HOW TO EVADE A RUST HWID BAN
Evading a HWID ban the correct way
● GUIDE · UPDATED 18.08.2026
Trying to evade a HWID ban these days can be a task in itself. I see so many people new to cheating getting caught out by them. This guide fully covers how you can evade one with ease.
CONTENTS
- Choose Your Spoofer (Required)
- Spoof Your PC (Required)
- Change Your IP (Required)
- Get a Fresh Steam Account (Required)
- Test It (Required)
- Common Account Mistakes
- Staying Unbanned
- Known Issues
STEP 1 · CHOOSE YOUR SPOOFER [REQUIRED]
A HWID ban bans your hardware, not just your account, so a fresh Steam account on its own won't get you back in. A spoofer is what changes the hardware IDs that EAC reads, so the game sees a brand new machine instead of your banned one. Everything else in this guide depends on getting this part right, and it's the part people get wrong most often.
If your spoofer fails, the account you're evading on gets game-banned. That happens when it doesn't cover every identifier EAC checks, or when its bypass has already been detected. Either way you get flagged, even if it looked like it spoofed fine. That is why the spoofer matters more than any other step here. I won't post a full provider list, as statuses change far too often to keep one accurate, but below is the spoofer I currently recommend, along with what makes a good one so you can judge any option yourself.
MY CURRENT RECOMMENDATION
[Only registered and activated users can see links. Click Here To Register...]
Permanent, one-time spoof. Currently working with Rust and tested across multiple setups. A solid option right now given the state of temp spoofers.
What to look for
- It spoofs everything. EAC reads a range of identifiers (disk and motherboard serials, MAC, TPM, SMBIOS and more). A spoofer that only changes some of them leaves the rest exposed, and that alone is enough to get you banned. Full coverage is the whole point.
- A working bypass. EAC actively hunts for spoofers, so changing your IDs is only half the job. The spoofer also has to get past EAC's anti-spoof checks. If the bypass is detected, you get banned no matter how clean the spoof looks.
- Actively maintained. EAC updates constantly. A spoofer that isn't being updated is one detection away from useless, so you want a dev who patches fast when EAC changes something.
- Honest about status. The good providers tell you when their product is down or risky. The ones that claim undetected through every ban wave and go quiet when people complain are the ones that get you banned.
- Track record. Boring, long-term uptime beats big promises every time. A spoofer that has held for months is worth more than a new one with a flashy thread.
Perm vs temp
- Permanent spoofers change your IDs at a lower level and hold through restarts. Applying one wipes and reformats your drives, usually alongside a full Windows reinstall, so it's more effort up front but the spoof stays until you revert it. How this is done is covered in Step 2.
- Temporary spoofers apply per boot and reset when you restart, so you are relying on it running correctly every single session. Good temp spoofers are rare right now, and anyone claiming a "100% working" temp is worth being very cautious of.
Statuses change constantly and nothing stays undetected forever. Do your own research and never assume undetected last week means undetected today.
STEP 2 · SPOOF YOUR PC [REQUIRED]
Strict EAC updates in 2026 leave deep traces across your system, so a full clean is part of the process either way. How you do it depends on whether you are on a perm or a temp. Follow the path that matches yours.
If you're using a PERMANENT spoofer
Every perm is different, so follow your provider's exact instructions. Do not try to apply a generic method. In general a perm will wipe and reformat your drives, and often reinstall Windows, and it spoofs you as part of that process. The exact method varies by provider, for example:
- Some give you their own custom software/firmware to format your drives with.
- Some have you reinstall Windows and reformat your drives (e.g. to RAID0), then run their loader once your PC boots.
If you're using a TEMPORARY spoofer
Here the clean comes first, then you spoof:
- Reinstall Windows with a clean install (do not use "Reset PC").
- Fully wipe and reformat all drives, including secondary drives.
- Once you're on a fresh Windows install, run the temp spoofer to spoof.
Note: as of writing there is no reliable temp spoofer known to work. See Known Issues.
STEP 3 · CHANGE YOUR IP [REQUIRED]
EAC tracks IP addresses, HWID. Rust/FP also tracks IP addresses and HWID. The goal is a genuinely fresh IP, ideally one that isn't already shared with other cheaters.
