[PSA] User "PokeAcer", who stole a developer's exploit and reported it to Nintendo for money has done the same with NbaYoh's Flipnote 3D exploit as we

TLDR: PokeAcer (who also stole ihaveamac's exploit) stole and reported a new exploit to Nintendo: the yet unreleased Flip Note 3D exploit by MrNbaYoh for userland homebrew on 11.5. The money has already been paid out so it's likely it'll be patched very soon - I highly advice you download it now.

In one of the Flipnote-related Discord chats recently, someone posted a ZIP containing the ugopwn exploit (an exploit for the DSi version of Flip Note), the SHA256 hash matching the one pinned in a certain private Discord server. It became obvious when looking around where it came from - ryanrocks's twitter.

Ryan was asked to take it down, and immediately complied (he also claimed that twitter analytics showed no one saw the tweet, but there's no way to verify that). Around the same time, a GBAtemp thread was posted with the files. At this point, several DCMA requests were filed on the sites to get the files taken down.

The Discord group the files came from only had 8 members, plus it was given to a few people outside of the discord. A total of around 10 people had access to the exploit files, all fairly trustworthy; there was initially no obvious leaker. Everyone was asked to think hard about who might have leaked it and messages were sent out.

Later hints were given that whoever leaked it had posted in the GBAtemp thread. After a bit of thinking we decided to ask PokeAcer (aka Billy Humphreys - this is public information available on his website and Twitter) about it. He eventually admitted to impersonating ryanrocks on Nintendo's HackerOne bug bounty to report this exploit. Eventually, he confessed to stealing the session token of one of the members of the Discord.

He's also admitted to having reported the Flipnote Studio 3D vulnerability to the HackerOne program and recently received a significant amount of money from the report. He's admitted to buying a new Macbook and other accessories with this money.

Additionally, this isn't the first time he's done this. He also reported ihaveamac's browser exploit to Nintendo for a significant amount of money as well, as seen here. Then he had the gall to write an apology post begging for forgiveness saying he'd "apology [for it] until the day [he] dies," then went around and did it again.

Additionally, he says not to judge one of the projects he works on, Project Kaeru (a custom server for Flipnote Studio 3D) as the rest of team doesn't condone his actions, but later on he admitted that he was reading and stealing information from people's notes on the Project Kaeru server.

To sum it up, PokeAcer has stolen three exploits that were not his. Two he reported to Nintendo for profit and one he leaked. He is not to be trusted, and did all this after profusely apologizing for the first time. Please avoid associating and sharing anything sensitive with him unless you want it leaked and/or reported to Nintendo for money.

Until now, this entire post until now has been serious and fact oriented, so allow me to insert some of my opinion here. PokeAcer or Billy, you seem to have some legitimate mental issues. I really hope you get those sorted out, both because you seem like a talented guy, and no one will (or should) trust you right now; but also because I'm seriously concerned about your well being.

Finally screenshots, because no good callout post is complete without proof: http://imgur.com/a/FNUMx
(I'm not the user in any of these screenshots)

EDIT: Archived his twitter, just in case: http://archive.is/JdRwP

DOUBLE EDIT: ihaveamac disclosed the amount that PokeAcer got when he sold his exploit:
[12:21 AM] ihaveahax: the amount was $1,382
Combined with the 2048 dollars from this one, that's a total of 3430 dollars
  • Like
Reactions: 25 people
Status
Not open for further replies.

Comments

This mob mentality though. Hm. Also, how did he get access to the user's discord token? Hm.
 
@jupiteer - the vomiting? That's me, different user name. I just felt more inspired to go long winded here. Is he really 14 though? I can see pointing out the age as an indication of his poor, immature character, but I just think pure scum is scum regardless of age.
 
  • Like
Reactions: 1 person
I would have forgiven him but he had to go out and blow his money on a macbook. A macbook. Literally the most overpriced underpowered computer out there. He could have gotten something great. Nope. He gets a fucking mac.
 
  • Like
Reactions: 16 people
This is where I slam my head into a table. Why mate..
I almost feel like you bought a Mac just for the irony of it. AT LEAST BUY SOME CHIPS WITH IT (Inside joke heh)
 
  • Like
Reactions: 2 people
He stole someone's discord user token to report two exploits to Nintendo. I don't care how what his age is, that's unforgivable.
 
