You just got hit with a ban screen in Valorant or League of Legends and you're sitting there thinking, "What did I even do?" Maybe you genuinely know what triggered it. Maybe you have absolutely no clue. Either way, you're now staring at a message from Riot Games telling you your account is restricted, and the confusion is real.
Here's the thing about Vanguard, Riot's anti-cheat system — it doesn't just look for one thing. It monitors a massive range of behaviors, software, hardware configurations, and player actions. And the reasons it bans players go way beyond "you used an aimbot." I've spent years deep in this ecosystem, scouring official Riot support pages, Reddit threads, Discord communities, and player forums. What I've compiled here is the most comprehensive tier list of every known reason Vanguard bans players, ranked by severity and likelihood.
Let's break this down tier by tier.
S Tier - Guaranteed Bans That Vanguard Catches Almost Instantly
These are the nuclear-level offenses. If Vanguard detects any of these, you're getting banned — usually within minutes to hours, and often with a full HWID ban that blacklists your entire machine.
-
Using aimbots or aim-assist software. This is the most obvious one. Vanguard's kernel-level driver monitors for external processes that manipulate mouse input or interact with the game's memory to adjust crosshair positioning. According to Riot's own anti-cheat updates, aimbots are consistently the most detected and banned cheat category.
-
Running wallhacks or ESP overlays. Any software that reads game memory to display enemy positions, health bars, or other hidden information through walls. Vanguard detects both internal (injected) and many external (overlay-based) ESP tools.
-
Triggerbots. These automatically fire your weapon when your crosshair passes over an enemy hitbox. Vanguard flags the unnatural input patterns and the memory hooks these tools require.
-
Speed hacks or movement exploits. Modifying player movement speed through memory manipulation. Vanguard's server-side validation combined with client-side detection catches these quickly.
-
Injecting code into the Valorant or LoL game process. This includes DLL injection, function hooking, or any method of inserting unauthorized code into the running game. Since vgk.sys loads at Windows boot, it monitors process integrity from the moment your system starts.
-
Running known cheat engines while Vanguard is active. Tools like Cheat Engine, even if you're using them for a completely different single-player game, will trigger Vanguard. The kernel driver sees these tools running in memory and flags your system. This catches a surprising number of players who had no intention of cheating in Valorant.
-
DMA cheating hardware. Direct Memory Access devices that read game memory through PCIe slots. These are physical hardware devices designed to bypass software-based anti-cheats. Vanguard's kernel-level access gives it visibility into hardware-level memory operations, and Riot has been actively targeting DMA cheats since 2024.
-
Kernel-level cheat drivers. Custom drivers designed to operate at the same ring-0 level as Vanguard itself. These try to hide cheating software from detection, but Vanguard actively monitors for unauthorized kernel drivers and will flag — and ban — systems running them.
I guarantee most of the people reading this already knew about these. But here's where it gets more interesting.
A Tier - Very High Probability of Getting Banned
These offenses don't always result in instant bans, but Vanguard and Riot's systems catch them consistently. Many of these lead to HWID bans rather than simple account restrictions.
-
Playing on hardware that's already HWID banned. This one catches people off guard constantly. You buy a used PC from someone, create your own Riot account, launch Valorant, and you're banned before your first match. Vanguard already has that hardware fingerprint blacklisted. Your disk serial numbers, motherboard UUID, CPU identifier — they're all flagged. It doesn't matter that you're a legitimate player. The hardware itself is banned.
-
Creating new accounts after an HWID ban. You get banned, make a new Riot account, and try again. Banned within minutes. Vanguard queries your hardware identifiers at boot, compares them against its database, and flags the new account before you even finish the tutorial. This is how most players discover they have an HWID ban rather than just an account ban.
-
Using detected HWID spoofers. A lot of the free spoofers floating around Discord servers are already detected by Vanguard. Running one is essentially the same as waving a red flag. Vanguard doesn't just check your hardware IDs — it also looks for the fingerprints of known spoofing tools. If your spoofer is on Riot's detection list, you're getting banned faster than if you'd done nothing.
-
Account boosting. Playing on someone else's account to inflate their rank. Riot tracks login patterns, hardware fingerprints, and IP addresses. When an account suddenly logs in from completely different hardware with dramatically different performance metrics, it triggers their detection systems.
-
Using skin changers or model modifiers. This surprises a lot of players. You might think a cosmetic-only modification is harmless, but skin changers typically require injecting code into the game process or modifying game files — both of which Vanguard treats as cheat-level offenses. The intent doesn't matter to the anti-cheat. The method of action does.
