Denuvo has been broken, company promises countermeasures against new DRM bypasses — zero-day game releases become norm as security concerns mount over hypervisor-based bypass
Denuvo has been broken, company promises countermeasures against new DRM bypasses — zero-day game releases become norm as security concerns mount over hypervisor-based bypass
(Image credit: Getty Images)
A good portion of the gaming- and piracy-adjacent internet has been on fire for the past few weeks, as a bypass for the (in)famous Denuvo copy-protection method has become popular. Not only did the new method enable the release of existing titles, but zero-day repacks are now the norm.
Contemporary versions of Denuvo and its multilayered DRM approaches have stood the test of time well and were widely regarded as the benchmark in the PC game DRM space. Naturally, this spells trouble for Denuvo and its parent company, Irdeto, as its primary source of revenue is now arguably useless.
Article continues below
Go deeper with TH Premium: AI and data centers
The performance remark refers to a past controversy in which Denuvo's checks caused CPU spikes that added strong stuttering and FPS drops in many titles and configurations. This fact was vehemently denied by Denuvo and subsequently mocked online, as cracked versions ran far better.
As usual for any DRM company or publisher, Irdeto also claimed that downloading games with the bypass is a security concern, but this time around, the company has a valid point. Using the hypervisor bypass, even in its latest incarnation, requires users to disable:
- Virtualization-Based Security (VBS): a layer that separates the Windows operating system from the its security enforcement features that run at a higher privilege level.
- Credential Guard: a sub-feature of VBS that keeps login credentials in an container isolated from the rest of the operating system.
- Driver Signature Enforcement: verification that any drivers installed in the system must have a digital signature issued by Microsoft to an identifiable company or developer, in order to prevent installing random drivers at the system level.
- Core Isolation / Memory Integrity (HVCI): similar to the above, but prevents any kernel-level unsigned code entirely, as well as modifications to existing signed code so programs can't attempt to mess with existing drivers.
- Installing a community-made hypervisor (HV) with Windows running on top of it. This HV fakes responses to the checks that Denuvo makes, and runs with higher permissions (ring level -1) than the operating system itself and has full, nearly untraceable access to hardware and software.
As you can imagine, disabling any one of those security features is not advisable, much less deactivating all of them at once. Once all those digital checkpoints are down, anything you run on your system has free rein to take it over completely, in ways that will be difficult to notice or fix, and will naturally evade detection by nearly any antivirus package.
Adding further concern, there's no telling that even without any malicious intent, the new HV won't have a security flaw of its own that, once exploited, runs at an access level beyond even that of the operating system itself.
To its credit, the community foresaw all of these issues, and game repacks include an easy-to-use script to disable and re-enable the security measures. The recommended procedure is to disable them, reboot, and play the game. Once your gameplay session is over, you would enable them again and restart. However, that's a chore for anyone, and one might guess your average user won't think twice about bothering with such trifles as "security."
Even within the piracy community, the team that designed the HV bypass and popular repackers like FitGirl have warned about the security implications of these releases, as trusted as they might be. Prospective gamers who are leery of bringing down their PCs' defenses will have to wait for an actual crack to come around.
Follow Tom's Hardware on Google News, or add us as a preferred source, to get our latest news, analysis, & reviews in your feeds.
Bruno Ferreira is a contributing writer for Tom's Hardware. He has decades of experience with PC hardware and assorted sundries, alongside a career as a developer. He's obsessed with detail and has a tendency to ramble on the topics he loves. When not doing that, he's usually playing games, or at live music shows and festivals.
Sign in to highlight and annotate this article

Conversation starters
Daily AI Digest
Get the top 5 AI stories delivered to your inbox every morning.
More about
releasecompany
Best Python Code Quality Tools Compared
Why Python needs multiple code quality tools Python's flexibility is both its greatest strength and its biggest code quality challenge. Dynamic typing, duck typing, implicit conversions, mutable default arguments, and runtime metaprogramming create entire categories of bugs that simply do not exist in statically typed languages like Rust or Go. A single Python linter cannot catch everything because the problems span multiple dimensions - style consistency, logical errors, type mismatches, security vulnerabilities, and structural complexity all require different analytical approaches. This is why the Python ecosystem has evolved a layered toolchain rather than a single monolithic solution. Formatters handle visual consistency. Linters catch rule violations and common mistakes. Type checkers

