Cheaters are already trying to poison the new VACnet: why it probably won't work

The predictable happened, and it happened fast. Barely two days after Valve launched the VACnet labeling portal, cheaters are already trying to break it from the inside.
The alert came from content creator Ozzny, in a post that has passed 319,000 views. According to him, cheaters are labeling clips of obvious cheating as "not cheating", and are also inviting each other to increase the number of false verdicts. His assessment is as honest as it is skeptical: this was fairly expected, so it remains to be seen how effective it turns out to be.
Reports go beyond manual voting. Software that automatically submits innocent verdicts has been detected, allowing hundreds of fake reviews to pile up in a short time. The cheaters' logic is simple: if human reviews train the AI, poisoning those reviews should stop the AI from learning to catch them.
Cheaters are already trying to abuse CS2's new Overwatch system ‼️
— Ozzny (@Ozzny_CS2) August 13, 2026
> As shown in the clip, they are labeling cheating clips as "not cheating"
> It's also reported that cheaters are inviting other cheaters in order to increase the number of fake labels
It was pretty expected… pic.twitter.com/P0hYCNyQtR
What exactly they're attacking
It's worth recalling how the system works, because it's key to understanding why the attack will probably fail.
The portal, launched on August 11 alongside a 42MB patch, is an external website accessible by invitation only. Reviewers watch short clips with X-ray enabled and choose from four labels — Aim Assist, WallHack, AutoBHop, and farming bot — with additional options to mark a case as uncertain or a clip as faulty.
And here's the fundamental difference from CS:GO's Overwatch: verdicts don't ban anyone. No sanction follows directly from a vote. All those labels do is feed the training of future VACnet models.
That distinction already defuses half the attack. A cheater voting "innocent" on another cheater's clip isn't saving anyone from a ban, because that ban didn't exist. At most, they're trying to dirty a dataset.
Why the poisoning probably won't work
The other half of the attack doesn't look promising either, and there are concrete reasons to think so.
The design already accounts for disagreement. Based on what's been documented about how the portal works, multiple reviewers can evaluate different segments of the same clip, letting Valve measure the level of agreement between reviewers and weight consistent labels more heavily. In other words, the system doesn't treat all votes as equivalent: it compares them. A vote that systematically deviates from consensus is, by definition, detectable.
Automated patterns are trivial to spot. An account submitting dozens of responses per minute, or voting identically in one hundred percent of cases, separates itself from human behavior with laughable ease. And this requires no AI: just look at the distribution. Even a script trying to disguise itself by alternating answers on a fixed pattern generates a recognizable signature.
Invitations leave a trail. In a closed system where every access comes from someone, Valve can follow the entire chain backwards. If one account turns out to be acting in bad faith, it isn't just that account that can be isolated, but the whole invitation branch hanging off it. That's a structural property of the trust-network model, not something bolted on afterward.
And they don't need to be banned to be neutralized. Here's the interesting part: the most efficient response isn't to kick cheaters out of the portal, but to let them keep voting while their answers are silently discarded. Shut the door on them and they know they've been caught, so they try another route. Leave them clicking buttons for hours believing they're doing damage, and they keep themselves busy while the dataset stays clean.
That last point deserves labeling for what it is: analysis, not confirmed information. Valve hasn't explained what countermeasures it has implemented, and its recent track record — including false-positive waves in VAC Live — justifies some community skepticism. But publicly launching a tool like this without having anticipated the most obvious scenario would be hard-to-believe negligence.
The underlying debate: why the community and not employees?
This episode has revived a legitimate question circulating since launch: if Valve has resources to spare, why rely on volunteers instead of hiring a dedicated team?
The argument that we're working for free for one of the industry's most profitable companies carries weight. But there's a practical wrinkle: distinguishing a subtle wallhack from good map reading, or a soft aimbot from a player with genuinely good aim, requires thousands of hours of playing experience. It isn't a job you can teach in a week to hired staff with no background in the game. Recruiting veteran players would be possible, but it's predictable that Valve would rather take advantage of a community volunteering precisely because it's fed up with cheaters.
And there's a nuance often overlooked: it's reasonable to assume this tool was already used internally before opening up, and that the decision to extend it to the community reflects exactly this — the volume of data required exceeds what an internal team can produce. Training a model doesn't demand good reviewers; it demands a great many of them.
What to expect now
Time to manage expectations. Even if the system works perfectly and every sabotage attempt is neutralized, the effects won't show up tomorrow. Labeling data, training a model, validating it, and deploying it takes months. Anyone loading into a Premier match today will run into exactly the same cheaters as always.
What can happen, if the process works, is a behavioral shift: blatant cheaters being forced to tone it down to avoid triggering detection. And while that isn't the dream solution, it would be real progress over the current situation.
In the meantime, the episode leaves an almost reassuring read. That cheaters have poured this much effort, this quickly, into sabotaging this tool suggests they consider it a serious threat. Nobody invests in destroying something they believe is harmless.
Source: Ozzny (@Ozzny_CS2) on X, TechTimes, PC Guide, skin.club.
