Tutorial  Updated

PS5 Exploit Guide

PS5 Hack Status:


FW Ranges:
2.XX = HEN+Kstuff+HV = PS4/5 backups, possible keys exploit (WebKit: 2.50 best / 2.7X max)
3.XX = HEN+Kstuff+HV+Linux = PS4/5 backups, possible keys exploit (WK/BDJB/LUA: 3.20 best / 3.21 max)
4.XX = HEN+Kstuff+HV+Linux = PS4/5 backups (WK/Y2JB/BDJB/LUA: 4.50 best / 4.51 max)
5.XX = HEN+Kstuff+HV+Linux = PS4/5 backups (
WK/Y2JB/BDJB/LUA: 5.50 best + max)

6.XX = HEN+Kstuff = PS4/5 backups, HV+Linux for 6.02 max (Y2JB/BDJB/LUA: 6.50 best + max)
7.XX = HEN+Kstuff = PS4/5 backups, no HV (
Y2JB/BDJB/LUA: 7.61 best + max)
8.XX-10.01 = HEN+ Kstuff = PS4/5 backups, no HV (Y2JB/LUA)
10.20-12.00 = KEX + Kstuff = PS4/5 backups, no HV (
LUA)
12.02-12.70 = KEX (
P2JB/SWRR)
13.XX = No KEX/HEN/Kstuff/HV (LUA)

NOTE: Recommended firmware is subjective. Staying low is always suggested first & foremost. It is not recommended to update too many major versions (e.g., 4.xx to 5.xx or 7.xx to 8.xx) because you should remain low unless all you want is backups.

DO NOT UPDATE OVER 12.00!! P2JB can take over 3 hrs to trigger an exploit.


Hypervisor (HV):
Highest known HV exploit: 6.02
Highest theoretical HV exploit: 7.XX
Highest implemented HV exploit: 1.00-4.51 (Cragson PS5Hen) / 3.00-6.02 (TheFlow)
*unreleased/unimplemented

Kernel (KEX):
Highest public Release:
12.70
Highest known: 12.70 (P2JB)
UMTX2: 1.00-7.61
Lapse: 1.00-10.01
Poopsploit: 4.XX-12.00
P2JB: X.XX-12.70

Userland (UL):
LUA: 2.00-LATEST (LUA game exploit, chain Lapse up to 10.01)
Y2JB: 4.03-12.60 (YouTube exploit, + Lapse up to 10.01)
NFNH: 4.03-12.XX (Netflix exploit, + Lapse up to 10.01)
YARPE: 4.03-12.XX (Ren'Py exploit, + Lapse up to 10.01)
BD-JB: 1.00-7.61 (Blu Ray exploit + UMTX2, 8.00-12.40 via UN BD JB + Poopsploit)
Webkit: 1.00-5.50 (PSFREE +UMTX2) (up to 13.20 coming soon)
Mast1C0re: 1.00-7.61 (PS2 backups)
LuaC0re: 10.20-12.02 (Star Wars RR: + Poopsploit up to 12.00)

NOTE: A userland entry exploit (UL) chained to kernel exploit (KEX) is required at a bare minimum to exploit your console.

NOTE 2: Since 12.60/13.00 Sony has removed the YouTube and Netflix apps and has added 30 day expirations to downloaded software used for LuaC0re/Mast1C0re/RenPy etc.

Digital consoles will now need a new webkit userland to hack their consoles as of 19/04/2026)


Useful Applications:
Elf loader: 8.00/7.61 HERE (use with BD-J)
Kstuff: 3.00-10.01 (3.00-12.70 soon)
HERE
Kstuff Lite: 3.00-12.70 HERE
Kstuff Toggle: 3.00-12.00 HERE
Dumping: Up to 8.00/7.61 (ItemzFlow / self decryptor) latest HERE
PS5 App Dumper: 3.00-12.00 HERE
Dump Runner: 3.00-12.00 HERE
Dump Installer: 3.00-11.60 HERE
Backporting: Possible (backpork / Porkfolio)
PS4/PS5 DLC: Work with kstuff (on retail disc games)
Homebrew Enabler: etaHEN (3.00-10.01) latest HERE
PS5 Backup Loading: Itemzflow HERE Compatibility list: HERE
PS4 Backup Loading: FPKG Enabler 3.XX-9.XX (rest mode & backports work, can crash).
PS5 Debug: Works
HERE
PS5 Remote Play: Works HERE & HERE
PS5 Trainers/Cheats: Work (Built into itemzFlow)

