Compatibility
Minecraft: Java Edition
Platforms
Tags
Creators
Details
Text version
VoidAC is a free, open-source, prediction-based anticheat for Minecraft servers, fork of Grim
- Free and open source (GPLv3). No license key, no authentication server, no paid tier. The code you read on GitHub is the code that runs.
- Safe out of the box. Automatic bans are off by default. Fresh installs only alert, log and (if you configure it) send Discord webhooks, so you can watch it on your own players before letting it punish anyone.
- Tune it on your own server. An opt-in Threshold Optimizer studies flags from players you trust and recommends punishment thresholds. It never changes your config by itself.
- Everything is documented and switchable. Every network request the plugin can make is listed in the Transparency section below.
What "prediction-based" means
Most anticheats compare a player's movement against fixed limits (speed X, distance Y). Those limits are a compromise: loose enough not to hit legit players, which leaves room for cheats.
VoidAC's movement check (Simulation) works differently. For every movement packet it recomputes, on the server, the set of positions the vanilla client could have reached from the previous state (input, friction, collisions, knockback, liquids, elytra, vehicles and more), and compares that with what the player actually did. If the client reports movement the game rules cannot produce, it flags. This is the architecture GrimAC pioneered, and VoidAC inherits it.
It is a strong foundation, not magic: no anticheat, prediction-based or not, can promise zero false positives on every server, client and network. Lag, proxies, modded clients and version translation all create edge cases, and VoidAC treats them as bugs to fix (see Support).
Detection coverage
More than 130 named checks ship in the source. Some of them are heuristics or protocol sanity checks rather than proofs, and the table says which is which.
| Area | What is covered | How it works |
|---|---|---|
| Movement | Speed, fly, water and lava movement (Jesus-style), climbing, elytra, knockback and explosion velocity, Phase, NoSlow, NoFall / ground spoof, sprint rules (7 checks), vehicles (7 checks) | Prediction engine plus rule checks |
| Timers | Timer, tick timer, negative timer, timer limit, vehicle timer | Packet timing balance with a configurable lag allowance |
| Combat | Reach, hitbox expansion, hits through walls, entity pierce, self-interact, multi-interact, AutoClicker (3 checks), AutoTotem | Server-side ray casts and interaction rules, plus click statistics for AutoClicker |
| Aim | Duplicate look packets and clients that wrap their rotation modulo 360 | Rotation sanity checks. These catch specific flaws in some cheat clients, not every aim assist |
| Building and breaking | Fabricated, far, out-of-position, wrong-rotation and air/liquid placement, multi-place, fast break, wrong break, no-swing break and more (19 checks) | Validated against the world state the client should see. This covers scaffold-style behavior |
| Inventory and actions | Inventory click validation (5 checks), multi-actions (7 checks) | Server-side inventory model |
| Packets and exploits | BadPackets (26 checks), PacketOrder (16 checks), Post, transaction order, Crash (9 checks), Chat (4 checks), Elytra exploits (9 checks), Vehicle exploits (6 checks) | Protocol validation |
| Automation | Baritone-style pathing | Heuristic |
| Cheat clients | Known cheat client brands and plugin channels (AntiSpoofA) |
Signature-based. Only catches clients that announce themselves. Kicks by default, switchable in config.yml (anti-spoof.auto-kick) |
Detection quality varies by check, client version, network conditions and configuration. If you want to know exactly what a check does, the source is public.
Bedrock: players connected through Geyser or Floodgate are not checked at all (all checks are skipped for them), because Java movement rules do not apply to Bedrock clients. This only works if Geyser or Floodgate is installed on the server VoidAC runs on.
Built for real servers
Latency and state compensation
VoidAC tracks what each client has actually acknowledged (via ping/transaction packets) and applies server-side changes to its own model only when the client would have seen them. This covers world changes (blocks, entities), inventory, cooldowns, fireworks and knockback. It exists to reduce false flags from lag and desync.
