ROM Hack Cheat Codes AMS and Sx Os, Add and Request

  • Thread starter Thread starter matias3ds
  • Start date Start date
  • Views Views 24,481,273
  • Replies Replies 73,653
  • Likes Likes 249
I don't know if the last three digit of the address where the red circle is will stay static over game restart. I would not bet on it but if you restart a few time and has observed that it does stay static then go ahead and use that.

If that address is M+ then yes, if it is different from the others you can absolutely use it as M+ will always have consistent last four digits when you restart the game. ( maybe not absolutely but if it is a modern game it should be, emulator may not always be static and some of them do use M+ for memory )

PS: The screenshot you did not draw circle did not just differ from the one with the red circle by the last three digits.
Unfortunately, he changes. If you have a suggestion to do so far I have never managed to separate the HP Player/Enemies.
Is there another method to do it, if not it hugs on pointer lol
 
Can you update to the latest version 2.0.27583 (v196608)?
BID: 3504A2DDCA4E6E9B
@dolpf thanks for info,already done.
2025042220323600-DB1426D1DFD034027CECDE9C2DD914B8.jpg

Note: it's only a part of the cheats,because the game is big to explore and complete and find all cheats.👋
 
  • Like
Reactions: zebrone and dolpf
Unfortunately, he changes. If you have a suggestion to do so far I have never managed to separate the HP Player/Enemies.
Is there another method to do it, if not it hugs on pointer lol
You can look at stack, Breeze let you capture up to 5, you can also look at register which the more recent release I let you catch one, finally you can follow some of the pointers and check if you can find anything ( very hard for human to spot if it is too far away from the pointer )

The top and the last differ by 0x1000 check if it is consistent and if so maybe can use that
1745324138104.png
 
Last edited by TomSwitch,
  • Like
Reactions: eco95 and Az91
You can look at stack, Breeze let you capture up to 5, you can also look at register which the more recent release I let you catch one, finally you can follow some of the pointers and check if you can find anything ( very hard for human to spot if it is too far away from the pointer )

The top and the last differ by 0x1000 check if it is consistent and if so maybe can use that
View attachment 500100
Thanks a lot
 
@TomSwitch Good evening, could you teach me how to do the Moonjump cheat in ASM? I couldn't do it, and I'd like to know how you did it. I mean, how you did it in Breeze (ASM Composer), because I found the instructions identical to yours after trying almost all 38 that appeared in Gen2 Menu. ldr s2, [x19, #0xcc]

*I'm asking here since you can't receive PMs.

In fact, I hadn't seen those three cheats you did. The way these cheats are arranged is very different.

Thank you so much.
for ldr, if the moonjump value is less than 41f80000 sometimes you could just use
ldr s2, [x19, #0xcc]
button
fmov s2, 31
200000000
 
  • Like
Reactions: Jericoss
Cheats request for

Bubble Ghost Remake 1.0.3​

TID: 010070601C7E4000
BID: FB89DBA26F7F2721
I made this.
==========================
[Breeze beta99b Bubble Ghost Remake 1.0.3 TID: 010070601C7E4000 BID: FB89DBA26F7F2721]

[Restore code]
04000000 028D8584 1E203900
04000000 028D952C 1E203900
04000000 02FB2EAC 1E203900
04000000 01E7B500 D10203FF

[The ring won't disappear]
04000000 028D8584 1E27F000

[Bats don't chase bubble]
04000000 028D952C 1E2E1000

[Spiders don't move, restore]
04000000 02FB2EAC 1E2E1000
80002000
04000000 02FB2EAC 1E203900
20000000

[Bubble Invincible]
04000000 01E7B500 D65F03C0

[Original Code by herowang]
20000000
===============================

This game has a KONAMI code, if you know how to use it, please let me know! :)
螢幕擷取畫面 2025-04-22 235941.jpg
 
all credits to ZiT, @roman2277 & @Az91 for porting this code

unfortunately some codes are not working so I removed it

anyway for those looking for the updated cheat like me of this old game (sorry I just found out about this game recently) :rofl:

Blue Fire v6.1.0
TID: 010073B010F6E000
BID: 2619FF1E39C93BAE
v458752

[Blue Fire v6.1.0 TID: 010073B010F6E000 BID: 2619FF1E39C93BAE]