UART:
HERE
Linux: (3.00-6.02) HERE
Kldload (wip): 3.00-6.50 HERE
Full chain exploit: 1.00-4.51 (byepervisor) HERE (also built into etaHEN up to 2.7X)
PSN access: NEVER
Latest OFW: 13.20 (23/04/26)
Summarised OFW/Model guide: HERE
1.XX-7.61 compatibility list:
HERE
PS5 SDK Repo: HERE
Legit PKG Updates: HERE or HERE
OFW Updates: HERE (history HERE)

Preparing Your Console:


It is recommended to either self-host offline or block these addresses in your router to avoid accidental updates or getting an update nag. Using the DNS method is no longer failsafe, as these are not guaranteed to be running 24/7.


dau01.ps5.update.playstation.net
dbr01.ps5.update.playstation.net
dcn01.ps5.update.playstation.net
deu01.ps5.update.playstation.net
dhk01.ps5.update.playstation.net
djp01.ps5.update.playstation.net
dkr01.ps5.update.playstation.net
dmx01.ps5.update.playstation.net
dru01.ps5.update.playstation.net
dsa01.ps5.update.playstation.net
dtw01.ps5.update.playstation.net
duk01.ps5.update.playstation.net
dus01.ps5.update.playstation.net
fau01.ps5.update.playstation.net
fbr01.ps5.update.playstation.net
fcn01.ps5.update.playstation.net
feu01.ps5.update.playstation.net
fhk01.ps5.update.playstation.net
fjp01.ps5.update.playstation.net
fkr01.ps5.update.playstation.net
fmx01.ps5.update.playstation.net
fru01.ps5.update.playstation.net
fsa01.ps5.update.playstation.net
ftw01.ps5.update.playstation.net
fuk01.ps5.update.playstation.net
fus01.ps5.update.playstation.net
hau01.ps5.update.playstation.net
hbr01.ps5.update.playstation.net
hcn01.ps5.update.playstation.net
heu01.ps5.update.playstation.net
hhk01.ps5.update.playstation.net
hjp01.ps5.update.playstation.net
hkr01.ps5.update.playstation.net
hmx01.ps5.update.playstation.net
hru01.ps5.update.playstation.net
hsa01.ps5.update.playstation.net
htw01.ps5.update.playstation.net
huk01.ps5.update.playstation.net
hus01.ps5.update.playstation.net
sgst.prod.dl.playstation.net
gs2.ww.prod.dl.playstation.net

Alternative DNS IP:
DNS 1: 172.245.146.114
(Leave DNS 2 blank)

To determine your OFW version:
Go to settings > system > console information.

Version string info:
Year.Half (1st/2nd half of the year)-Major Version No.Minor Version No.Extended info-Further Info.Retail/Debug

21.02-04.03.00.00-00.00.00.0.1

It is recommended to keep your console as low as possible to have access to better jailbreak stability and features. Stay as low as possible within the "Golden" firmware brackets that apply to your current firmware.

Current Examples:

2.00 could be updated to 2.50 maximum to retain Webkit/BD-JB/LUA HV + KEX + HEN.
4.00 could be updated to 4.51 maximum for WebKit/BD-JB/LUA + KEX + HEN + potential HV exploits.
5.00 could be updated to 5.50 maximum for WebKit/BD-JB/LUA + KEX + HEN.
6.XX-7.XX could be updated to 7.61 maximum for HEN using only BD-JB or LUA.
Digital/Pro users on 6.XX-LATEST cannot use BDJB or LUA without an activated console. Wekbit does not go beyond 5.50 for now.
Digital/Pro users or Disc console users on 8.XX-LATEST should consider waiting or selling/swapping consoles to get a lower firmware.
(No jailbreak is ever guaranteed. No developer is obliged to release anything publicly)

WARNING:

Only update OFW manually via USB by getting the firmware file from HERE and installing from <USB>:/PS5/UPDATE/PS5UPDATE.PUP

SYSTEM UPDATES:

12.00 SYS MD5: 79d3171ec4ef38ca27f8ff36a9940847 (Exploited - No HEN yet)

10.01 SYS MD5: 68a31944c1867bf9643798fd1c14998e (Exploited + HEN)
9.00 SYS MD5: e74ddccd3360941ca24475c13195e031 (Exploited + HEN)
8.00 SYS MD5: 7616128c57581d5e49b42d1b3f308232 (Exploited + HEN)
7.61 SYS MD5: d5eca8b171a8d7df7ba225167f77e645 (Exploited + HEN)

6.50 SYS MD5: 98db854ba47a75dff0cb09355bca9025 (Exploited + HEN)
5.50 SYS MD5: edb3513ec531b2bd28f3a0b52a82a54f Exploited + HEN)
4.51 SYS MD5: 1330b7bf63bf5c93d809b1eb1f4e1f01 (Exploited + HEN)
4.03 SYS MD5: 3716e4e6e0d223cd94cd4a8e5bd4fb94 (Exploited + HEN)