Per-player world model
Each player has their own compensated view of the world used for collision and movement, so predictions use the world the client believes it is in, not the one the server has moved on to.
Multi-version and Via support
Version-specific behavior (collision boxes, movement quirks, blocks that older clients cannot see) is handled in the engine, including OptiFine's FastMath. Servers using ViaVersion, ViaBackwards and ViaRewind are supported, and optional attenuation settings exist for cross-version players (viaversion-attenuation), disabled by default.
Threading and platforms
Packet handling and prediction run on packet threads rather than the main server thread, and VoidAC declares Folia support. Real cost depends on your hardware, player count and plugins, so measure it: /void perf shows the prediction engine's own timing.
Moderation and punishments
Automatic punishments
Configurable per check group in punishments.yml: a violation count, an interval and a command list. Built-in actions are [alert], [log], [webhook] and [proxy]. You can add any console command (kick, tempban, your ban plugin of choice).
Separately, auto-punish in config.yml can ban or kick when one check reaches its own threshold. It is disabled by default. The comments in the shipped config explain why checks like Simulation need a higher threshold than combat checks and warn against lowering them.
Manual punishments and ban waves
/void punish <player> <duration> [reason]: built-in ban with a templated kick screen and a ban ID./void banwave add|list|remove|execute|clear: queue suspects and ban them together later. The ban-wave feature is enabled in the config, but players only enter the queue if you add them or turn onqueue-on-auto-punish./void unban: removes bans issued through VoidAC.- Any ban plugin works: set
prefer-custom-ban: trueand a command template such aslitebans:tempban {player} {duration} {reason}(the shipped template uses LiteBans syntax, so change it if you use something else).
Investigating flags
| Command | Purpose |
|---|---|
/void alerts |
Toggle alerts for yourself |
/void verbose |
Also show near misses, not only flags that fired |
/void profile <player> |
Client version, brand and related info |
/void spectate <player> and /void stopspectating |
Spectate a player |
/void history <player> |
Stored violation history by session, filterable by check name |
/void debug <player> |
Toggle the prediction trace for a player |
/void log and /void dump |
Export a trace or a diagnostic dump (see Transparency for where it goes) |
/void perf |
Prediction engine timing |
/void brands |
Show client brands |
/void reload |
Reload configuration |
Violation history
Flags are stored so you can review them after the player logs out. The default backend is a local SQLite file. MySQL, PostgreSQL, MongoDB and Redis backends are supported through per-backend config files, and retention is configurable (defaults: 365 days for violations, 90 days for sessions). The whole system can be disabled (database.enabled: false).
Alerts everywhere
Console, in-game staff, Discord webhooks, and across a proxy network with the optional VoidBridge plugin for BungeeCord and Velocity (signed, replay-protected messages, shared bans and alerts, grouping by server).
Threshold Optimizer (opt-in)
Different servers have different lag, plugins and playstyles, so a good punishment threshold on one may be wrong on another. The optimizer helps you pick thresholds from your own data.
- Set
threshold-optimizer.enabled: trueinconfig.ymland/void reload. - Give trusted players the permission
void.optimizer.legit. - Run
/void optimizer startand let the server run with normal play (the plugin recommends at least 24 hours). - Run
/void optimizer stop, then/void optimizer save. - Review
threshold-optimizer-report.ymland apply what makes sense to your config yourself.
How it works: for each check it records the highest violation level reached by players with the legit permission. If a check has at least 5 legit flags, it recommends ceil(highest legit VL x 1.5). Checks with less data are marked insufficient-data.
What it is not: it does not edit your config, it does not run in the background by itself, and a recommendation is only as good as the sample. Five flags from one player on one evening is thin data, so collect more before changing production thresholds. It uses a small amount of extra CPU while running, so stop it when you are done. Collected data is held in memory until saved or discarded.
