PUBG anti-cheat PoC goes public after researcher says Krafton dismissed risk
ころころゴロリ says Zakynthos flaws could expose protected processes and physical memory; a linked GitHub repository contains C proof-of-concept code.
By Ryan Merket · Published
Primary source: X
Why it matters
Anti-cheat software with deep system access can itself become a security boundary. The public PoC raises that risk for PUBG players, while the reported KRAFTON response leaves the severity dispute resting on claims from the researcher and the company.

On September 26th, security researcher ころころゴロリ (@k0mkc) published a proof of concept targeting Zakynthos, KRAFTON's anti-cheat software for PUBG: BATTLEGROUNDS. The researcher says the flaws could allow access to protected processes and physical memory, and says KRAFTON had told them it found no significant security impact.
The disclosure links to a GitHub repository containing C proof-of-concept code. The code includes a routine labeled for reading physical memory. That demonstrates what the posted code is designed to do; it does not independently establish that the reported exploit works across systems or that attackers have used it. The researcher describes the issues as serious and calls the result a rootkit.
Zakynthos is KRAFTON's proprietary anti-cheat system. In a 2021 anti-cheat developer letter, PUBG said it had implemented Zakynthos in January of that year and planned to add kernel drivers as part of its anti-cheat work. KRAFTON's 2024 midyear review later described new Zakynthos features and other security updates. Those company statements explain the software's role; they do not confirm or address the vulnerabilities in this disclosure.