographically instead of just reading a text value from the registry, and that gap sits at the level of chip physics, not operating system settings. For Vanguard in Valorant that makes the task an order of magnitude harder than for other protections, which is why fewer working solutions exist for Vanguard and they cost more. A dedicated breakdown of the HWID ban and TPM specifically in Valorant lives in a separate blog article, here we cover the general mechanism rather than one specific anti-cheat. The TPM standard's designers deliberately ruled out a user-side rewrite of the Endorsement Key at the specification stage, so no future spoofer driver update removes that limitation.
What actually gets spoofed: registry, SMBIOS, EFI variables and disk
Real spoofers operate at a level that is physically reachable: the Windows registry, SMBIOS tables, EFI variables, disk and network serial numbers, the MAC address and the Windows Product ID. That is exactly the zone where REPORTED swaps identity with one click inside an active session instead of a full Windows reinstall, and the identity holds until a PC reboot. BC works in a similar way in its static mode: the same set of spoofed data persists on every launch until the user manually deletes the bauntihwid file from the loader folder and requests a fresh data set. The TPM Endorsement Key is not part of that chain for any product in our catalog, and any seller who promises to rewrite it is promising something that contradicts chip physics rather than a merely difficult technical task. That is exactly why sellers who describe their product honestly always list a concrete set of parameters instead of a vague promise of total invisibility.
What this means for you in practice
The mechanics of the boot order race translate into concrete recommendations that we build into our HWID Spoofer catalog picks. None of the recommendations below are detached from an actual price or an actual product, everything ties back to a catalog we maintain and test ourselves.
- One-time purchase versus subscription: PERMANENT at $44 and UBGG's Lifetime tier at $61 close the question with a single install, because they rewrite identifiers physically instead of reloading them on every game launch, which matters most for people who do not want to fiddle with settings every session.
- Budget entry point: SMG starts at $2 a day and stays the cheapest product in the catalog, while still rewriting BIOS, CPU, motherboard, RAM, storage drives and the registry in one pass, and it is a convenient way to try spoofing technology for the first time without a big upfront cost.
- RAID0 breaks the boot order race: a disk array changes controller initialization order, so any spoofer in the catalog needs the array dissolved before installation, exactly as stated in the PERMANENT and UBGG descriptions, and we recommend checking your disk configuration before buying rather than after a failed install.
- Multiple sessions in one day: REPORTED, whose identity gets reused without randomization on every launch, fits situations where stability between sessions matters more than a one-time Windows reinstall, from $29 for 14 days, and that shows up most in games where you have to relaunch several times in one evening.
- Games without a hard TPM dependency: for Arena Breakout, Delta Force and PUBG we carry separate products from Crooked Arms at $4-5 a day, they reset on PC reboot and require launching the cheat first, then the spoofer, which is worth planning for ahead of a session.
Where to get a tested HWID Spoofer for your situation
All nine products we mentioned are currently undetected and sit together in the ForgeCheats HWID Spoofer lineup, where you can compare protection type, price and compatibility before buying. We update statuses manually rather than through an automated scanner, so the list stays current as of this article's publish date.
If you play a game with a hard kernel-anticheat like Vanguard or Ricochet, check the separate breakdown Which games a spoofer cannot help with: Vanguard, Ricochet and hard kernel-anticheat, it lays out honestly where a spoofer genuinely will not help. We think it is fair to flag those limits upfront instead of leaving it as a surprise after purchase.
We cover installation questions and mode selection for specific motherboards in Telegram (200+ members) and Discord (637+ members), our specialists there can point you to the HWID Spoofer catalog option that fits your exact case. We answer in both chats personally, without bots or template replies to technical questions.
Frequently asked questions about TPM 2.0, Secure Boot and how HWID Spoofer works
Can a spoofer actually rewrite the TPM Endorsement Key?
No, the Endorsement Key is burned in by the chip manufacturer at the factory and is not meant for software rewriting, which is why no product in our catalog claims that function. Spoofers work at the level of the registry, SMBIOS, EFI variables and disk and network serial numbers, a separate zone that is actually reachable. That is a fundamental limit for any spoofer on the market, not a quirk of one specific product in our catalog.
Why does the same spoofer work on some motherboards and not others?
Driver initialization order in UEFI and the set of available EFI variables differ between manufacturers, which is why PERMANENT and UBGG are separately tested on GIGABYTE, ASUS, MSI, ASRock, Acer and Lenovo. If your board is not on the tested list, it is worth confirming compatibility before buying. We update the tested board list as feedback comes in from buyers.
What is the boot order race in plain terms?
It is a race between the spoofer driver and the protection driver over which one initializes first in the Windows kernel after Secure Boot. Whoever loads first decides which serial numbers the system sees down the line, which is why the spoofer driver's signature and load timing are critical to the outcome. Understanding this principle explains why the same spoofer can behave differently after a Windows update.
Why is Vanguard in Valorant harder to spoof than EasyAntiCheat or BattlEye?
Vanguard is tied to Secure Boot and TPM 2.0 with the Endorsement Key, while EasyAntiCheat, BattlEye, ACE and FACEIT operate at kernel level without that hard dependency on the physical chip. That leaves fewer solutions for Vanguard, they cost more, and they update slower after patches. We recommend budgeting extra time to find a working solution specifically for Vanguard compared to the catalog's other protections.
Which spoofer in the catalog is easiest for a beginner to run?
SMG from $2 a day and ANCIENT from $4 a day rewrite the full parameter set in one pass and need no manual tuning for a specific motherboard. It is worth comparing the full current lineup in our catalog of working HWID spoofers before choosing between a one-time purchase and a subscription, and if in doubt it is worth confirming compatibility with support first.