-
Running reverse engineering or debugging tools. Programs like x64dbg, IDA Pro, or even Visual Studio's debugger attached to game processes. Vanguard monitors for debugging hooks and memory inspection tools that could be used to analyze or manipulate the game.
-
Packet manipulation. Using tools to intercept, modify, or replay network packets between your client and Riot's servers. This includes lag switches, packet editors, and network interception proxies aimed at the game connection.
-
Running virtual machines to play. Vanguard generally doesn't allow gameplay from within VMs because virtualized environments can be used to hide cheating software and spoof hardware identifiers. If Vanguard detects it's running inside a VM, it typically blocks the game from launching entirely, or bans the account.
B Tier - Common Bans That Many Players Don't Expect
This tier is where things get really interesting. These are the reasons that generate the most confused, frustrated posts on Reddit and Riot's support forums. Players in this tier often genuinely don't understand why they got banned.
-
Having cheat software installed but not running. This one comes up on Reddit constantly. A player has Cheat Engine installed from modding a single-player game weeks ago. They never opened it while playing Valorant. But because vgk.sys loads at boot and scans the system continuously, it can detect the presence of known cheat-related software — even when it's not active. The safest practice is to completely uninstall these tools.
-
Sharing a PC with someone who cheated. Your roommate, sibling, or friend uses your computer to cheat in Valorant once. They get caught. Now your hardware is flagged. Every account that logs in on that machine — including your legitimate one — gets caught in the HWID ban. This is one of the most common "I didn't do anything wrong" scenarios in the community.
-
Extreme toxicity, hate speech, and verbal abuse. Vanguard itself doesn't handle behavioral bans — that's Riot's reporting and moderation system. But the result is the same: your account gets banned. Repeated offenses can escalate from chat restrictions to temporary bans to permanent account bans. According to Riot's community guidelines, severe hate speech can result in immediate permanent bans without prior warnings.
-
AFK behavior and match abandonment. Consistently going AFK or disconnecting from matches triggers Riot's automated penalty system. This starts with queue restrictions and escalates to temporary bans and eventually permanent account bans for serial offenders. Riot detailed their AFK penalty system publicly.
-
Playing from restricted or blocked countries. Riot doesn't offer service in every country. If you're connecting from a country blocked from playing Valorant or a country blocked from League of Legends, your account can be restricted or banned. This sometimes catches travelers or people using VPNs to access other regions.
-
Using VPNs. This is a gray area that causes confusion. Riot doesn't explicitly ban all VPN usage, but connecting through flagged VPN IP addresses, using VPNs to circumvent regional restrictions, or VPN usage patterns that look like account sharing can trigger bans. Some VPN IPs are also shared with previously banned players, creating guilt-by-association flags.
-
Win trading in ranked. Coordinating with players on the enemy team to intentionally lose, inflating your rank artificially. Riot's systems analyze match patterns, and when the same players repeatedly appear in opposite teams with suspicious outcomes, both parties get flagged.
-
Intentional griefing and sabotage. Team-killing with abilities, blocking teammates, body-blocking in corners — consistent intentional griefing reported by multiple players leads to account penalties that can escalate to permanent bans.
-
Purchasing or selling accounts. Buying a Valorant or LoL account violates Riot's Terms of Service. If Riot detects an account has changed hands (through hardware fingerprint changes, IP shifts, behavioral pattern changes), the account gets banned. Purchased accounts are also frequently discovered during ban waves.
C Tier - Surprising Reasons That Catch Players Off Guard
Now we're getting into the territory that most guides never cover. These are the reasons I've found deep in forum threads, niche Discord communities, and player reports that don't get much mainstream attention.
-
Chargebacks on Riot Points purchases. Disputing a VP or RP purchase with your bank or credit card company almost always results in an immediate account ban. Riot treats chargebacks as fraud. Your account gets locked until the balance is resolved, and many players report permanent bans even after settling the debt. Riot's support documentation addresses this clearly.
-
Running certain overlay and capture software. Most mainstream software like OBS, Discord overlay, or NVIDIA GeForce Experience works fine. But certain third-party overlays that hook into DirectX or Vulkan in non-standard ways can trigger Vanguard. Players on forums have reported issues with lesser-known recording software, custom FPS counters, and screen annotation tools that inject into the rendering pipeline.
