HOW TO EVADE A RUST HWID BAN
Evading a HWID ban the correct way
● GUIDE · UPDATED 18.08.2026
Trying to evade a HWID ban these days can be a task in itself. I see so many people new to cheating getting caught out by them. This guide fully covers how you can evade one with ease.
CONTENTS
Choose Your Spoofer (Required)
Spoof Your PC (Required)
Change Your IP (Required)
Get a Fresh Steam Account (Required)
Test It (Required)
Common Account Mistakes
Staying Unbanned
Known Issues
STEP 1 · CHOOSE YOUR SPOOFER[REQUIRED]
A HWID ban bans your hardware, not just your account, so a fresh Steam account on its own won't get you back in. A spoofer is what changes the hardware IDs that EAC reads, so the game sees a brand new machine instead of your banned one. Everything else in this guide depends on getting this part right, and it's the part people get wrong most often.
If your spoofer fails, the account you're evading on gets game-banned. That happens when it doesn't cover every identifier EAC checks, or when its bypass has already been detected. Either way you get flagged, even if it looked like it spoofed fine. That is why the spoofer matters more than any other step here. I won't post a full provider list, as statuses change far too often to keep one accurate, but below is the spoofer I currently recommend, along with what makes a good one so you can judge any option yourself.
Permanent, one-time spoof. Currently working with Rust and tested across multiple setups. A solid option right now given the state of temp spoofers.
What to look for
It spoofs everything. EAC reads a range of identifiers (disk and motherboard serials, MAC, TPM, SMBIOS and more). A spoofer that only changes some of them leaves the rest exposed, and that alone is enough to get you banned. Full coverage is the whole point.
A working bypass. EAC actively hunts for spoofers, so changing your IDs is only half the job. The spoofer also has to get past EAC's anti-spoof checks. If the bypass is detected, you get banned no matter how clean the spoof looks.
Actively maintained. EAC updates constantly. A spoofer that isn't being updated is one detection away from useless, so you want a dev who patches fast when EAC changes something.
Honest about status. The good providers tell you when their product is down or risky. The ones that claim undetected through every ban wave and go quiet when people complain are the ones that get you banned.
Track record. Boring, long-term uptime beats big promises every time. A spoofer that has held for months is worth more than a new one with a flashy thread.
Perm vs temp
Permanent spoofers change your IDs at a lower level and hold through restarts. Applying one wipes and reformats your drives, usually alongside a full Windows reinstall, so it's more effort up front but the spoof stays until you revert it. How this is done is covered in Step 2.
Temporary spoofers apply per boot and reset when you restart, so you are relying on it running correctly every single session. Good temp spoofers are rare right now, and anyone claiming a "100% working" temp is worth being very cautious of.
Statuses change constantly and nothing stays undetected forever. Do your own research and never assume undetected last week means undetected today.
STEP 2 · SPOOF YOUR PC[REQUIRED]
Strict EAC updates in 2026 leave deep traces across your system, so a full clean is part of the process either way. How you do it depends on whether you are on a perm or a temp. Follow the path that matches yours.
If you're using a PERMANENT spoofer
Every perm is different, so follow your provider's exact instructions. Do not try to apply a generic method. In general a perm will wipe and reformat your drives, and often reinstall Windows, and it spoofs you as part of that process. The exact method varies by provider, for example:
Some give you their own custom software/firmware to format your drives with.
Some have you reinstall Windows and reformat your drives (e.g. to RAID0), then run their loader once your PC boots.
Whatever the method, the reformat/reinstall and the spoof happen together. Your provider's guide is the source of truth here, not this thread.
If you're using a TEMPORARY spoofer
Here the clean comes first, then you spoof:
Reinstall Windows with a clean install (do not use "Reset PC").
Fully wipe and reformat all drives, including secondary drives.
Once you're on a fresh Windows install, run the temp spoofer to spoof.
Note: as of writing there is no reliable temp spoofer known to work. See Known Issues.
STEP 3 · CHANGE YOUR IP[REQUIRED]
EAC tracks IP addresses, HWID. Rust/FP also tracks IP addresses and HWID. The goal is a genuinely fresh IP, ideally one that isn't already shared with other cheaters.
