← Back to Blog

Troubleshooting | Jun 1, 2026 | 8 min read

Are Overlay Apps Safe With Anti-Cheat? Keep It Minimal

By Mohit Sehrawat

Are Overlay Apps Safe With Anti-Cheat? Keep It Minimal — Edge Drop Guide

A clipboard overlay is not a cheat. It does not read game memory, it does not inject into the game's process, and it does not draw on top of the game's render target. But to the anti-cheat running underneath a competitive game, the distinction is not always obvious. Anti-cheat systems flag patterns, not intentions, and several of the patterns they watch for — topmost windows, low-level keyboard hooks, input injection — overlap with the patterns a clipboard overlay uses. This explainer covers what anti-cheat systems actually look for, why a click-through edge shelf is fundamentally different from an injected overlay, and how to choose a clipboard tool that minimises the risk of a false positive.

For neighbouring topics, see should a clipboard app hide in games, streaming while using a clipboard shelf, clipboard tools on multi-monitor Windows setups, and ultrawide screens and modal clipboard popups.

What anti-cheat actually looks for

Modern competitive anti-cheat (Vanguard, BattlEye, Easy Anti-Cheat, FACEIT AC) operates at kernel level on Windows. Running in ring 0 gives the anti-cheat visibility into every process on the machine, every loaded driver, and every handle opened against a protected game. What it does with that visibility is pattern-match against a known-cheat signature database plus a set of behavioural heuristics. The behavioural heuristics are the ones that catch clipboard tools.

The behaviours anti-cheat treats as suspicious fall into three broad categories.

DLL injection and process injection

A cheat that wants to read game memory or hook game functions has to get its code into the game's address space. The standard techniques — CreateRemoteThread, SetWindowsHookEx with WH_GETMESSAGE or WH_CBT, manual mapping of a DLL via NtMapViewOfSection — are well known to anti-cheat vendors and are flagged on sight. A clipboard tool that does any of these is at high risk of being flagged, regardless of what the injected code actually does.

No mainstream clipboard manager does this. The risk is theoretical for clipboard tools that stay in their own process. The risk is real for clipboard tools that advertise "paste into the game's chat field" via simulated input — that is not injection, but it is the next category.

Low-level input hooks

A clipboard tool that needs to detect a hotkey has two options. The clean option is RegisterHotKey, which asks Windows to deliver a WM_HOTKEY message to the tool's window when the combination is pressed. Windows itself handles the keyboard state and dispatch, and the tool never sees the keystrokes that are not its hotkey. This is safe.

The invasive option is SetWindowsHookEx with WH_KEYBOARD_LL (or WH_MOUSE_LL). A low-level hook receives every keyboard event on the machine, before the focused window sees it. This is the same mechanism a keylogger uses, and anti-cheat systems treat it accordingly. Some clipboard tools use WH_KEYBOARD_LL because it lets them intercept hotkeys that RegisterHotKey cannot (for example, hotkeys involving only modifier keys, or hotkeys that need to fire before the focused app processes the input). The cost is anti-cheat risk.

Overlay drawing on the game's swap chain

The riskiest overlay technique is hooking the game's DirectX or Vulkan present call and drawing into the swap chain before the frame is presented to the screen. This is how aimbot overlays, ESP overlays, and wallhack overlays render their HUD on top of the game. Anti-cheat systems look for processes that have handles to the game's swap chain, that hook IDXGISwapChain::Present, or that inject a DirectX wrapper DLL.

Legitimate overlay tools that use this technique — Discord's in-game overlay, NVIDIA GeForce Experience overlay, Steam's overlay — are signed, whitelisted, and have negotiated arrangements with anti-cheat vendors. A clipboard tool that hooks the swap chain without that whitelist will be flagged.

What a click-through edge shelf actually is

A hover-activated clipboard shelf like Edge-Drop is none of the above. It is a standard Win32 top-level window, created with CreateWindowEx, positioned at the edge of the screen, with the WS_EX_TOPMOST extended style so it stays above other windows and WS_EX_NOACTIVATE so it never takes focus. The window is transparent (alpha-blended) and click-through when collapsed, meaning mouse events pass through it to whatever window is underneath. The shelf does not draw on the game's swap chain; it draws on its own window, which the desktop compositor (DWM) composites onto the screen along with the game.

This is the same mechanism used by the Windows taskbar, by the Win+V clipboard panel, and by every notification flyout. It is uninteresting to anti-cheat because it cannot read game memory, cannot intercept game input, and cannot draw inside the game's frame. The shelf sees the game the same way the taskbar sees the game: as a window on the desktop.

The catch is that an always-on-top transparent window is still visible during gameplay if it is not suppressed. A shelf that hovers its trigger strip over a fullscreen game is not a cheat, but it is a focus thief and a visual distraction. The right behaviour is to suppress hover activation when the foreground window is in exclusive fullscreen, which Edge-Drop does via SHQueryUserNotificationState. See should a clipboard app hide in games for the suppression logic.

Why "less is safer"

The phrase "less is safer" is shorthand for a specific trade-off. The more techniques a clipboard tool uses to integrate with the OS — low-level hooks, input injection, swap-chain hooks, global message filtering — the more overlap it has with the techniques anti-cheat systems flag. A tool that uses only RegisterHotKey, standard clipboard polling (AddClipboardFormatListener), and a top-level window has near-zero overlap with cheat signatures. A tool that adds WH_KEYBOARD_LL for fancier hotkey handling has non-zero overlap. A tool that adds DirectX present hooks for "in-game overlay" has substantial overlap.

