Blog / anti-cheat · · 11 min read · Signed KyTech Research

Choosing a Cheat Provider in 2026: Red Flags, Green Flags, and Real Signals

A technical buyer's guide for evaluating kernel cheat providers without falling for reseller marketing.

The average cheat landing page in 2026 looks like a phishing kit that got fired from a phishing job. Neon gradients, animated "ONLINE" pills, a five star rating with no reviewer names, and a countdown timer that resets when you refresh. Somewhere near the bottom, in a smaller font, sits the actual product: a monthly subscription to a Windows kernel driver that will either read game memory reliably for six months or get you HWID-banned inside a week. There is no way to tell which from the landing page. That is the problem this post exists to solve.

This is a buyer's guide for people who are picking a kernel cheat provider and want to evaluate one the way an engineer would evaluate a SaaS vendor. It is written from the KyTech engineering desk. We sell cheats. We are not going to pretend otherwise. What we are going to do is walk through the technical and operational signals that separate a serious provider from a reseller with a Shopify template, because a bad pick costs you an account, a hardware ID, and, if the provider is really shady, your payment method.

Red Flag: "100% Undetected" Anywhere in the Copy

Nothing sold on the internet is 100% undetected. Nothing. Not KyTech, not the provider your friend swears by, not the private closed-source cheat that costs a thousand dollars a month. Every ring 0 cheat in existence is either currently undetected or currently detected, and the state can flip during a single BattlEye update push on a Wednesday afternoon. A provider that writes "100% undetected forever" in the product hero has either been in the market for less than three months or is knowingly lying to close the sale.

The honest version of that claim is boring. It reads something like: "Undetected since our last public detection on 2026-04-11. See status page." That sentence carries information. "100% undetected" carries none.

Red Flag: No Changelog, No Build Cadence Transparency

If the provider's front page has never shown a build number, a patch note, or a commit-style log, the cheat is either not being maintained or the maintenance is happening in secret. Both are bad. Game clients update. Anti-cheat drivers update on independent cadences: BattlEye pushes signature updates without game patches, and Easy Anti-Cheat's integrity checks rotate on the vendor's own schedule (see our writeup on BattlEye vs Easy Anti-Cheat for how that split affects release engineering on the cheat side). A provider that ships silently cannot tell you whether they patched today, last week, or last quarter.

A real cadence log looks like this:

## 2026-07-29  build 3411  apex
- rebuilt against S25 client hash 0x9E3A1B44
- rotated overlay compositor entry point (previous flagged 2026-07-27)
- fixed crash on ADS during ring close on Storm Point

## 2026-07-27  build 3407  apex
- DETECTED at 03:14 UTC by EAC signature push
- users on 3406 and older auto-disabled at loader
- rolled back overlay hook to shared-memory transport
- no bans observed, all sessions terminated cleanly

## 2026-07-25  build 3405  apex
- S25 loot pool table offset refresh

If the provider does not publish something in this shape, ask why. If the answer is "we don't want to give info to anti-cheat vendors," treat that as a euphemism for "we don't want to give info to customers either."

Red Flag: Refusing to Explain How the Driver Loads

Every kernel cheat in 2026 has to answer the same question: how do you get code into ring 0 on a Windows 11 24H2 machine with Driver Signature Enforcement, HVCI, and the Microsoft signed third-party driver Blocklist all active? There are a small number of honest answers. Attestation-signed driver with a real cert. Test-signing mode with a warning to the user. A signed third-party driver approach with a specific driver name and a rotation policy. Manual mapper on top of a leaked signed driver. Each has trade-offs, and each is a legitimate technical choice.

A provider who refuses to answer at all is hiding one of two things: they are using a load technique that will not survive HVCI (see Microsoft's HVCI documentation at learn.microsoft.com/en-us/windows-hardware/design/device-experiences/oem-hvci-enablement), or they are riding a signed third-party driver that MiShowBadMapper on 24H2 now refuses to alias as NonCached over WriteBack kernel pages. That last one killed a whole generation of cheats in the second half of 2025 and most of the providers that got wiped out never told their customers what happened.

Ask. If the answer is a shrug or "trade secret," walk.

Red Flag: Resellers Pretending to Be Developers

The tell is structural. Look at the TOS: does it name a legal entity, or is it a wall of copy-pasted clauses from three other sites? Look at the Discord: are the support roles named things like "Reseller," "Distributor," "Level 3 Support" instead of "Dev," "QA," "Ops"? Look at the update announcements: are they signed, or posted by a bot that just links to a Telegram channel you cannot read?

Resellers are not evil by themselves. A reseller who is upfront about being a reseller and points you at the upstream provider is a legitimate part of the market. A reseller pretending to be the developer will not be able to fix your problem when the cheat breaks, will not know when a patch is coming, and will not refund you when the upstream goes dark. This is where most "the site just disappeared with my money" stories come from.

