Hacking Decrypting Animal Crossing New Leaf 00000001.sav File

  • Thread starter Thread starter HawkEmAce
  • Start date Start date
  • Views Views 1,811
  • Replies Replies 29

HawkEmAce

Member
Newcomer
Joined
Jun 24, 2025
Messages
15
Reaction score
1
Trophies
0
Age
28
XP
36
Country
United States
Hey, so my 3DS was stolen back in March 2015. However, I miraculously backed up the SD card from that 3DS (I don’t even remember doing this). My copy of ACNL was a digital copy, and know this is the original SD card because there are in-game screenshots of my original ACNL town from February 2015.

I found the 00000001.sav file in the 00040000/00086300 folder, so I know this is the ACNL save.

Even though I no longer have the original 3DS, I was able to retrieve the movable.sed using the friend code of that stolen 3DS using another 3DS.

I tried using wwylele’s 3ds-save-tool and entered the key from the movable.sed file into secrets.py, in addition to the key0x30X and key0x34X keys (from a pastebin file). I saw on the pastebin file a “generator” key. Is this the “keyConst” key that is required by secrets.py?

Because every time I run “disa-extract.py,” I get “Error: CMAC mismatch,” even though I’m pretty sure I have the correct keys.

All help is appreciated! Thanks!
 
Last edited by HawkEmAce,
Even though I no longer have the original 3DS, I was able to retrieve the movable.sed using the friend code of that stolen 3DS using another 3DS.
I hope you know what you were doing when you did that.

I tried using wwylele’s 3ds-save-tool
You've done a surprising amount of work, but did none of your searching suggest using threeSD, as in https://gbatemp.net/threads/restore-save-data-from-dead-3ds-2ds.606907/ ? That is much, much easier than using 3ds-save-tool. (Be sure to read the first couple of posts in the thread.)
 
Yeah, I tried using threeSD, but I was confused as to why it needs me to mount the entire SD card. Is there any way to decrypt a single 00000001.sav without having to mount the whole SD card card? Does the 00000001.sav have to be it’s original location for threeSD to decrypt the it?

I have the contents of the entire SD card, so this is not a problem, but I’m just curious.
 
Does the 00000001.sav have to be it’s original location for threeSD to decrypt the it?
Yes, you don't technically have to "mount the entire SD card" as long as the .sav file is in the correct location. That's why you don't have to manually specify the title ID like you would when using 3ds-save-tool.
 
Ok, so I selected the original file location for 00000001.sav file (as well as choosing my movable.sed and boot9.bin) but threeSD is throwing this error: "An error occurred while performing the operation."
Capture.PNG
Capture2.PNG
 
Did you read the first couple of posts in the thread, as I suggested..? Apparently you need to select the ID1 path as the SDMC root.

I also have no idea if you retrieved your movable.sed correctly.
 
I simply went to Bruteforce Movable and entered the friend code of the stolen 3DS. Then, I entered the ID0 of my current 3DS (not the ID0 of the original 3DS that got stolen). I must've done everything correct on Bruteforce Movable, and the ID0 has to be correct. Otherwise, Bruteforce Movable would have thrown an error, right?
 
I simply went to Bruteforce Movable and entered the friend code of the stolen 3DS. Then, I entered the ID0 of my current 3DS (not the ID0 of the original 3DS that got stolen). I must've done everything correct on Bruteforce Movable,
Did you add a bot to a Friend list at some stage of that process..?
 
Did you add a bot to a Friend list at some stage of that process..?

I made a bot while I was putting CFW on my current 3DS. I see the bot in my friends list. Does the bot have any significance in terms of decrypting the 00000001.sav?
 
I made a bot while I was putting CFW on my current 3DS.
You didn't "make a bot", you added a bot to your Friends list.

Does the bot have any significance in terms of decrypting the 00000001.sav?
Yes, it appears you did not correctly generate your movable.sed. I'm not entirely clear why bruteforce movable didn't give you an error message, but I'm not entirely clear on exactly what you did, either.

When you add the bot to your Friends list, the bot (i.e. some other 3DS) generates a piece of data: the "lfcs_b", sometimes also called the "movable_part1". This data is then used with your id0 to compute the movable.sed.

So, when you entered the Friend code of your stolen 3DS into bruteforce movable, it tried to add that unit as a Friend – except of course 3DS online services are shut down, so exchanging Friend codes online is longer possible. There really ought to be a warning of some sort on the website. (Needless to say, using the lfcs_b of one unit and the id0 of a completely different unit shouldn't work at all.)

If you have access to another 3DS that has the Friend code of your stolen unit registered in its Friend list (complete with a Mii, and not just "provisionally registered"), then you can manually retrieve the lfcs_b from that unit (using homebrew) and use Seedminer with the id0 from your backup to bruteforce the movable.sed. Or if you generated a Mii QR code on your stolen unit, that can also be used with Seedminer.

ETA: I am mistaken. Online Friend code exchange is indeed still possible. Not that it is in any way relevant to this current operation.
 
Last edited by Kwyjor,
Yes, it appears you did not correctly generate your movable.sed. I'm not entirely clear why bruteforce movable didn't give you an error message, but I'm not entirely clear on exactly what you did, either.

So the 3DS that I have right now I bought on Facebook marketplace on June 2022 and had something else’s data. I formatted that 3DS and, as a result, wiped whatever friend code was on it.

I hadn’t had access to my original NNID in a long time (since March 2015 when my original 3DS got stolen), so I called Nintendo (around early 2024) to see if I could recover my NNID.

