Developer knowledge network · moderated exchange

UnreliableCode コミュニティ

開発者リサーチ、リバース エンジニアリング、コーディング コミュニティ

Guide

Spoofing Humanoid.WalkSpeed via __index Metamethod to Bypass Anti-Speed Scripts [v2.4 Technical Discussion]

luau_hacker
Luau Expert
MEMBER
担当者: 159
参加日: Aug 2020
投稿: 17
ありがとう: 26
1 か月前 · Jul 6, 2026 7:24 PM
#1

Why client-side anti-cheats flag speed modification:

Games use local scripts that periodically check if Humanoid.WalkSpeed > 16 then Ban() end.

The Metamethod Bypass:

LUA
local mt = getrawmetatable(game)
local oldIndex = mt.__index
setreadonly(mt, false)

mt.__index = newcclosure(function(self, key)
    if not checkcaller() and key == "WalkSpeed" and self:IsA("Humanoid") then
        return 16 -- Always return standard 16 WalkSpeed to game security scripts
    end
    return oldIndex(self, key)
end)
setreadonly(mt, true)

You run at 100 WalkSpeed while game scripts read exactly 16!

hook_doctor
Hooking Specialist
MEMBER
担当者: 181
参加日: Jul 2019
投稿: 21
ありがとう: 50
1 か月前 · Jul 6, 2026 10:15 PM
#2

checkcaller() filtering ensures that your own exploit UI reads real values while game scripts receive spoofed values. Textbook metamethod hook.

ptr_arithmetic
C++ Wizard
MEMBER
担当者: 162
参加日: May 2018
投稿: 73
ありがとう: 42
1 か月前 · Jul 7, 2026 5:37 AM
#3

Completely neutralizes client-side WalkSpeed auditors.