[--SectionStart:Az91--]
00000000 00000000 00000000

[Walk Through Walls (Hold R)]
580F0000 060E14F8
580F1000 00000088
580F1000 00000080
780F0000 000002D0
610F0000 00000000 00000002
80000080
610F0000 00000000 00000001
20000000

[Moon Jump]
80000002
580F0000 060E14F8
580F1000 00000088
780F0000 0000009C
640F0000 00000000 44C00000
20000000

[Speed Up]
580F0000 060E14F8
580F1000 00000088
780F0000 0000015C
640F0000 00000000 45300000

[Inf. Life]
580F0000 060E0E10
580F1000 00000008
780F0000 00000180
640F0000 00000040 00000020

[--SectionEnd:Az91--]
00000000 00000000 00000000
cheats not showing up.
 
cheats not showing up.

From @TomSwitch

Atmosphere has a builtin CheatVM. This is what execute the cheat codes.

Cheat code is loaded into CheatVM memory by atmosphere when a game launch if the file /atmosphere/contents/<TID>/cheats/<BID>.txt is available.


There will be some cheats appearing if the syntax of the file is good.
The following is an example of good syntax:
"
[Cheat name]
01234567 01234567 01234567
01234567 01234567
01234567
"
The name of the cheat is between either "[" and "]" or "{" and "}" AND out side of these quote there are only sets of 8 hex digits and only space or CR that separate the 8 hex digits.

If the file /switch/EdiZon/cheats/<BID>.txt is present when EdiZon SE is launched
EdiZon SE will remove all the cheats loaded in Atmosphere's CheatVM memory and load the content of this file into CheatVM's memory. After loading the file EdiZon SE will move this file to /atmosphere/contents/<TID>/cheats/<BID>.txt
This is good for people making cheat code. Put the file, launch EdiZon SE and the code is ready for testing.

Ask Breeze to load file
Breeze can load file from either Atmosphere directory /atmosphere/contents/<TID>/cheats/<BID>.txt or Breeze directory /switch/Breeze/cheats/<BID>.txt or any file in /atmosphere/contents/<TID>/cheats/ or /switch/Breeze/cheats/

EdiZon SE, Breeze, Zing let you toggle the on/off state of the cheat codes

If these app says no cheat code available it means either there isn't any cheat code loaded into the CheatVM or CheatVM can't work with the game that is running (this can happen with some rom hack).

CheatVM may not able to attach to a game because something else has already attached to the game as a debugger, you may have other hack which beat CheatVM to it. To test this possibility remove all sysmodules and rom hack by (temporarily) renaming your existing contents directory to a different name and create a contents directory that has only the cheat files and any file that comes with Atmosphere distribution from github, reboot your switch and check if now the cheats would appear.

For reference if all else failed.
https://gbatemp.net/threads/cheat-codes-ams-and-sx-os-add-and-request.520293/post-9679294
 
  • Like
Reactions: gregozone
@2K417 could you update portal knight to 1.7.2?

Portal Knights 1.5.3
TitleId: 0100437004170000
BuildId: 4F3D7062D176246D

Code:
[Unlimited Items (On)]
04000000 003E7400 D503201F

[Unlimited Items (Off)]
04000000 003E7400 4B0C014A

[Toggle Unlimited Items (Press Minus)(AMS only)]
80000800
540F0000 003E7400
C045F400 4B0C014A
04000000 003E7400 D503201F
20000000
C045F400 D503201F
04000000 003E7400 4B0C014A
20000000
20000000

[Don't fall Down (Hold ZL)]
04000000 003BC6E0 BD000662
80000100
04000000 003BC6E0 D503201F
20000000

[No Fall Damage (On)]
04000000 003BD480 D503201F

[No Fall Damage (Off)]
04000000 003BD480 1E283800

[Always Revive with 100% HP/Mana/Oxy (On)]
04000000 00BA3CC8 3F800000

[Always Revive with 100% HP/Mana/Oxy (Off)]
04000000 00BA3CC8 3EE147AE

[Unlimited Range in Build Mode (On)]
04000000 00BA3E3C 461C3C00
04000000 00BA3E40 461C3C00
04000000 00BA3E44 461C3C00

