Almost two decades ago, it was relatively easy for cheaters to simply patch the memory of a running game client and see it straight up rebroadcast any of those modifications directly to the server, amusingly then becoming an
unmitigated spectacle for any other connected player. Thankfully though, the categorically surgical efforts of game engine architects and the sorta anxious, well-meaning energy of anti-cheat developers, have for the most part, since made “user-mode” methods of cheating obsolete, and almost all games today come pre-built with defenses hardened to the cheats of old. For example:
- To slow the speed at which cheat developers can disassemble, understand, and instrument each game client, many competitive titles also make use of client-sided obfuscation to hinder attackers from too easily deciphering their routines.
- Studios now utilize game engines with authoritative, fully-simulated servers that absolutely reject “nonsense” data from their connected clients, meaning you’d rarely see “exploits” like godmodes, infinite ammo, teleporting, or say, turning into a horse, because the server should never “believe” these requests to be physically possible, unless the game you're playing is Pretty Derby, in which case, the only true exploit would be successfully explaining it to my dad.
- Most multiplayer games also have detections for third party tools that might try to tamper with the running process, looking for local anomalies, like libraries in their application that shouldn’t be there or modifications to assets on disk that would break the game.
Fortunately, these defaults are no less true for Riot, and we would consider ourselves fairly well-defended against under-sophisticated “internal” cheating methods, which are used today only by those that are addicted to bans. So for the last 5 years, the fast-favorite methods for a competitive edge in our competitive games have been “kernel-level” cheating, Direct Memory Access abuse (DMA), and computer vision cheats (pixelbots).