-
Modified game files. Changing config files, modifying texture files, or altering any game data. Even seemingly innocent changes like custom crosshairs implemented through file modification rather than in-game settings can trigger Vanguard's integrity checks. Vanguard verifies game file hashes, and mismatches get flagged.
-
Using automation macros for gameplay. I'm not talking about keyboard macros for typing. I mean tools like AutoHotkey scripts that automate in-game actions — automatic spray patterns, rapid-fire macros, or movement automation. Vanguard and Riot's systems detect unnatural input patterns, and macro usage for gameplay advantage violates Terms of Service.
-
Registry remnants from previously uninstalled cheats. You installed a cheat months ago, uninstalled it, and thought you were clean. But the cheat left registry entries, driver remnants, or system artifacts. Vanguard scans for these traces. Even if the cheating software is long gone, its footprint can trigger detection. This is why a clean Windows install is often recommended after any exposure to cheating software.
-
Running certain peripheral software. Some mouse or keyboard software that allows complex macro programming has been reported to cause issues. Products from less mainstream brands that install kernel-level drivers for their hardware customization can conflict with or trigger Vanguard's driver monitoring. The Vanguard FAQ addresses driver blocking but doesn't list every specific product.
-
Network anomalies and lag switching. Intentionally manipulating your network connection to gain an advantage (like making yourself temporarily unhittable). Riot's servers validate player positions and actions, and severe network manipulation patterns get flagged as cheating rather than poor connection.
-
Exploiting known game bugs intentionally. There's a difference between accidentally benefiting from a glitch and repeatedly, intentionally exploiting it. When Riot identifies a known exploit, they sometimes retroactively ban players who systematically abused it. This has happened in both Valorant and League of Legends during major bug exploits.
D Tier - Edge Cases and Disputed Bans
These are the reasons that show up in heated forum debates. They're not universally confirmed, but there are enough documented reports to take seriously. Do you see why understanding Vanguard's full scope matters?
-
False positives from specific hardware configurations. Certain hardware combinations have been reported to trigger false Vanguard detections. This has been documented during specific Vanguard update waves where batches of legitimate players with similar hardware got swept up. These are rare, but they're real. If you believe you've been falsely banned, understanding this possibility matters.
-
Internet café and shared computer environments. Players at internet cafés or LAN centers report bans because a previous user on the same machine cheated. The hardware is flagged, and every subsequent player inherits that flag. This is essentially the same mechanism as buying a used banned PC, just in a shared environment.
-
Having development tools or system inspection software running. Process Monitor, Process Explorer, kernel debuggers, and similar system analysis tools have been reported to trigger Vanguard in certain configurations. These tools operate at system levels that Vanguard monitors, and their behavior can resemble cheat-related activity.
-
Overclocking software conflicts. Some players report that certain overclocking tools — particularly those that modify CPU or GPU behavior at a low level — have triggered Vanguard blocks or bans. Tools that install custom kernel drivers to access hardware directly can conflict with Vanguard's driver integrity monitoring.
-
Dual-boot configurations. Players running dual-boot systems (especially Windows alongside Linux) have reported issues where Vanguard behaves unexpectedly after switching between operating systems. Boot-level changes and partition configurations can sometimes trigger Vanguard's integrity checks.
-
Phone number association with banned accounts. Riot requires phone number verification for ranked play in Valorant. If your phone number was previously linked to a banned account, using it on a new account can trigger automated detection. Multiple forum threads document this specific scenario.
-
Payment method association. Some players report that using the same credit card or payment method as a previously banned account flags new accounts. While Riot hasn't officially confirmed this as a ban trigger, the correlation appears in enough forum reports to warrant mention.
-
Same email domain patterns. Creating new accounts using obviously related email addresses (like player1@gmail.com, player1alt@gmail.com) after a ban. Riot's systems reportedly look for patterns in account creation that suggest ban evasion.
-
Running Windows Insider or preview builds. Non-standard Windows builds can cause unexpected interactions with Vanguard's kernel driver. Players on Windows Insider builds have reported both blocks (Vanguard refusing to load) and false detections.
F Tier - Rare and Unconfirmed But Reported
These are the most obscure reasons I've found across deep dives into community forums and niche discussions. They're not well-documented, but they appear often enough in independent reports that they deserve mention.
-
Bans carrying across Riot titles. Getting HWID banned in Valorant has been reported to affect League of Legends access, and vice versa. Since both games use Vanguard and share the Riot account system, this makes technical sense — Vanguard's hardware fingerprint is tied to the Riot ecosystem, not individual games.
