The first wave was a warning. The second wave was a confirmation.
In early July, five OSRS bot providers went dark in four days. PowBot, TRiBot, Storm Client, Inubot, and OSMB all paused sales or shut down between 1 and 4 July. We wrote at the time that the pattern pointed to commercial or legal pressure rather than an anti-cheat update, and that nobody outside those teams actually knew the cause.
A month later, three more names have fallen: Sammich Scripts, RuneMate, and DreamBot. These aren't small operations. Sammich had been running for over a decade. RuneMate operated one of the largest bot marketplaces in the game. DreamBot was the entry point for a generation of new botters, with 125,000+ forum posts in its scripts section alone.
The pattern from the first wave has held. The announcements are about lawyers, not patches. Sales pages went down before clients did. And every provider is pointing to something external, not a detection breakthrough.
This is what a market correction driven by business-layer pressure looks like. Here's what happened to each of them, what they were, and what connects the three.
Sammich Scripts: ten years of AHK, ended by a letter
What it was. Sammich (originally "ZantomatoAHK") wasn't a bot client at all. It was an AutoHotkey macro business selling color-clicker scripts and PvP hotkeys as a one-time $40 purchase. It launched in 2016 on gaming forums and built a loyal following for its AHK-based approach: screen reading and input simulation at the OS level, no client modification, no injection, no reflection. Around 2019 it expanded into mobile emulator macros, which brought more visibility and, reportedly, more attention from Jagex's enforcement side.
Sammich survived the January 2026 Java client retirement unscathed. AHK color bots don't depend on the Java client, or any specific game client at all. They read pixels and click. The architecture that killed injection and reflection bots was irrelevant to Sammich's approach.
What happened. In early July 2026, the Sammich website went offline. The owner posted on Discord:
"I have recently received legal correspondence relating to the business. While I obtain independent legal advice and consider the appropriate response, I have decided to temporarily suspend operations."
A follow-up confirmed the closure is permanent:
"After a lot of thought, I've made the difficult decision to close the business indefinitely. For more than ten years, this community has been a huge part of my life. I think it's time for me to move in a different direction."
Why it matters. Sammich is the clearest confirmed instance of a direct legal trigger among all the providers that have gone down this summer. No ambiguity about "events outside our control" or "current landscape." The owner received legal correspondence and shut down. The fact that a color-clicker macro business, not even a bot client, got hit tells you something about the breadth of whatever pressure campaign is underway. This isn't targeted at a specific client architecture. It's targeted at the commercial layer.
RuneMate: the biggest bot store in OSRS, permanently closed
What it was. RuneMate was a Java-based bot client that had been running for over a decade, built on injection and reflection against the official game client. Its distinguishing feature was scale: a "Bot Store" marketplace with nearly 350 bots published by community developers, a freemium model offering 200 free botting hours per month, and per-hour billing on scripts that started at a few cents. It marketed features like "zero knowledge encryption" through its RuneMate Vault system and positioned itself as the most feature-rich option in the space.
RuneMate had already been under strain since the January Java client shutdown. Like every injection and reflection bot, it lost its primary attack surface when Jagex retired the Legacy Java Client, and the exact state of its post-Java migration was unclear to users through mid-2026.
What happened. A site-wide banner went up:
"RuneMate will permanently shut down on August 7, 2026 due to events outside our control. You can continue using RuneMate until this date after which it will no longer be available. All account upgrade subscriptions have been cancelled."
The community reaction was immediate and messy. On RuneMate's own forums, a thread titled "Is this the end?" captured the mood as prominent bot developers pulled their entire catalogs without explanation: users reported that developers known as "Cuppa," "Based," and "Daz" had removed everything overnight. One developer (applebots) tried to calm the community, saying the takedowns were precautionary rather than evidence that RuneMate itself was done. Users also surfaced an open WIPO domain dispute case as possible evidence of legal action, though this remains unverified.
Why it matters. RuneMate wasn't just a bot client: it was a platform with a developer ecosystem, a marketplace economy, and a user base that depended on third-party script authors. When it went down, it didn't just take one tool offline. It wiped out hundreds of scripts maintained by independent developers who had built small businesses on top of it. The platform risk here is the lesson: if your automation depends on a marketplace, you lose access to everything when the marketplace disappears.
DreamBot: the beginner-friendly giant, locked down
What it was. DreamBot launched in 2014 and became the most accessible OSRS bot client in the market: a drag-and-drop interface, a large script marketplace (the SDN), an active forum community, a free tier with ads, and a $9.99/month VIP subscription. It was where most beginners started: the forum had 125,000+ posts in its scripts section, a scale of community activity that none of its competitors matched.
Like RuneMate, DreamBot was built on Java injection, and like RuneMate, it lost its foundation when the Java client was retired in January 2026. As of mid-2026, DreamBot had not shipped a fully working post-Java client, but its website and community continued operating normally through early July.
What happened. An announcement from "The Dream Team" went out:
"We are pausing all new sales and existing subscription renewals effective immediately while we consult with legal counsel about the current landscape. Existing subscriptions will continue to work through the end of your current billing period and no new charges will be made. We will be locking down the site starting August 10th. You will not have access to your profile once the site is locked down. We will update you all when we are able to, but will be following the advice of our legal team."
The user reactions were a mix of grief and scrambling. People who had recently renewed VIP subscriptions posted refund requests. Others said their goodbyes. One user wrote: "So sad. DreamBot is the best botting site in the world. Very disappointed. Hopefully we can do something about it."