  • Like
Reactions: 10 people
How did he get access to the token?

Stupid is as stupid does. Still some undefined here.
 
  • Like
Reactions: 1 person
He released a trojan horse BetterDiscord plugin which sent the token of anyone who installed it to him. This included people in the private chat
 
  • Like
Reactions: 13 people
Two wrongs don't make a right, being a goody two-shoes after stealing personally identifiable information is a douche move no matter who it is or what their reasons are. This can only end badly for the perp.
 
  • Like
Reactions: 2 people
People insulting him are not being any much better than he is, please stop doing that. It was done and we are aware of it. Not saying he should be left without consequences of stealing but don't start becoming worst than what you was prior to this problem before it begins.

Don't treat this like a salem witch trial and try burning him at the steak. Just don't associate with him if you "strongly dislike him." Why does it have to turn into some hate crime?

@astronautlevel thank you for bringing this to our attention and I will consider being more careful with things I share online. I don't know the person personally nor talk as much as you have, but sorry he has hurt you and some others in the "scene" I hope things are resolved. :(
 
Status
Not open for further replies.

Blog entry information

Author
astronautlevel
Views
1,929
Comments
241
Last update
Rating
1.00 star(s) 1 ratings

More entries in Personal Blogs

  • 4: Reddit
    Finally, number 4! Never thought this day would come, did you? Uhh...
  • books
    1. I am cool as hell, have one million dollars 2. I am banned from...
  • Syncthing is fun!
    Having been kinda active in an Android forum I quickly got sick about...
  • Feeling at home here
    Not much to say this time. I'm depressed. Like almost always. Trying to...
  • I'll start, rate mine 1-10
    It's a very mixed bag, some rock, some rap, some video game music, a...

More entries from astronautlevel

Share this entry

General chit-chat
Help Users
  • BakerMan @ BakerMan:
    saves a lot of time fr
  • Sicklyboy @ Sicklyboy:
    It's 11:30 PM here, I just took the trash out and my god is it awful outside
  • Sicklyboy @ Sicklyboy:
    This heatwave can eat my ass
    +3
  • MysticStarlight @ MysticStarlight:
    omg same, it's VERY hot here, too
  • BakerMan @ BakerMan:
    fuck this heatwave, i don't usually sleep with a fan, but i believe the fan is getting put on the bed rather than beside it
  • BakerMan @ BakerMan:
    IT'S 12:30 IN THE FUCKING MORNING AND IT'S STILL 78°, WHAT THE FUCK?
    +1
  • NinStar @ NinStar:
    78º seems abnormal for any part of the day
  • BigOnYa @ BigOnYa:
    Yea it was 96 F for the high, 78 F for the low today, in Ohio, bout same for bakerman in Michigan
  • BigOnYa @ BigOnYa:
    F- fahrenheit C-Celsius. We in USA use F as our temp ratings
  • Sicklyboy @ Sicklyboy:
    F = Freedom units
    +2
  • HiradeGirl @ HiradeGirl:
    So... C = Cum units?
    +1
  • K3Nv2 @ K3Nv2:
    Clip units
  • SylverReZ @ SylverReZ:
    @HiradeGirl, That's how they get bigger loans at the bank.
    +1
  • HiradeGirl @ HiradeGirl:
    Welp.
  • K3Nv2 @ K3Nv2:
    Wasn't me
  • K3Nv2 @ K3Nv2:
    Got around to playing A way out is pretty fun coop game to kill time
    +1
  • BigOnYa @ BigOnYa:
    Me and a buddy used to play that, is pretty fun. Graphics were pretty good also at that time, I think what 5-6 years ago. --Edit yea was 2018
  • BigOnYa @ BigOnYa:
    Surprised they never made a second one.
  • K3Nv2 @ K3Nv2:
    It takes two was their newest different theme
  • BigOnYa @ BigOnYa:
    I didn't care for that one so much, but didn't play it much either.
  • BigOnYa @ BigOnYa:
    I just played little of "Still Wakes The Deep" , just came to gamepass today, its alright, kinda creepy. I'm not usually a horror game fan, but it looks really good graphic wise, esp w 4k
    BigOnYa @ BigOnYa: I just played little of "Still Wakes The Deep" , just came to gamepass today, its alright, kinda...