Use case · Game anti-cheat
Keep banned cheaters out, without invasive software on players' PCs.
Cheaters get back in by making new accounts: a fresh 'smurf' (a throwaway account a banned or high-skill player hides behind) that bots level up before it lands in ranked. Root Herald checks the security chip built into virtually every modern laptop and PC to prove a real, distinct machine sits behind each account — at signup, in ordinary userspace, with no kernel driver and nothing invasive running while people play.
Economics
Where smurfs stop paying.
Fresh Valorant smurfs sell for $2.50–$15, CS2 accounts for $10–$56. Making an account cost a real $30+ machine wipes out the fresh-account market and forces the rest (like reselling a ranked-up account for cash) into slow, capital-heavy operations you can spot.
Gaming smurf accounts
Valorant fresh $2.50–$15 · CS2 $10–$56 · ranked-up $30–$150
Per-identity yield
$2.50 – $150
Rational ceiling
< $30 fresh, < $100 ranked
Fresh smurfs collapse; high-rank RMT is partial.
What stops working
Smurfs, bots, and ban dodging.
Fresh smurfs
Spin up a throwaway account on a cloud server, bot it to a low rank, and sell it to someone who wants to stomp beginners. Rejected. A cloud server can't prove it's a real machine, so it never passes.
Coming back after a ban
A banned machine stays known. Its anonymous device ID doesn't change when the cheater swaps emails, names, or payment methods. Your ban sticks, even against the tricks that fool hardware-ID spoofers.
Bot-leveling farms
50 bots on 50 cloud servers add up to zero valid devices. 50 bots on 50 real Chromebooks give 50 device IDs, but all on one network, one location, one model. Easy to spot as a farm.
The case that remains
Selling high-rank accounts, honestly.
Selling a Diamond-rank account for $150 still clears the $30 machine cost. Here the defense changes shape: the anonymous device ID tells you when one machine is being passed between players (a paid rank boost), and shifts in the device's health tell you when the same machine suddenly plays like a different person.
Why not kernel anti-cheat
The Vanguard problem.
Kernel anti-cheat runs deep inside the player's operating system while they play. It buys detection power at a high cost: player backlash, crashes and instability, and a powerful new target for attackers. It also checks identity at game launch (after the account already exists), not at signup. Root Herald moves the check to signup, running as ordinary user software rather than deep inside the operating system. The security chip is the anchor; we never need that privileged level of access.
Real-world signals
The category is already moving.
FACEIT requires the same kind of security chip we check for ranked play. Epic Fortnite requires a verified secure startup. The Riot Vanguard backlash created demand for an architectural alternative: rooted in that chip, without burying software deep inside the operating system.
Put the check at signup, not in players' PCs.
Free up to 10K device checks a month, no card.