Buyer's guide

Anti-cheat explained

Every game we cover ships an anti-cheat, and each one detects differently. Knowing which system you are facing tells you why a build goes offline, why bans arrive late, and which precautions actually change your odds.

Delivery
Instant

Keys assigned atomically the second payment clears.

Refunds
24h window

Full refund if a key never activates. No games.

Payment
Card & crypto

Stripe, NOWPayments, wallet credit. No scraping.

Support
Human

Operators on Discord, not scripted bots.

The systems you'll meet

Easy Anti-Cheat (EAC)

Kernel driver + user-mode module
Seen in: Tarkov (legacy), Rust, Apex Legends, Fortnite, Delta Force

Signature scans of loaded modules, integrity checks on the game process, handle and thread inspection, plus server-side heuristics on impossible aim and movement. Detection often lands in delayed ban waves rather than instantly.

BattlEye

Kernel driver with dynamic module streaming
Seen in: Escape from Tarkov, Rainbow Six Siege, ARC Raiders, DayZ

Streams new detection modules to clients at runtime, so a build that was clean this morning can be flagged this afternoon without a game patch. Heavy on memory reads, process enumeration and driver-level hooks.

Riot Vanguard

Always-on kernel driver, loads at boot
Seen in: Valorant, League of Legends

The most invasive of the mainstream systems: it runs before the game, enforces secure boot and TPM, blocks unsigned or vulnerable drivers, and bans at the hardware level. This is why Valorant editions have the strictest requirements on our store.

Tencent ACE / ACE-Guard

Kernel driver + server-side behaviour analytics
Seen in: Arena Breakout Infinite, Delta Force

Aggressive process and driver scanning combined with server-side statistical review of headshot ratio, loot routing and reaction time. Accounts are often flagged by behaviour first and confirmed by client telemetry after.

Three detection layers

  • Signatures. Known bytes of a known build, on disk or in memory. Beaten by private distribution and frequent rebuilds - which is exactly what "on update" downtime buys.
  • Integrity and system state. Injected threads, tampered game memory, open handles, unsigned or blocklisted drivers, secure boot and TPM state. This is where per-edition requirements come from.
  • Behaviour. Server-side scoring of aim snaps, headshot ratio, reaction time and loot routing. No build can hide this for you; only your settings and restraint can.

What this means before you buy

  • Check the edition's live status and its dated transition history, not a permanent badge.
  • Read the requirements panel: CPU vendor, secure boot, virtualisation and spoofer notes are anti-cheat driven.
  • Expect downtime after game patches - that is a provider protecting you, not failing you.
  • Keep settings human. Behavioural detection does not care how private your build is.
  • Never run your main account on a title with hardware-level bans.

FAQ

How does anti-cheat detect a cheat?
Three broad ways. Signature detection matches known bytes of a build in memory or on disk. Integrity and behavioural checks look for tampered game memory, injected threads, suspicious handles and unsigned drivers. Server-side analytics ignore your PC entirely and score how you play - headshot percentage, snap angles, reaction time and loot routing. A private build can defeat the first two and still get you flagged by the third.
What is a kernel-level anti-cheat?
A driver that runs in ring 0, the same privilege level as Windows itself. It can see every process, every driver and every memory region on your machine, which is why kernel anti-cheats require secure boot and blocklist vulnerable drivers. It is also why cheats for those games are harder to build, more expensive, and more sensitive to Windows updates.
What is a ban wave?
Detections are collected quietly and actioned in batches, sometimes weeks later, so cheaters cannot tell which build or which session was flagged. That delay is exactly why 'I have been using it for a month with no ban' is not evidence a build is safe.
Why do builds go on update?
When an anti-cheat vendor ships a new detection module or the game patches, developers pull the build offline until it is re-verified. On Norium that state is published as 'on update' with the date, and licence timers freeze while it lasts, so you are not billed for downtime.
Does a HWID spoofer defeat anti-cheat?
No. A spoofer addresses hardware bans - it changes the identifiers used to recognise your machine after an action. It does not hide a cheat from a memory scan and it does not undo behavioural flags. Our HWID spoofer explainer covers when it genuinely matters.
Which games are riskiest?
Anything on Vanguard, because of boot-time kernel enforcement and hardware bans. BattlEye titles are next because modules stream in without warning. Tencent ACE titles sit in the middle technically but lean hard on behavioural review, so playing conservatively matters more than the build you run.
Can anti-cheat see my whole PC?
A kernel driver technically can enumerate processes, drivers and memory while it is running. That is a real privacy trade-off you accept when you install the game, not something a cheat changes. It is also why running unknown free loaders as administrator is a much bigger risk than most people assume.
Check what's undetected right now
Live state for every edition we sell, with the date it last changed.