[Unlimited Range in Build Mode (Off)]
04000000 00BA3E3C 41700000
04000000 00BA3E40 41A00000
04000000 00BA3E44 41700000
Note1: "Unlimited Items" affects all items, this includes crafting stuff, so be careful when using it.
Note2: "Don't fall Down" is like a fly cheat, you can move freely in air, but no Up/Down...
Note3: Toggle Unlimited Items is a code that ONLY works on Atmosphere, this code type is not implemented in SX OS!
Only press a small amount of time to toggle it, it works like this:
Code:
if("Minus" is pressed)
{
    R15 = read32(Main + 0x3E7400);
    if(R15 == 0x4B0C014A) write32(Main + 0x3E7400, 0xD503201F);
    if(R15 == 0xD503201F) write32(Main + 0x3E7400, 0x4B0C014A);
}

The game has a really strange way to hide it's values and it does memory crc checks. (most likely a remnant from the pc version)
0xCEDA2313 = Health
0x68ED562C = Oxygen
0x60D64632 = Mana
these values are used together with "keen::impactsystem::findAttribute", but i couldn't find any decrease or damage function, only fall damage and death...
 
for ldr, if the moonjump value is less than 41f80000 sometimes you could just use
ldr s2, [x19, #0xcc]
button
fmov s2, 31
200000000
Okay, thank you very much. How do I set a value higher than 31 in float? Is that not possible?

In fact, can't you put float values after a "#"??
I mean:
#0x58 I've seen examples like this (word) or something like #999

So #42c800000 like this example can't be done, right?
 
Last edited by dsrules,
  • Like
Reactions: Jericoss
credits to @zzpong & @soemone

:!: code updater update

tested / working

if not working best option downgrade game version with the working cheats @soemone 1.10.1

PS: I tried to update @kindren's cheat but I think something major change
in this update that his cheat can't be updated (shows incomplete code)

@Az91's cant be updated also bec. of the Ptr. Master Code

Unofficial Cheat Update

Hello Kitty Island Adventure v1.11.0
TID: 010027901C89C000
BID: 8AFD11C2D0E46F23
131072

PS: Item +100 (Hold L On Acquire) gives you 999 unlike before it gives you +100
this could prevent you from progressing later on SAVE REGULARLY

[Hello Kitty Island Adventure v1.11.0 TID: 010027901C89C000 BID: 8AFD11C2D0E46F23]

[--SectionStart:soemone--]
00000000 00000000 00000000

[Restore Code]
04000000 00770F28 BD404200
04000000 02E01D74 B9401268
04000000 03699A1C B9401AA9

[Item +100 (Hold L On Acquire)]
04000000 03699A1C B9401AA9
80000040
04000000 03699A1C B9401AA9
04000000 03699A1C 15105F02
04000000 07AB1624 52800C89
04000000 07AB1628 B9001AA9
04000000 07AB162C 16EFA0FD
04000000 07AB1630 00000064
21000000
04000000 03699A1C B9401AA9
20000000

[Stamina]
04000000 00770F28 BD404200
04000000 00770F28 15CD01C3
04000000 07AB1634 1E245000
04000000 07AB1638 BD004200
04000000 07AB163C 1632FE3C

[XP +1000]
04000000 02E01D74 B9401268
04000000 02E01D74 1532BE33
04000000 07AB1640 52807D14
04000000 07AB1644 B9401268
04000000 07AB1648 16CD41CC

[Inf. Item (Not For Event Items)]
04000000 040CC98C 4B0A0129
04000000 040CC98C 2A0903E9

[--SectionEnd:soemone--]
00000000 00000000 00000000
Uh I think the "Hold L for +100 items" is... SLIGHTLY broken on the old one. This is creating 1 Fertilizer and holding L. I .. guess I have while to go before I run out of fertilizer now. At least it.. works? 🤣

EDIT: Found an update.
 

Attachments

  • Screenshot 2025-04-22 215022.png
    Screenshot 2025-04-22 215022.png
    6 KB · Views: 46
Last edited by Maverynthia,
Okay, thank you very much. How do I set a value higher than 31 in float? Is that not possible?