I Tested Every Gemma 4 Model Locally on My MacBook - What Actually Works
Audio ASR in 3 languages, image understanding, full-stack app generation, coding, and agentic behavior -- all running on a MacBook M4 Pro with 24GB RAM. Interactive version with playable audio, live charts, and the working React app: gemma4-benchmark.pages.dev Google just released Gemma 4 -- their new family of open-source multimodal models. Four sizes, Apache-2.0 licensed, supports text + image + audio. I spent a day testing every variant. Real audio files. Real images. Code that has to compile and run. Here is my honest report. The Gemma 4 Family E2B -- Dense 2.3B, Text/Image/Audio, 4 GB at 4-bit. Phones and edge. E4B -- Dense 4.5B, Text/Image/Audio, 5.5 GB at 4-bit. Laptops. 26B-A4B -- MoE 4B active/26B total, Text/Image, 16-18 GB at 4-bit. 31B -- Dense 31B, Text/Image, 17-20 GB at 4-bi

I Put VS Code, Claude, and a Terminal Inside a File Manager I built using React and Rust — Here's What Happened
Remember when file managers were just... folders and files? I got tired of switching between Finder, VS Code, Terminal, and ChatGPT every 30 seconds. So I built a file manager that has all of them built in. It's called Xplorer , it's free, and I just shipped the first alpha. The "Why" — File Managers Haven't Changed Since 2005 Think about it. Your code editor got AI autocomplete, your browser got extensions, your terminal got split panes. But your file manager? Still the same grid things... I wanted one app where I could: Browse files Preview code with syntax highlighting Ask AI "what's in this PDF?" Run git commands Open a terminal Install extensions So I built it. What It Looks Like VS Code Vibes, But For Your Files Multi-tab browsing, split panes, file tree sidebar, AI chat — all in one
Knowledge Map
Connected Articles — Knowledge Graph
This article is connected to other articles through shared AI topics and tags.
More in Releases

Best Python Code Quality Tools Compared
Why Python needs multiple code quality tools Python's flexibility is both its greatest strength and its biggest code quality challenge. Dynamic typing, duck typing, implicit conversions, mutable default arguments, and runtime metaprogramming create entire categories of bugs that simply do not exist in statically typed languages like Rust or Go. A single Python linter cannot catch everything because the problems span multiple dimensions - style consistency, logical errors, type mismatches, security vulnerabilities, and structural complexity all require different analytical approaches. This is why the Python ecosystem has evolved a layered toolchain rather than a single monolithic solution. Formatters handle visual consistency. Linters catch rule violations and common mistakes. Type checkers

Software-update - FairScan 1.18.0
Fairscan is een eenvoudige en elegante documentscanner voor Android. Het is opensource, toont geen advertenties, heeft geen internet nodig om zijn werk te kunnen doen en kan meerdere pagina s in een document opslaan. Er zijn drie stappen: scannen met automatische documentherkenning en perspectiefcorrectie, preview, en opslaan. Downloaden kan via de Google Play of F-Droid. Sinds versie 1.16.0 zijn de volgende veranderingen en verbeteringen aangebracht: FairScan 1.18.0

Software-update - FairScan 1.18.0
Fairscan is een eenvoudige en elegante documentscanner voor Android. Het is opensource, toont geen advertenties, heeft geen internet nodig om zijn werk te kunnen doen en kan meerdere pagina s in een document opslaan. Er zijn drie stappen: scannen met automatische documentherkenning en perspectiefcorrectie, preview, en opslaan. Downloaden kan via de Google Play of F-Droid. Sinds versie 1.16.0 zijn de volgende veranderingen en verbeteringen aangebracht: FairScan 1.18.0



Discussion
Sign in to join the discussion
No comments yet — be the first to share your thoughts!