-
Bluetooth and wireless peripheral anomalies. A handful of reports mention that certain Bluetooth input devices that frequently reconnect or change their identifiers caused Vanguard to flag input inconsistencies. This is extremely rare but has appeared in troubleshooting threads.
-
BIOS updates changing hardware identifiers. Updating your motherboard BIOS can change the SMBIOS UUID and other identifiers that Vanguard tracks. In some cases, this has reportedly caused players to be flagged because their hardware fingerprint changed unexpectedly — resembling spoofing behavior.
-
Third-party antivirus conflicts. Certain aggressive antivirus programs that operate at the kernel level can conflict with Vanguard. While this usually prevents the game from launching rather than causing bans, some players report that the conflict resulted in incorrect behavioral flagging.
-
RGB and device management software. Programs like iCUE, Razer Synapse, or ASUS Aura that install low-level drivers for hardware control. While mainstream versions are generally fine, specific versions or beta releases have been reported to trigger Vanguard's driver scanning in rare cases.
What Happens After Vanguard Bans You
So now you know why Vanguard might have banned you. But the important part is understanding what kind of ban you actually got, because that determines what happens next.
If it's an account ban, your specific account is restricted but your hardware isn't flagged. You could theoretically create a new account and keep playing. These are typically issued for behavioral offenses like toxicity, AFK penalties, or minor Terms of Service violations.
If it's an HWID ban, that's a completely different situation. Your hardware fingerprint — disk serial numbers, motherboard UUID, CPU identifier, RAM serials, MAC addresses, monitor EDID data, and more — is blacklisted. Any new account you create on that machine gets flagged before you even reach the main menu. These bans are typically permanent with no defined expiration.
The way Vanguard works is that vgk.sys queries your hardware identifiers at boot — before you launch the game, before you even see your desktop. It creates a composite fingerprint from multiple identifiers. Changing just one component, like swapping your network adapter or spoofing only your IP address, isn't enough because Vanguard cross-references multiple data points.
This is why a lot of the "fixes" people try don't work. Formatting your drive changes the volume serial but not the hardware serial burned into the firmware. Changing your MAC address only covers one of eight or more identifiers Vanguard checks. Using a VPN does nothing for hardware identification.
Why Understanding the Reason Matters
If you're going to deal with a Vanguard ban, you need to understand exactly what triggered it. Why? Because different ban reasons require different approaches.
A behavioral ban can potentially be appealed through Riot's support system. An HWID ban from cheating? That appeal almost never works. A ban from flagged hardware you bought used? That requires dealing with the hardware fingerprint itself.
For HWID bans specifically, the options come down to either replacing enough physical hardware components to change the fingerprint — which can cost over $1,800 depending on what's flagged — or using a spoofer that emulates hardware identifiers at the level Vanguard checks.
Tools like Saturn Spoofer exist specifically for this scenario. It's built exclusively for Riot's Vanguard, spoofing CPU, motherboard, RAM, SSD, network card, router, monitor, and peripheral identifiers without requiring a Windows reinstall. They offer a 2-hour free trial so you can verify it works with your specific situation before committing. But as with any tool in this space, the cat-and-mouse game between anti-cheat and spoofing is ongoing — what works today may need updates as Vanguard evolves.
The other thing is, if you know your ban was behavioral, going straight to a spoofer is overkill. Understand what you're dealing with first. If you're not sure whether you have an account ban or hardware ban, try creating a new account on the same machine. If the new account gets instantly banned, you're hardware flagged.
So to Kind of Recap
Vanguard bans players for a much wider range of reasons than most people realize. From the obvious stuff like aimbots and wallhacks down to surprising triggers like chargeback disputes, cheat engine remnants, skin changers, shared hardware, and even specific hardware configurations during bad ban waves.
The severity tiers matter because they determine the type of ban you'll receive, how likely an appeal is to work, and what you actually need to do next. S-tier offenses almost always result in permanent HWID bans. B and C-tier offenses might give you a shot at a successful appeal. D and F-tier situations often represent false positives or edge cases where Riot's support team might actually help — if you can clearly document your situation.
Whatever your situation is, the worst thing you can do is panic and start trying random fixes from outdated Discord advice. Understand what triggered the ban, understand what type of ban you have, and then make an informed decision about how to move forward.
Stay safe out there.