Option A: Dynamic routers only
- Unplug your router for 10-15 minutes.
- Check your IPv4 before and after.
- If it doesn't change, leave it for 12 hours. Only if it still hasn't changed after that, call your ISP and ask them to change your IPv4 (just tell them you're being DDoSed).
Option B: Residential VPN
- Star residential ($20 package): a community suggestion. Grants fully unique IPs, so you aren't sharing an address with other cheaters.
- Mysterium Dark: works well for myself.
Option C: Phone hotspot
- A community suggestion. Turning your mobile data off and on assigns a completely new IP address each time, and unlimited data plans are cheap.
- Downside: your PC must be able to connect to wireless, and your mobile data needs a solid connection.
These are suggestions only. Do your own research before committing to any option.
Optional: Disable IPv6 on your router.
Optional: Use a MAC address changer (TMAC).
STEP 4 · GET A FRESH STEAM ACCOUNT [REQUIRED]
- Avoid "fake hour" accounts. Don't buy 50-200h accounts that have never joined a real server. EAC flags these instantly.
- Use trusted marketplaces.
- Lolz Market: Real Hour Accounts, NFA & FA (look for 100+ hour accounts)
- G2G FA (trusted sellers only)
- APs Market NFA
- Check BattleMetrics hours. If you have the Steam link, check the account's BattleMetrics hours in the Atlas Rust Discord profile-checker channel (use the command ,player <steamid>).
STEP 5 · TEST IT [REQUIRED]
Before you touch an account that matters, confirm the spoof actually worked. Always test on a fresh FA (full access) account you don't mind losing.
- Run the spoofer, join an EAC server on the fresh FA account, and go AFK.
- HWID bans land within around 120 minutes of playtime on an EAC server. So if the spoof failed and you are still HWID banned, you will get banned inside that window.
- Make it past 120 minutes and the spoof has done its job. Keep in mind some spoofers can still trigger a temporary ban around 3 days later, so a clean first session isn't always the full picture.
- If you do get banned, don't blame the spoofer straight away. Most failures come from skipping a step in the provider's instructions, so double-check you followed them exactly.
COMMON ACCOUNT MISTAKES
- Fake hours. Accounts with botted hours mean nothing. Admins can see straight through botted hours, so make sure your account has REAL hours on BattleMetrics.
- Zero in-game achievements. Ideally, you want to purchase an account that has already completed multiple in-game achievements, as this shows the account has REAL playtime.
- Trying to make in-game purchases on day one. Avoid making any purchases with merchants for the first 14 days, as this can lead to the account being community banned. Always use gift cards to purchase in-game items, and make sure the gift card matches the account's origin currency.
STAYING UNBANNED
Rust utilises a server-side anti-cheat system called Cerberus to monitor player activity. When logging into an account from a new hardware ID, the system assigns it a low trust score, significantly increasing the risk of a ban during this initial period.
To mitigate this risk:
Avoid in-game F7 reporting. Never use the in-game F7 report on other players. When you F7 report someone, you are effectively flagging your own account to admins/FP at the same time. Do not F7 report anyone until your account has built a high trust score.Quote:
sirosix: Avoid PvP engagements for the first 10-20 hours of in-game playtime. This allows the system to gradually build trust in your account based on non-combat behaviour.
Note that Cerberus prioritises playtime accumulated on your current hardware ID over the account's total hours. Even older accounts may face low trust if recently switched to new hardware.
KNOWN ISSUES
Repeated temp-ban cycle. Once you get one permanent game-ban, you can keep getting instant 3-day temp bans after that.
- Wait until the temp ban expires (usually 48h to 3 days).
- After it expires, you can play again.
Important. A spoofer helps prevent fresh flags, but if you have already entered the repeated temporary-ban cycle after a permanent game-ban, it will not instantly remove that cycle.
There is also an ongoing issue where some people using temp spoofers get perm banned after 3 days of playing. As of 18.08.2026, I don't know of any 100% working temporary spoofers.
Play clean, play patient. Questions and suggestions welcome below.
Last verified: 18.08.2026
Last verified: 18.08.2026