Once they gave me access to me NNID, I can’t remember if my original friend code was automatically transferred to my current 3DS (does it work like this?), or if, once I signed into my NNID, the original Mii/friend appeared in my friends list.

The original Mii is now in friends list regardless, and the friend code for that original Mii was what I entered into Bruteforce Movable.

I then entered the ID0 present on the SD card from my original/stolen 3DS. However, I get “We we’re unable to successfully complete your bruteforce request. :`(“

But what I don’t understand is when I enter the ID0 of the new 3DS that I bought, along with original Mii’s (supposedly from the stolen 3DS) friend code, everything works flawlessly and I’m able to download a movable.sed.

I don’t know why the ID0 of my stolen 3DS doesn’t work on Bruteforce Movable, but the ID0 of a random 3DS I bought works.

Anyways, that’s the situation with Bruteforce Movable right now.
 
Once they gave me access to me NNID, I can’t remember if my original friend code was automatically transferred to my current 3DS (does it work like this?), or if, once I signed into my NNID, the original Mii/friend appeared in my friends list.
Transferring an NNID merely allows you to use that NNID to connect to the eShop and other online services and does not affect your Friend code or Friend list, if I'm not gravely mistaken.

I don’t know why the ID0 of my stolen 3DS doesn’t work on Bruteforce Movable, but the ID0 of a random 3DS I bought works.
Maybe it's just a weird coincidence.

What happens if you try using the actual, current Friend code of your 3DS with Bruteforce Movable?
 
the actual, current Friend code of your 3DS
Do you mean the friend code that's present on my current 3DS? That friend code paired with ID0 of that 3DS is what worked on Bruteforce Movable. Could it be possible that the friend code on my stolen 3DS is, in fact, different than the one on my current 3DS?

I should have mentioned earlier that the name if my Mii is "Ping." This is the name I see on my current 3DS and I'm pretty sure this was also the main Mii that was on my stolen 3DS.
 
Do you mean the friend code that's present on my current 3DS?
I am referring to the very first entry in your Friends list.

That friend code paired with ID0 of that 3DS is what worked on Bruteforce Movable.
Well, that makes sense, at least.

ETA: I should emphasize that the only reason Bruteforce Movable is giving you anything at all is probably because it has retained the data from when you last used it with this 3DS.

Could it be possible that the friend code on my stolen 3DS is, in fact, different than the one on my current 3DS?
Yes, that is almost certainly the case. You may have gotten your old NNID back, but that has nothing to do with your Friend code.
 
Last edited by Kwyjor,
Yes, that is almost certainly the case. You may have gotten your old NNID back, but that has nothing to do with your Friend code.
So I restored a NAND backup of a 3rd 3DS that I created in 2020, and it actually has the true original friend code of the stolen 3DS. And, as mentioned earlier, I have the ID0 of the stolen 3DS on an SD card.

Now that I have the friend code and ID0 of the stolen 3DS, is it now possible to retrieve the real movable.sed of the stolen 3DS and decrypt the Animal Crossing New Leaf save?
 
So I restored a NAND backup of a 3rd 3DS that I created in 2020
Restoring a NAND backup of a 3DS to a unit different than the one that was used to create the backup is one surefire means of bricking a unit, just so you know.
and it actually has the true original friend code of the stolen 3DS.
To be clear: when you say it "has the true original friend code", do you mean that the Friend code is the first entry in the Friends list, or do you mean that it is registered as a Friend somewhere else in the list? This is an important distinction.

ETA: Also, to be clear, if it is registered as a Friend somewhere else in the list, does it have a Mii, or is it just "provisionally registered"?
 
Last edited by Kwyjor,
Restoring a NAND backup of a 3DS to a unit different than the one that was used to create the backup is one surefire means of bricking a unit, just so you know.

Restoring from that NAND backup worked, as I’m able to boot the 3DS from that backup. (It’s a long story, I can explain if it’s relevant).

To be clear: when you say it "has the true original friend code", do you mean that the Friend code is the first entry in the Friends list, or do you mean that it is registered as a Friend somewhere else in the list? This is an important distinction.

ETA: Also, to be clear, if it is registered as a Friend somewhere else in the list, does it have a Mii, or is it just "provisionally registered"?

Sorry, I should have clarified. The friend is not the first one in the entry. It’s somewhere in the middle, but it’s fully registered, not provisionally, since there’s a Mii avatar.

My question now is: Is it still possible to get the movable.sed from the stolen 3DS and decrypt the save?
 
Sorry, I should have clarified. The friend is not the first one in the entry. It’s somewhere in the middle, but it’s fully registered, not provisionally, since there’s a Mii avatar.
All right then. As per my earlier post: the next step is to dump the lfcs_b using homebrew, and then use Seedminer with the id0 from your backup to get the movable.sed. Specifically, you need to run seedstarter.3dsx (or seedstarter.cia) from https://github.com/zoogie/seedminer/releases/tag/v2.1 on the 3DS and follow the instructions in readme.txt , under "[B - No homebrew but friend with homebrew]".

(You might be able to find someone on the Homebrew Discord to run Seedminer for you if your PC's hardware is inadequate. The Bruteforce Movable website used to provide this functionality, but it vanished long ago.)
 
Last edited by Kwyjor,
On which 3DS do I dump the lfcs_b?
How many different units do you have at this point..? You are going to get the lfcs_b corresponding to the Friend code registered in the Friend list that you were referring to. Each Friend code in the list will have its own lfcs_b.

Is it whatever 3DS is fully registered to the stolen 3DS?
I'm afraid I'm not even sure what you mean by that.
 
Last edited by Kwyjor,

Site & Scene News

Popular threads in this forum