NanoVM

Documentation

Reference guide for the NanoVM Obfuscator — setup, Luau support, compatibility, architecture, and troubleshooting.

Getting Started

  1. 1.Sign in at /account using Google or Discord. An account is required to use the obfuscator.
  2. 2.Open the Obfuscator at /obfuscate. On desktop both panes are visible; on mobile use the Input / Output / Configure tabs.
  3. 3.Paste or drop your script into the Input pane. Accepted formats: .lua .luau .txt.
  4. 4.Select your tier and flags in the Configure panel, then click Obfuscate.
  5. 5.Copy or download the obfuscated output from the Output pane.

Input & Limits

File types.lua, .luau, .txt
Max script size2 MB
Free tier runs3 per 24 hours
Pro tier runsCredit-based (no daily limit)

Drag and drop a file onto the Input pane to load it directly. The filename is preserved in the download.

Free vs Pro

Free — Light

  • ✓ Multi-scheme JIT string encryption
  • ✓ Per-build name randomization (~80 symbols)
  • ✓ Roblox environment probe binding
  • ✗ No bytecode VM layer
  • ✗ No anti-tamper checksum

Pro — NanoVM

  • ✓ Everything in Free
  • ✓ Full bytecode VM (custom instruction set)
  • ✓ Shattered deserialiser
  • ✓ Fake opcode injection
  • ✓ Opcode masking via environment probes
  • ✓ Rolling runtime integrity checksum

See the full comparison and feature explanations at /pro. Pro access is available via the 833s Discord .

Supported Luau

NanoVM supports standard Luau 5.3 syntax as used in Roblox executor scripts, including:

  • ✓All standard Luau operators and control flow
  • ✓Roblox globals (game, workspace, script, etc.)
  • ✓String manipulation (string library)
  • ✓Coroutines and task library
  • ✓Metatables and __index chains
  • ✓Multiple returns and varargs
  • ✓Closures and upvalues
  • ✓Most loadstring patterns
  • ✓pcall / xpcall error handling
  • ✓Numeric and generic for loops
Note: Highly dynamic loadstring patterns — scripts that generate and execute Luau source code at runtime from runtime-computed strings — may require adjustment after obfuscation. Static and semi-static loadstring usage is generally supported.

Executor Compatibility

NanoVM output is tested with high UNC/sUNC Roblox executors. No custom environment functions are required.

RealRonixPotassiumWave+ other high UNC/sUNC executors

Compatibility tested September 2026. Executor environments change; if you encounter an issue with a specific executor, report it in the Discord server.

Requirement: A high UNC/sUNC executor is required. Executors with low UNC compliance or without standard Luau globals will not run NanoVM output correctly.

Limitations

  • —2 MB script limit. Scripts larger than 2 MB are rejected before processing.
  • —Dynamic loadstring. Scripts that use loadstring on runtime-computed strings may produce unexpected behaviour. Simplify or restructure these patterns before obfuscating.
  • —Roblox execution only. All builds include Roblox environment probe binding. Output will not run correctly outside Roblox. This is intentional.
  • —Free tier: 3 runs per 24 hours. The window resets 24 hours after your first run in a period.
  • —No deobfuscation. NanoVM output cannot be reversed. Keep your original source code.

VM Architecture

All builds share a common base. Pro adds the full bytecode VM layer on top.

All Builds

  • String encryption: each string constant is encrypted at build time using one of four randomized schemes and decrypted on first access at runtime.
  • Name randomization: ~80 internal symbols are replaced with per-build random identifiers. No two builds share the same symbol names.
  • Environment binding: five Roblox environment probes are baked into the decryption key. Output built for Roblox cannot be decrypted outside Roblox.

Pro Only

  • Bytecode VM: source is compiled to a custom instruction set executed by a dedicated VM. Static analysis tools never see real Luau bytecode.
  • Keyed binary wrapper: the serialized VM payload is wrapped in a keyed binary outer layer. Tooling sees noise.
  • Shattered deserialiser: the VM loading logic is split across 6 randomly named cooperating functions per build. Signature detection fails across builds.
  • Fake opcode injection: 40–60 dead dispatch entries are injected into the opcode table each build. Disassemblers and pattern matchers hit dead code.
  • Opcode masking: real opcodes are masked against Roblox environment probe values. The unmasked dispatch table is never present in memory until execution begins.
  • Runtime integrity checksum: a rolling checksum is baked into the VM at compile time. A single flipped bit in the bytecode corrupts execution silently.

Full feature breakdown and comparison: /pro

Troubleshooting

My script produces errors after obfuscation.

The most common cause is a complex dynamic loadstring pattern. Check whether your script generates Luau source code at runtime and passes it to loadstring. Simplify or restructure those sections, then retry.

I received a syntax error from the obfuscator.

The error message includes a line and column number pointing to the location in your source. Fix the issue in your original script, then submit again. The obfuscator does not modify source — if it worked before, the error is in the submitted text.

Obfuscation is taking a long time.

Pro builds are heavier by design. The first run after a period of inactivity may take longer while the backend service initialises. Subsequent runs are faster. If the job has not completed after 90 seconds, it will time out — retry once.

Credits were deducted but the job failed.

Credits are automatically refunded when a job fails due to a service error on our side. If a refund did not appear, contact contact@833s.net with the approximate time of the job.

The output does not run on my executor.

Verify your executor has high UNC/sUNC compliance. NanoVM output requires a Roblox execution context and a compliant executor environment. Low-compliance executors will not run NanoVM output correctly.

FAQ

Will obfuscation break my script?

NanoVM is designed to preserve script behavior across supported Luau constructs. If your script works before obfuscation it will work after. The exception is highly dynamic loadstring usage — see Limitations.

Does the free tier expire?

No. Free-tier access is permanently available at 3 runs per 24-hour window. The window resets 24 hours after the first run in a period, not at midnight.

Can I deobfuscate my own output?

No. The VM format is not designed to be reversible. Always keep your original source code.

Is my source code safe?

Free-tier source code is automatically deleted after 3 days. Pro-tier source code is retained for the lifetime of your account to support job history, and is deleted when your account is closed. The compiled output is not persistently stored. Full details in the Privacy Policy.

How are Pro credits calculated?

Credit cost is based on script size. Credits are deducted only on a successful obfuscation job. Jobs that fail due to a service error are automatically refunded. For the current credit rate, ask in the Discord server.

Where do I get Pro?

Pro access is available via the 833s Discord server. Credits and subscriptions are managed through Discord.

NanoVM Documentation | 833s.net