Denuvo’s anti-tamper protections have been significantly weakened by two parallel developments: a widely adopted hypervisor-based bypass that has enabled near zero-day piracy of protected PC games, and a reported full crack of Resident Evil: Requiem by voices38 that allegedly removes Denuvo entirely. The bypass has already been used across multiple newer titles, accelerating repacks on piracy sites, while the full crack is described as a more complete defeat that strips the DRM rather than merely spoofing its checks. Tom’s Hardware reported that the cracked build of Resident Evil: Requiem ran faster and used less VRAM and system memory than the bypassed version, with claims of roughly 5% higher FPS.
The hypervisor method has also raised serious security concerns because users have reportedly had to disable key Windows protections, including VBS, Credential Guard, Driver Signature Enforcement, and Core Isolation/Memory Integrity, before installing a community-made hypervisor operating at a privilege level above the OS. That setup could create opportunities for stealthy system compromise or exploitation of flaws in the hypervisor itself, prompting warnings even within piracy circles. Denuvo parent Irdeto said it is developing countermeasures and asserted that its response will not further degrade performance or require deeper operating-system access, but the emergence of more plug-and-play bypasses suggests the company is facing a broader erosion of its DRM model.

Get the actors, campaigns, and ATT&CK mapping behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Tom's Hardware reported that Denuvo and 2K Games introduced mandatory online verification every 14 days in titles including NBA 2K25, NBA 2K26, and Marvel's Midnight Suns. The reported change appears intended to blunt the hypervisor-based bypass because it relies on live server communication that the bypass cannot emulate.
An upgraded version of the hypervisor-based Denuvo bypass was reported that may no longer require users to disable major Windows security protections, making the method easier to use. This marked a further escalation beyond the earlier cumbersome bypass approach.
A cracker identified as voices38 reportedly produced a full crack for Resident Evil: Requiem that disables or strips out Denuvo rather than merely bypassing its checks. The cracked build was reported to run faster and use less VRAM and system memory than the bypassed version.
In response to the spread of the hypervisor-based bypass, Irdeto, Denuvo's parent company, said it was working on countermeasures. The company stated the changes would not harm performance or require going deeper into the operating system.
A community-made hypervisor-based method for bypassing Denuvo DRM became broadly adopted in gaming and piracy circles, enabling protected games to be released and making zero-day repacks increasingly common. The technique reportedly required users to disable multiple Windows security protections before installation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
4 references tracked. Mallory keeps watching after this page renders.
techdirt.com
Open sourcetomshardware.com
Open sourcetomshardware.com
Open sourcetomshardware.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.