Option A: Dynamic routers only
Unplug your router for 10-15 minutes.
Check your IPv4 before and after.
If it doesn't change, leave it for 12 hours. Only if it still hasn't changed after that, call your ISP and ask them to change your IPv4 (just tell them you're being DDoSed).
Option B: Residential VPN
Star residential ($20 package): a community suggestion. Grants fully unique IPs, so you aren't sharing an address with other cheaters.
Mysterium Dark: works well for myself.
Option C: Phone hotspot
A community suggestion. Turning your mobile data off and on assigns a completely new IP address each time, and unlimited data plans are cheap.
Downside: your PC must be able to connect to wireless, and your mobile data needs a solid connection.
These are suggestions only. Do your own research before committing to any option.
Optional: Disable IPv6 on your router.
Optional: Use a MAC address changer (TMAC).
STEP 4 · GET A FRESH STEAM ACCOUNT[REQUIRED]
Avoid "fake hour" accounts. Don't buy 50-200h accounts that have never joined a real server. EAC flags these instantly.
Use trusted marketplaces.
Lolz Market: Real Hour Accounts, NFA & FA (look for 100+ hour accounts)
G2G FA (trusted sellers only)
APs Market NFA
Check BattleMetrics hours. If you have the Steam link, check the account's BattleMetrics hours in the Atlas Rust Discord profile-checker channel (use the command ,player <steamid>).
STEP 5 · TEST IT[REQUIRED]
Before you touch an account that matters, confirm the spoof actually worked. Always test on a fresh FA (full access) account you don't mind losing.
Run the spoofer, join an EAC server on the fresh FA account, and go AFK.
HWID bans land within around 120 minutes of playtime on an EAC server. So if the spoof failed and you are still HWID banned, you will get banned inside that window.
Make it past 120 minutes and the spoof has done its job. Keep in mind some spoofers can still trigger a temporary ban around 3 days later, so a clean first session isn't always the full picture.
If you do get banned, don't blame the spoofer straight away. Most failures come from skipping a step in the provider's instructions, so double-check you followed them exactly.
COMMON ACCOUNT MISTAKES
Fake hours. Accounts with botted hours mean nothing. Admins can see straight through botted hours, so make sure your account has REAL hours on BattleMetrics.
Zero in-game achievements. Ideally, you want to purchase an account that has already completed multiple in-game achievements, as this shows the account has REAL playtime.
Trying to make in-game purchases on day one. Avoid making any purchases with merchants for the first 14 days, as this can lead to the account being community banned. Always use gift cards to purchase in-game items, and make sure the gift card matches the account's origin currency.
STAYING UNBANNED
Rust utilises a server-side anti-cheat system called Cerberus to monitor player activity. When logging into an account from a new hardware ID, the system assigns it a low trust score, significantly increasing the risk of a ban during this initial period.
To mitigate this risk:
Quote:
sirosix: Avoid PvP engagements for the first 10-20 hours of in-game playtime. This allows the system to gradually build trust in your account based on non-combat behaviour.
Note that Cerberus prioritises playtime accumulated on your current hardware ID over the account's total hours. Even older accounts may face low trust if recently switched to new hardware.
Avoid in-game F7 reporting. Never use the in-game F7 report on other players. When you F7 report someone, you are effectively flagging your own account to admins/FP at the same time. Do not F7 report anyone until your account has built a high trust score.
KNOWN ISSUES
Repeated temp-ban cycle. Once you get one permanent game-ban, you can keep getting instant 3-day temp bans after that.
Wait until the temp ban expires (usually 48h to 3 days).
After it expires, you can play again.
Important. A spoofer helps prevent fresh flags, but if you have already entered the repeated temporary-ban cycle after a permanent game-ban, it will not instantly remove that cycle.
There is also an ongoing issue where some people using temp spoofers get perm banned after 3 days of playing. As of 18.08.2026, I don't know of any 100% working temporary spoofers.
Play clean, play patient. Questions and suggestions welcome below.