Why it matters. DreamBot's announcement is the most operationally detailed of the three. It describes a methodical wind-down: sales paused, renewals stopped, existing subscriptions honored, site locked on a specific date, legal counsel engaged. This reads less like a panic shutdown and more like a provider following legal advice to minimize liability exposure. The "current landscape" phrasing mirrors the language from the first wave, and the emphasis on legal counsel reinforces the pattern that this is a business problem, not a software problem.
Three different providers, the same pattern
These three providers could hardly be more different in their technical approach:
- Sammich was an AHK color-clicker business. No client modification, no injection, no Java dependency. Survived the January client retirement without a scratch. Got hit anyway.
- RuneMate was a Java injection/reflection platform with a massive developer marketplace. Already weakened by the Java client death. Got the kill shot in August.
- DreamBot was a Java injection client with a beginner-focused community and subscription model. Also weakened by January, also finished in August.
An AHK macro seller, a developer marketplace, and a consumer bot client. Three completely different architectures, three different business models, three different user bases. The only thing they share is that they were visible commercial operations selling OSRS automation.
That's the signal. The announcements talk about legal correspondence, legal counsel, and events outside their control. Nobody is talking about broken scripts, ban waves, or detection updates. When Jagex patches a detection vector, developers scramble to fix code and users report bans, and that pattern is absent here. What's present is the language of lawyers and payment processors.
The community's leading theory, documented in a widely-shared analysis on Medium, is coordinated legal and/or payment-processor pressure. Nobody outside these teams has confirmed this. But the shape of the evidence points strongly in that direction, and Sammich's explicit mention of "legal correspondence" is the closest thing to a confirmed data point.
This has happened before, and it looked the same
Jagex has a track record of going after the business side of automation once it reaches a certain scale of visibility.
The clearest precedent is RSBot and Powerbot. On 2 October 2020, Jagex announced that "following legal proceedings, RSBot, and the Powerbot website, will be shut down, and permanently closed by midnight on 3rd October 2020". The powerbot.org domain was signed over to Jagex. RSBot had been one of the longest-running bots in OSRS history. It didn't die because its reflection hooks were patched. It died because the entity behind it lost a legal fight.
Before that, Impulse Software (makers of the "iBot" macro) lost a US federal lawsuit in 2012 on five counts: copyright infringement, DMCA circumvention, trademark infringement, computer fraud and abuse, and tortious interference with contracts. The operators were ordered to hand over all websites, domains, source code, and customer details to Jagex.
The pattern across a decade and a half is consistent. Individual bot users get banned by the tens of thousands (Jagex reported banning over 6.9 million accounts in 2023 alone). But the commercial operations that sell automation get a different kind of attention: when a bot becomes a storefront with subscription tiers, a support forum, and a customer base, it tends to eventually become a legal target.
That doesn't mean every provider gets hit at once. Clearly they don't. But the market periodically loses its largest and most visible players, and July–August 2026 is the most dramatic example of that pattern in OSRS history. Eight providers and counting, across a single summer.
What it means for the space
The era of large, public bot clients is over. The January Java client retirement eliminated the technical foundation. The summer legal wave is eliminating the commercial operations that survived it. Between those two events, 2026 has reshaped the OSRS automation landscape more than any single year since Bot Nuking Day in 2011.
Architecture matters more than it used to. Providers built on injection or reflection into the Java client were already dead from January. Providers built on AHK macros (Sammich) had the technical durability to survive, but not the legal durability. The survivors are the approaches that don't require a separate, identifiable commercial client: RuneLite plugin-based systems that run inside the vanilla client, and self-written scripts that never touch a marketplace.
Platform risk is real. If your automation runs on a platform you don't control (a marketplace, a subscription client, a developer ecosystem), you lose everything when that platform goes down. RuneMate's shutdown didn't just take away a client, it wiped out hundreds of third-party scripts that independent developers had built and maintained. DreamBot's site lockdown means users won't even be able to access their profiles after August 10. The less dependent your setup is on a single provider's infrastructure, the more resilient it is.
Behavioral detection hasn't changed. Lost in the noise of the legal wave is the fact that Jagex's actual anti-cheat pipeline, Botwatch, is still what gets individual accounts banned. Client choice reduces one class of detection risk, but it doesn't address behavioral analysis at the server level. Mouse movement patterns, click timing distributions, session lengths, and action cadence are what Botwatch scores. The safest architecture in the world won't help you if the behavioral patterns look robotic.
Where Pluginscape fits
We're not immune to the pressures that hit the providers above. Nobody in this space honestly can claim to be. What we can control is the architecture we've chosen, and how transparent we are about it.
Pluginscape plugins sideload into vanilla RuneLite. There is no custom client, no fork, no modified JAR, no separate executable. You download RuneLite from runelite.net like every other player, and load our plugin into it. The client binary is identical to what millions of legitimate players run. If the Pluginscape website disappeared tomorrow, the plugin file on your machine would still work.
We don't sell antiban as an upgrade. Every plugin ships with randomized input profiles, session management, and behavioral humanization, because Botwatch doesn't check your subscription tier. Gating safety-adjacent features behind a paywall means treating your account as an upsell surface. We think that's the wrong approach.
We're a registered Austrian business with a published Impressum and a verifiable identity. In a space where most operators are anonymous Discord accounts, we think that matters, not because registration makes anyone invincible, but because accountability is part of trust.
We built this for durability, not scale. The goal isn't to be the biggest provider in the market. It's to be one that's still here next month.
If you've been displaced by any of the shutdowns this summer, see what we ship. Vanilla RuneLite, antiban included, plugin files you keep.
Further reading: Five OSRS bot providers went dark in four days → · RuneLite vs custom clients in 2026 → · How Jagex actually detects bots →