Anti-Xray and StorageESP (optional, off by default)
- Anti-Xray (Paper only): VoidAC can write Paper's built-in anti-xray settings for you (
AntiXray.configure-paper: true). It needs a full restart to apply. This uses Paper's engine, it is not a separate xray detector. - StorageESP decoys: sends fake storage blocks to clients to mislead ESP mods, and can flag players who interact with a decoy. Players with
void.storageespbypass it.
An experimental anti-esp feature also exists in the config. It is clearly marked as not production ready and is disabled. Do not enable it on a live server.
Configuration and languages
Files are generated on first start under plugins/Void/ (config.yml, punishments.yml, messages.yml, discord.yml, database files). Configs update themselves between versions.
Thirteen languages are bundled for the main config and messages: English, German, Spanish, French, Italian, Japanese, Dutch, Polish, Portuguese, Romanian, Russian, Turkish and Chinese. Punishment, Discord and database templates are translated into 11 of them (Polish and Romanian currently cover only the main config and messages).
Requirements
- Java 17 or newer.
- Paper, Spigot, Purpur or Folia. Minecraft 1.8 through 26.1 is the supported range. Servers on 26.2 and 26.3 are recognized, but full anticheat behavior on those versions has not been verified yet, so test before relying on it.
- PacketEvents is bundled, you do not need to install it.
- Optional: ViaVersion, ViaBackwards, ViaRewind, Geyser, Floodgate, PlaceholderAPI, ProtocolLib.
- Optional: VoidBridge on BungeeCord or Velocity for network-wide alerts and bans.
Install: drop the jar in plugins/, start the server, read config.yml, and run with alerts on for a few days before enabling any automatic punishment.
Transparency
You are giving a plugin control over who can play on your server, so here is exactly what else it does. All of this is in the public source.
Network requests
- Update check: once an hour, VoidAC asks the public Modrinth API for the latest version and tells staff with
void.alerts. Nothing about your server is sent. - bStats: standard anonymous plugin statistics. Disable it globally in
plugins/bStats/config.yml. - Discord webhooks: only if you configure a webhook URL. Avatars in embeds are loaded from
crafthead.netby the Discord client. - Pastebin: only if you put your own API key in
pastebin-api-key. Without a key,/void logand/void dumpsave files to your server and upload nothing. - VoidBridge: talks only to your own servers, authenticated with a shared secret you control.
Things you might not expect
- The
/ac,/anticheatand/blackowlzzcommands print a short "this server uses VoidAC" message with the Modrinth and Discord links. It is allowed for everyone by default. Remove thevoid.advertpermission from players (or set it to false) to hide it. - When the plugin author's own Minecraft account joins a server that runs VoidAC (online-mode servers only), staff with alerts see a join notice, and that account receives a private status message (version, platform, player count, TPS, language). The author's accounts can also get an answer to the info command above even if you block it. None of this grants any permission, changes any setting or sends data off your server.
anti-spoof.auto-kickis on by default and kicks players whose client announces a known cheat client. Set it tofalseif you would rather only be alerted.- Forge clients on 1.18.2 to 1.19.3 are disconnected by default (
disconnect-blacklisted-forge-versions) because those Forge versions shipped with extended player reach.
Permissions
void.exempt skips all checks for a player. Staff permissions such as void.alerts default to OP, while void.advert is open to everyone.
Support and false positives
VoidAC is maintained by one developer, and support is community-based. If a legitimate player gets flagged, please report it: include the check name, the player's client version, ping and what they were doing, and attach a /void dump if you can. False-positive reports are how the engine gets better.
Open source and credits
VoidAC is released under the GNU GPL v3 and is based on GrimAC, which uses the same license. You can read the code, build it yourself, report issues and send fixes. The repository includes unit tests for parts of the punishment, config, localization, packet-version and anti-ESP logic.
- GrimAC by MWHunter (DefineOutside) and contributors: prediction engine and original anticheat foundation.
- LightningGrim by Axionize: upstream fixes incorporated where applicable.
- PacketEvents: packet layer.
Copyright 2026 blackowlzz, MWHunter (DefineOutside) and contributors.




