'I had my fun' says hacker who used Call of Duty anti-cheat exploit to ban 'thousands upon thousands' of innocent players

A promotional screenshot from Call of Duty: Modern Warfare III. In a multiplayer mode, a skeletal player character with purple glowing eyes is flanked by two other armed operatives.
(Image credit: Activision Blizzard)

Last month, Activision posted that they'd "identified and disabled a workaround" within their automated anti-cheat tool, Ricochet. The language of the post is purposefully vague about what actually happened, but the studio asserts that only a "small number" of legitimate Call of Duty: Warzone and Modern Warfare III players were affected, and that those accounts have since been reinstated.

However, it wasn't long before hackers shared their side of the story—to say nothing of all the angry responses under Activision's post from players still locked out of their accounts. A hacker known as Zeebler was the first to publicly share details of the exploit, explaining how it allowed them to remotely permaban players by typing as few as two words into the lobby chat. TechCrunch has since caught up with the hacker who originally found the exploit. 

Going by the handle Vizor, the hacker in conversation alleges the extent of the issue was much farther reaching than Activision is willing to admit, saying they were able to remotely ban “thousands upon thousands” of players. Perhaps most damningly, the hacker also tells TechCrunch, "I could have done this for years and as long as I target random players and no one famous it would have gone without notice."

Aimbots have been the bane of many a shooter fan's existence—and indeed even threw Apex Legends' anti-cheat software for a loop—so you can understand why Ricochet would have cheats like this in its sights. What is a lot less straightforward to understand is how simply typing the words 'aim bot' and sending them to another player could get them banned.

Vizor explained that Ricochet uses a list of hardcoded strings of text to detect cheaters and that they then exploited this to ban innocent players by simply sending one of these strings via an in-game whisper. To test the exploit the day they found it, they sent an in-game message containing one of these strings to themselves and promptly got banned.

Vizor elaborates, "I realized that Ricochet anti-cheat was likely scanning players’ devices for strings to determine who was a cheater or not. This is fairly normal to do but scanning this much memory space with just an ASCII string and banning off of that is extremely prone to false positives."

To put it in simplified terms, Ricochet was picking through player's setups, looking for anything from a list of keywords—or signatures—and then banning when it found them, regardless of the context in which those keywords appeared. That's not the wildest part.

What's wilder is that Vizor wrote a script that then automated the exploit process, allowing them to "join a game, post a message, leave the game, join a new game, repeat repeat repeat," and keep dishing out permabans even while they were away on holiday. As Activision continued to update the anti-cheat software with new string signatures to look out for, Vizor kept up to date too, and continued, in their own words, "trolling" both the developer and Call of Duty players alike. This continued right up until fellow hacker Zeebler made the exploit much more widely known.

So now that Activision has finally worked out this workaround, how does Vizor feel with their "trolling" days at an end? Their takeaway may surprise you: "It was nice to see it get fixed and see unbans,” they admit before adding, "I had my fun.”

Best gaming PCBest gaming laptop


Best gaming PC: The top pre-built machines.
Best gaming laptop: Great devices for mobile gaming.

Jess Kinghorn
Hardware Writer

Jess has been writing about games for over ten years, spending the last seven working on print publications PLAY and Official PlayStation Magazine. When she’s not writing about all things hardware here, she’s getting cosy with a horror classic, ranting about a cult hit to a captive audience, or tinkering with some tabletop nonsense.

Read more
Ghost, from Call of Duty: Modern Warfare 2 (2022), looks bleakly at a fellow passenger in a transport.
For COD’s sake: One player’s 763-day legal quest to make Activision unban their account ends in total success: ‘Worth the effort’
Black Ops 6
Call of Duty devs admit Ricochet anticheat 'did not hit the mark for integration' at the start of Season 1, and want to do better
black ops 6 season 1
Call of Duty: Black Ops 6 has now banned 136,000 accounts as part of the ongoing struggle to ensure fair play but still says that IP banning isn't an option
Marvel Rivals units - Three superheroes
Marvel Rivals admits that it accidentally banned some players for trying to run the game in a different operating system, which isn't cheating
talk to the joneses fortnite
Epic sues Fortnite cheater, donates his winnings to charity, forces him to publicly apologise, bans him for life, and all but sends him to his room without dinner
marvel rivals characters screenshots
'We will take measures to vanquish this nefarious behavior': Marvel Rivals will ban console players who use a mouse and keyboard
Latest in Hardware
Nvidia RTX 5080 Founders Edition graphics card from different angles
Nvidia says it really has sorted RTX 50-series black screen issues this time around as yet another driver fix finds its way to release
A collection of upturned CDs, DVDs and Blu-Rays on a carpeted floor
Warner Bros says it will replace certain DVDs damaged by 'disc rot', but you might not get the same movie you sent in for replacement
Skytech Shadow gaming PC on a blue background
Screw waiting for GPU restocks, with an AMD RX 9070 gaming PC going for as cheap as this I'd hop on the pre-built bandwagon
A screenshot from a YouTube video showing a sticker being pulled from the front of a fake 9800X3D CPU
This Amazon-bought fake AMD Ryzen 7 9800X3D is actually a 14-year-old Bulldozer chip with a cheap sticker on it
OneXPlayer 2 pro on a table
I never thought a handheld PC bloated with Windows could replace my Steam Deck, but after gaming on an old OneXPlayer 2 Pro I can see now I judged it too harshly
Asus ROG Swift PG27UCDM gaming monitor
Asus ROG Swift PG27UCDM review
Latest in News
Pedro Pascal as Joel in a coat in winter looking unhappy
'Don't you know what he did?': The truth comes out in The Last of Us Season 2 trailer
Aloy
'Creepy,' 'ghastly,' 'rancid': Viewers react to leaked video of Sony's AI-powered Aloy
Split Fiction trailer still - Zoe and Mio standing side by side, wearing glowing neon sci-fi jammies
Split Fiction sells 1 million copies over 2 days
A soldier looks out over the Verdansk map, as a single tear rolls down his cheek.
The original Verdansk map is returning to Call of Duty: Warzone, to celebrate which we get a soldier crying to Nat King Cole
More than 5 years after launch, Control gets a surprise patch that lets everyone play the Hideo Kojima mission
Swen Vincke
Swen Vincke stamps seal of approval on Stardew Valley mod that yoinks the Baldur's Gate 3 cast out of D&D and into a cosy pastoral life