The same logic applies to feature surface area. A clipboard tool that does not script, does not auto-paste, does not auto-type, and does not inject has a smaller behavioural footprint than one that does. The smaller tool is less likely to trip a heuristic, and when it does trip one, the vendor has a simpler story to tell the anti-cheat vendor: "we use RegisterHotKey, we use AddClipboardFormatListener, we draw a top-level window, here is our source code."

For Edge-Drop specifically, the relevant facts are: it uses RegisterHotKey for its hotkey, it uses AddClipboardFormatListener for clipboard polling, it uses a top-level transparent window for its shelf, and it suppresses hover activation in exclusive fullscreen. It does not inject, does not use low-level hooks, does not hook DirectX, and does not auto-type. Its source is public under Apache-2.0. None of this guarantees a particular anti-cheat will not flag it — anti-cheat heuristics are not public — but it puts the tool in the lowest reasonable risk category.

Per-game risk notes

Anti-cheat behaviour varies by vendor and by game. A few specific notes that are worth knowing.

  • VALORANT (Vanguard). Vanguard is the most aggressive of the mainstream anti-cheats. It loads at boot, runs at kernel level, and is known to flag a wide range of overlay tools. A clipboard tool that uses RegisterHotKey and stays in its own process should be safe, but Riot has not published a whitelist. Players who want zero risk should suppress the clipboard tool entirely while Vanguard is running.
  • Counter-Strike 2 (VAC). VAC is less aggressive than Vanguard but bans in waves, which makes false positives hard to attribute. Standard overlay tools are not flagged; injection-based tools are.
  • Apex Legends (Easy Anti-Cheat). EAC is tolerant of legitimate overlay tools but does flag low-level hooks. Discord and Steam overlays work; unsigned overlay tools that hook input may not.
  • Fortnite (BattlEye). Similar to EAC. Topmost windows are fine; injection is not.
  • FACEIT AC. FACEIT's anti-cheat is stricter than the game's built-in anti-cheat and may flag tools that the game's own anti-cheat tolerates. Competitive players on FACEIT should suppress the clipboard tool during matches.

The common thread: a clipboard tool that uses standard APIs and suppresses itself in fullscreen is at low risk on every major anti-cheat. A clipboard tool that uses injection, low-level hooks, or swap-chain hooks is at non-zero risk on every major anti-cheat. For the gaming-setup angle, see gaming fullscreen and clipboard hotkeys.

What "suppression" buys you

Suppressing a clipboard tool in fullscreen does three things, two of which are anti-cheat related.

  • Removes the visible overlay. Even a no-activate, click-through topmost window is visible to the player. Removing it removes the visual distraction.
  • Removes the handle to the game window. Some clipboard tools enumerate foreground windows to decide whether to suppress. A suppressed tool stops enumerating, which means it stops opening handles to the game window. This is a small reduction in anti-cheat surface area.
  • Signals intent. A tool that suppresses itself in exclusive fullscreen is behaving the way a non-cheat tool should behave. If a player is ever asked to justify their tool list, "it hides itself in fullscreen" is a cleaner answer than "it draws an overlay on top of the game."

The third point is the most important one. Anti-cheat is not a court of law; the standard is "does this look like a cheat to a heuristic," not "is this a cheat." A tool that visibly suppresses itself in fullscreen looks less like a cheat than one that does not.

A short checklist

For a clipboard tool on a gaming machine, the safe-set is:

  • Uses RegisterHotKey for hotkeys, not SetWindowsHookEx with WH_KEYBOARD_LL.
  • Uses AddClipboardFormatListener for clipboard polling, not clipboard viewer chain injection.
  • Draws its UI as a top-level DWM-composited window, not via DirectX present hooks.
  • Suppresses itself when SHQueryUserNotificationState returns D3D fullscreen.
  • Does not auto-type, auto-paste, or simulate input into the foreground window.
  • Has public source or a published vendor statement about anti-cheat compatibility.

Win+V satisfies all of these (it is part of the OS). Ditto satisfies the API requirements but does not suppress by default. Edge-Drop satisfies all of them and suppresses by default. CopyQ satisfies the API requirements; its scripting layer can violate them if a user writes a script that simulates input, so the user is responsible for what their scripts do.

For the streaming variant of this conversation — where the leak risk is not to the game's anti-cheat but to the audience — see streaming while using a clipboard shelf.

Related reading

Sources

Mohit Sehrawat
Written by Mohit Sehrawat · Author & Software Tester

Mohit Sehrawat is a B.Tech Computer Science Engineering student with a focus on software testing, bug detection, and product quality. He is interested in exploring applications, identifying issues, and improving the overall user experience through thorough testing.

GitHub · LinkedIn

Copy. Stack. Drop.

Transform your clipboard into an interactive edge shelf. Stack, pin, and drag assets into any app with zero friction.

Download for Windows Get from Microsoft Store

How to Install Guide · First 10 Minutes Guide · Drag & Drop Guide · Edge-Drop vs Win+V · Support

Free · Lightweight · Privacy First
Find us on CodeHype