Last verified: 18.08.2026
This was actually the list I was planning to make, thanks mate Could you check your DMs on Discord? I want to share some information from a few of my own customers
Good informative post. I can personally vouch for these steps. Make sure you're following the instructions of the spoofer provider you're using very carefully as well, e.g. the Windows reinstallation steps, to anyone following this.
Good informative post. I can personally vouch for these steps. Make sure you're following the instructions of the spoofer provider you're using very carefully as well, e.g. the Windows reinstallation steps, to anyone following this.
Can we talk on Discord? Some of my users said they used your spoofer but couldn’t get a refund and were given some questionable reasons and no help. Not accusing you of anything, I just want to get some info about what happened.
This was actually the list I was planning to make, thanks mate Could you check your DMs on Discord? I want to share some information from a few of my own customers
@ hope he didnt tell you to add his friends spoofer byteon, right?
also would recommend star $20 residential package as it grants you fully unique ips, i would definetly not be saying for people to use mysterium dark is very misleading for evading bans as ur using a big pool of ips already destroyed by every cheater and there nans
Quote:
Originally Posted by getdownonit
also would recommend star $20 residential package as it grants you fully unique ips, i would definetly not be saying for people to use mysterium dark is very misleading for evading bans as ur using a big pool of ips already destroyed by every cheater and there nans
also would highly reccomend phone hotspot as every time you turn it off and on will grant you a completely new ip address and can get unlimited data very cheap
also would recommend star $20 residential package as it grants you fully unique ips, i would definetly not be saying for people to use mysterium dark is very misleading for evading bans as ur using a big pool of ips already destroyed by every cheater and there nans
also would highly reccomend phone hotspot as every time you turn it off and on will grant you a completely new ip address and can get unlimited data very cheap
I have heard great things about star residential VPN. I might add this as a suggestion on the steps!
Also Phone hotspot is a great idea. Ill definitely add this as a suggestion. Only downside is your PC must be able to connect to wireless connections, and your mobile data needs a solid connection!
oh well i remember you promoting byteon just to not work on rust in the end?
It worked for Rust at the time, and I said so. When it stopped working, I said that too. If that's “promoting,” then I suppose correcting yourself when the facts change counts as promotion now
I got hit as well with verse spoofing and wasn't cheating and got banned!
Already reported issue in their discord and i haven't got an answer what could be the solution for me.
I got hit as well with verse spoofing and wasn't cheating and got banned!
Already reported issue in their discord and i haven't got an answer what could be the solution for me.
NOTE: Ill edit after i receive a news
Thank you for the post! I've updated the status on the list already, let me know the outcome of your experience!
Can we talk on Discord? Some of my users said they used your spoofer but couldn’t get a refund and were given some questionable reasons and no help. Not accusing you of anything, I just want to get some info about what happened.
Refunds are reviewed and handled on a case-by-case basis, and are issued whenever a request is determined to be valid and appropriate under the circumstances. No legitimate refund request is intentionally ignored or dismissed.
Please keep in mind that our support team can receive around 400 tickets per day. During periods of higher volume, response times may therefore be longer than usual. We understand that waiting several hours without a response can be frustrating and may create the impression that a request is being overlooked, but a delay in response should not be interpreted as a refusal to assist or review the matter, of course.
Questions or concerns are always welcome, and you are free to DM me directly. I will respond as soon as I can give the matter the attention it deserves. I cannot provide a specific ETA, as I am currently managing several projects and responsibilities at the moment, but I will not intentionally ignore a genuine concern.
Refunds are reviewed and handled on a case-by-case basis, and are issued whenever a request is determined to be valid and appropriate under the circumstances. No legitimate refund request is intentionally ignored or dismissed.
Please keep in mind that our support team can receive around 400 tickets per day. During periods of higher volume, response times may therefore be longer than usual. We understand that waiting several hours without a response can be frustrating and may create the impression that a request is being overlooked, but a delay in response should not be interpreted as a refusal to assist or review the matter, of course.
Questions or concerns are always welcome, and you are free to DM me directly. I will respond as soon as I can give the matter the attention it deserves. I cannot provide a specific ETA, as I am currently managing several projects and responsibilities at the moment, but I will not intentionally ignore a genuine concern.
have you guys figured out what’s causing the detection or are you still investigating?