Red Flag: No Stated Anti-Cheat Coverage Per Game

"Works with Apex." Which anti-cheat? Apex Legends ships with Easy Anti-Cheat as the primary layer plus a proprietary Respawn overlay that watches for input anomalies. A cheat that handles EAC's kernel driver but ignores the input pipeline gets its user shadow-banned inside three matches. "Works with CS2" is the same story: Valve Anti-Cheat plus VACnet server-side ML (Valve announced VACnet at GDC 2018 and has since expanded it, per their own community posts). A serious provider tells you exactly which layers they defeat and which layers they do not touch, per game.

Red Flag: Free Trials That Ask for a Credit Card

If you have to hand over a payment method to try the cheat, it is not a free trial. It is a subscription with a cancel button, and cancel buttons on cheat sites do not always work. A real trial is a time-limited key, given out through the Discord to users who have been in the server long enough to prove they are not a competitor doing recon.

Red Flag: No Public Outage or Detection History

This is the single loudest signal that separates a technical provider from a marketing operation. When a cheat gets detected, the userbase gets banned in a wave. There is no hiding it. If the provider never posts about downtime and their community suddenly loses a hundred accounts on the same day, you are watching a coverup in real time. The honest move is to post the detection within the hour, disable new activations, and publish a post-mortem. The dishonest move is to blame "user error" in DMs while the frontpage still says "ONLINE."

Red Flag: Guarantees on Ban Immunity

"Ban guarantee" is a marketing hallucination. No provider can guarantee this because the ban decision is made on a machine they do not own by a company that hates them. What a provider can offer is a prorated refund or credit against paid days on their own downtime, which is a business commitment, not a technical one. If you see "if you get banned we give you a new account free," ask where the new accounts come from. The answer is usually "stolen or farmed," which is a supply chain you probably do not want to be part of.

Red Flag: Bulk Discounts as the Main Pitch

"Buy 5 keys, get 2 free" as the hero copy is a tell that the provider is selling to resellers, not end users, and expects a short product lifetime. Cheats with long undetected runs price for retention, not for volume dumps.

Red Flag: Discord Locked Behind Purchase

You cannot evaluate a provider whose community you cannot read. A public preview channel with old changelogs, status pings, and general chat is table stakes. Fully-gated Discord means the provider does not want prospective buyers to see the complaints.

Green Flag: Transparent Architecture

A provider willing to say "we run a signed kernel driver, we do not inject anything into the game process, we communicate over a private IOCTL with an obfuscated code table" is telling you something falsifiable. You can verify it with Process Explorer and a driver list. Vagueness is the enemy. Any usermode-vs-kernel decision has real consequences for detection surface, and a shop that will not commit to which side of the line they sit on is not one you should be paying.

Green Flag: Documented Update Cadence

The best providers publish a target window. "We patch within 48 hours of a game update or we credit the day." That is a service level, not a slogan. It gives you a number to hold them to. If they miss, you have grounds to complain in public. If they never miss, the number becomes a marketing asset that they earned rather than invented.

Green Flag: Honest Downtime Posts

When a detection hits, the correct response is a pinned message within an hour, activations disabled, and a plain-English explanation. The KyTech loader posts a machine-parseable status blob that looks like this:

{
  "product": "kytech-apex",
  "build": "3411",
  "status": "operational",
  "last_detection": "2026-04-11T03:14:00Z",
  "days_undetected": 116,
  "loader_reachable": true,
  "credit_active": false
}

That blob comes from a real endpoint. Users can curl it. There is no "trust us" involved.

Green Flag: Operator Cap on Signups

Mature providers cap new activations. There is a technical reason: every new user is a new opportunity for a competitor or an anti-cheat researcher to buy a copy and reverse it. A provider that runs an open floodgate has either not thought about this or does not care. KyTech's Apex product runs a soft cap and reopens when we ship a new build. If you see "unlimited slots forever," expect a short product lifespan.

Green Flag: HWID Spoofer Sold Separately

A provider who bundles "spoofer included, don't worry about it" is usually shipping a hardcoded registry cleaner that HWID banners defeated in 2023. Real HWID spoofing is its own subsystem: it hooks the driver stack for storage, network, and SMBIOS reads, and it has to be maintained against BattlEye and EAC's independent hardware fingerprint modules. Selling it separately is a signal that the provider treats it as a real product, not a checkbox. KyTech's HWID spoofer is currently in Apex-only beta for exactly this reason: we would rather ship one working spoofer than five broken ones.

Green Flag: Public Technical Writing

If the provider maintains a technical blog that describes real Windows internals correctly (PsSetCreateProcessNotifyRoutineEx, ObRegisterCallbacks, MmCopyVirtualMemory, PsLookupProcessByProcessId, the difference between ProbeForRead and just dereferencing a usermode pointer inside a driver), they employ engineers. If the blog is generic anti-cheat trivia scraped from Wikipedia, they employ a marketing intern. This distinction shows up everywhere else in the product.