In fact, can't you put float values after a "#"??
I mean:
#0x58 I've seen examples like this (word) or something like #999

So #42c800000 like this example can't be done, right?
replace 3 lines

movz w2 ,#0
movk w2 ,#0x42C8,lsl#16
fmov s2 ,w2

or code cave jump at str s2,[xY,#0xYYYY]

b #0xXXXXXXXX
ldr s2,#0xC
str s2,[xY,#0xYYYY]
b #0xZZZZZZZZ
42C80000
 
Okay, thank you very much. How do I set a value higher than 31 in float? Is that not possible?

In fact, can't you put float values after a "#"??
I mean:
#0x58 I've seen examples like this (word) or something like #999

So #42c800000 like this example can't be done, right?
You cannot do that with one instruction. That is the pain of using RISC instruction set. There are some nice thing with RISC too but code don't have to use the stack to make a call is the worst of ARM64. Sometime it can be very hard to find the caller.
 
@TomSwitch: on the topic of the moon jump but not ASM but pointer code what thus it mean when the pointer code stops working then will work again then after sometime it stop again. (just a bad pointer?)

ex. Beholgar

[Moon Jump]
80000042
580F0000 0499EED0
580F1000 00000130
580F1000 00000040
580F1000 00000038
580F1000 00000098
580F1000 00000040
580F1000 00000078
780F0000 00000044
640F0000 00000000 420C0000
20000000
 
@TomSwitch: on the topic of the moon jump but not ASM but pointer code what thus it mean when the pointer code stops working then will work again then after sometime it stop again. (just a bad pointer?)

ex. Beholgar

[Moon Jump]
80000042
580F0000 0499EED0
580F1000 00000130
580F1000 00000040
580F1000 00000038
580F1000 00000098
580F1000 00000040
580F1000 00000078
780F0000 00000044
640F0000 00000000 420C0000
20000000
Bad pointer is one way to call it. The thing is a pointer may not always be needed and therefore may not be always valid. Most of the time such pointer don’t get corrupted and there for the time when it wasn’t needed don’t cause problem as they are still valid although there is no need for it to be valid

For example you sell car and today you are on holiday so you don’t have the latest price but what you know may or may not be still the correct price. If some one ask what is the price and it wasn’t 2 April what you say may still be good
 
Last edited by TomSwitch,
  • Like
Reactions: Jericoss and 2K417

Okay, very well, I understand. Thank you very much.

replace 3 lines

movz w2 ,#0
movk w2 ,#0x42C8,lsl#16
fmov s2 ,w2

or code cave jump at str s2,[xY,#0xYYYY]

b #0xXXXXXXXX
ldr s2,#0xC
str s2,[xY,#0xYYYY]
b #0xZZZZZZZZ
42C80000

I don't understand. How would it work in a real-life example? Well, don't you have an example from another game?

If not, okay, look, I'll look for an instruction in str from a game, and when I have it, I'll let you know so you can tell me how it would work.

Thank you very much.

You cannot do that with one instruction. That is the pain of using RISC instruction set. There are some nice thing with RISC too but code don't have to use the stack to make a call is the worst of ARM64. Sometime it can be very hard to find the caller.

ok got it thank you so much
@TomSwitch: on the topic of the moon jump but not ASM but pointer code what thus it mean when the pointer code stops working then will work again then after sometime it stop again. (just a bad pointer?)

ex. Beholgar

[Moon Jump]
80000042
580F0000 0499EED0
580F1000 00000130
580F1000 00000040
580F1000 00000038
580F1000 00000098
580F1000 00000040
580F1000 00000078
780F0000 00000044
640F0000 00000000 420C0000
20000000

One of the things I've seen when a pointer cheat works and then doesn't, or in some parts of the same screen, is that the cheat needs to go deeper. I mean, if the cheat is 6 deep, sometimes it needs to be 7, 8, or more.

*If I remember correctly (although I don't have it anymore), the maximum depth I did was 14 or 15 or 16 , I don't remember exactly.
And I don't remember the game but it was supposed to only be possible to do ASM in that moment but I did the HP one.

I Think was Eastward game.

By the way, @TomSwitch , isn't it possible to search for more than or in 8 digits in Breeze (FFFFFFFF) in a "search range"?

Since I've seen that Breeze only allows 4 digits.
 
Last edited by Jericoss,
  • Like
Reactions: 2K417

Site & Scene News

Popular threads in this forum