Where Cheat Quality Signals Actually Come From

Three places, in order of reliability:

  1. Build cadence, publicly logged. Not a "recent updates" widget that shows the same three entries for a month. A dated log with rollbacks visible. If the log shows a rollback, that is a good sign, not a bad one. Rollbacks mean the provider tests in production and admits when something breaks.
  2. Signature rotation policy for shops riding third-party signed drivers. For providers that load via a signed third-party driver with a known primitive, the question is how often they rotate to a new driver when Microsoft's blocklist catches up. Weekly is aggressive. Monthly is typical. "Never, we've been on the same driver for two years" is a warning. Our driver is signed under our own attestation, which removes the rotation problem, but the trade-off is that our signing surface is a real business asset we have to protect.
  3. Driver load protocol, documented. A one-page technical doc that describes how the loader talks to the driver, what IOCTLs it exposes, and what happens if the driver is already loaded. This document exists in every serious shop. It rarely gets published, but it always exists internally, and a support team that has read it answers questions differently.

Marketing Copy vs Status Page: Side by Side

Here is the shape of a reseller landing page, the kind you should close:

<!-- reseller landing page: every line of this is a lie or noise -->
<section class="hero">
  <h1>100% UNDETECTED APEX CHEAT 2026</h1>
  <div class="pill online">ONLINE 24/7</div>
  <div class="stars">5.0 (12,847 REVIEWS)</div>
  <p>Trusted by over 50,000 players worldwide since 2019!</p>
  <p>Lifetime ban protection guarantee.</p>
  <div class="timer">FLASH SALE ENDS IN 00:14:32</div>
  <a href="/buy" class="cta">BUY NOW - BULK DISCOUNTS</a>
</section>

Here is the shape of a technical provider's status page, the kind you should trust:

kytech-apex           build 3411   op   116d clean
kytech-cs2            build 1902   op    54d clean
kytech-ow2            build 0812   op    31d clean
kytech-bo7            build 0447   op    22d clean
kytech-fh6            build 0203   op    88d clean
kytech-roblox         build 0119   dev  beta, no SLA

last incident: 2026-04-11 03:14 UTC  kytech-apex  EAC signature push
resolution:    2026-04-11 05:02 UTC  rebuilt, users credited 1 day

One is a slot machine. The other is a service. Pick the service.

Quick Comparison Table

Signal Reseller / Slop Shop Real Provider
Undetected claim "100% forever" "Since date X, see status"
Build log Absent or fake Dated, includes rollbacks
Driver load method Refuses to say Named honestly
Status page Marketing widget Machine-readable endpoint
Support roles "Reseller Level 3" "Dev," "QA," "Ops"
Free trial Requires card Community-issued key
Downtime posts Never Within an hour
HWID spoofer "Included" Sold separately, scoped
Discord access Purchase-gated Public preview channels
Bulk pricing Hero of the page Available, not the pitch

How KyTech Handles This

KyTech was established in 2025 by two founders. The product line is deliberately narrow: kytech-apex, kytech-cs2, kytech-ow2, kytech-bo7, kytech-fh6, and kytech-roblox. All six ship on a shared kernel driver that we sign under our own attestation, so there is no third-party driver to rotate and no injected DLL sitting in the game process for a checksum walker to find. The loader talks to the driver over a private IOCTL, and the overlay compositor runs out-of-process with no window handle in the game's window tree.

The HWID spoofer is currently in Apex-only beta. It is not bundled with any cheat product because it is not finished for the other games, and we would rather ship one working spoofer than five that break your machine on reboot. When it exits beta for another title, we will say so on the changelog with a date.

We do not publish invented user counts. We do not publish an uptime percentage that we cannot compute. We do not run a five-star review widget with reviewer names we made up. When a build gets detected, the loader disables new activations for the affected product within minutes and the changelog gets a post-mortem inside the hour. Users on the detected build get credited the day they lost. That is the whole policy. This is the architecture behind KyTech Apex, the product with the most hours in production against the checklist above.

If you have read this far and want the product, it is at /purchase. If you want to keep researching, our writeup on how the two dominant anti-cheat drivers actually differ is the next thing worth reading: BattlEye vs Easy Anti-Cheat. Either way, evaluate whoever you buy from against the checklist above. The market is full of people betting that you will not.

Further reading

Signed by KyTech Research

We still play these games and we still push every build in production. If something in here is wrong, and eventually something will be, ping us in Discord and we will fix it.

Enough theory. get in.

The loader is one click away. Ring-0 kernel driver, polymorphic per download, memory-only injection. Six games across VAC, EAC, Ricochet, Byfron, and Warden.

Get in ›