RECOVERY UPDATES (wipes HDD):
12.00 REC MD5: f993e4c35ed6659b516346941980de4b (Exploited - no HEN yet)

10.01 REC MD5: 5202be086fc726d881f722d46e4486c6 (Exploited + HEN)
9.00 REC MD5: 6fbbda82c325bb5d6ec0717c2223b5c0 (Exploited + HEN)
8.00 REC MD5: 6cbb7a2fa2ace926202bd6e71304fb06 (Exploited + HEN)
7.61 REC MD5: 932f24e934723050fe49561b67e95226 (Exploited + HEN)
6.50 REC MD5: 4305223c12bd6dda9b944c0ee49c94c0 (Exploited + HEN)
5.50 REC MD5: c939ac8b37e07bbc129816a61002d30a (Exploited + HEN)
4.51 REC MD5: da78ca268da90a963d89b0f45db0f061 (Exploited + HEN)
4.03 REC MD5: e6dcc800d8d1dcada4f2bcd6e7ff162c (Exploited + HEN)

PS5 factory mode PUP installation path:

/usb/PROSPERO/UPDATE/PROSPEROUPDATE.PUP

Select Your Jailbreak:


WEBKIT (1.00-5.50):BD-JB 1.00-7.61:LUA (2.00-LATEST):Mast1c0re (2.00-7.61):Y2JB (4.03-10.01):NFNH (4.03-10.01):YARPE (4.03-10.01):LuaC0re (12.00 REQUIRES SWRR):BD UN JB (REQUIRES JB'D CONSOLE):


  1. PSFREE 1.XX-5.XX: https://github.com/kmeps4/PSFree
    Recommended host: https://zecoxao.github.io/luasauce/ (UMTX2 + Webkit for 1.XX-5.XX)

    Recommended WebKit hosts:
    https://zecoxao.github.io/luasauce/
    (UTMX2 with Lua and WebKit for 1.xx-5.xx)
    https://zecoxao.github.io/umtx/ or https://es7in1.site/
    (UMTX 2 exploit works on 3.00-5.50 with PSFREE WebKit)

    Alternative hosts:
    https://zecoxao.github.io/ps5jb/

    https://ps5jb.pages.dev/
    https://sleirsgoevy.github.io/ps4jb2/ps5-403/index.html

  2. You will need a BD dive paired to your Slim/Pro console, or an OG Phat model on 1.00-7.61 to run this exploit.

    Viktorious AIO Auto BD-JB ISO for 4.XX-7.61: https://github.com/Viktorious-x/ps5-bdjb-modified-ISOs/releases
    (Alternative: UMTX Kernel exploit 7.61 JAR loader by Hammer83: https://github.com/hammer-83/ps5-jar-loader/releases)

    Burn ISO to a blank BD-R or BD-RE, put it into your console, and click on the [DISC PLAYER] icon.
    Highlight [PIPELINE RUNNER] then click option 2 [Normaljailbreak-etaHEN-UMTX1.pipe] to auto load etaHEN ready for ItemzFlow.
    Debug settings will be loaded, and the package installer can be found under [SETTINGS] > [DEBUG SETTINGS].
    ELF Loader will be running on your PS5 IP: port 9021


  3. Important:
    Up to 10.01 has a kernel exploit + HEN
    11.XX-12.70 has a kernel exploit but no HEN yet.
    LUA entry point works on the latest OFW, but there is no kernel or HEN yet.
    (A compatible PS4 game is required to launch the exploit on PS5. See below)

    Your PS5 console must be activated to use save copying for PS4 games.

    1. Insert your game disc and, as soon as possible, make a save file within it.
    2. Copy the save files to USB, go to [SETTINGS] > [STORAGE] > [CONSOLE STORAGE] > [SAVE DATA] > [PS4 GAMES] > select the game save and copy to a USB drive.
    3. On PC, using a Google Drive account, make a new folder with the GAME ID of your game, and upload the savedata & savedata.bin files to that folder.
    4. Share the folder, set it to editor mode, share with anyone, and click "copy the link".
    5. Join the HTOS Discord group: HERE type "/decrypt", select "FALSE" for including SCE_SYS, paste or type in the Google Drive link, and press enter. The bot should begin mounting your save. (If it doesn't, paste in the link again.)
    6. Click "ENCRYPTED" to remove the Sony PFS layer. Download the generated files and extract the folder to your desktop (you should have 4 files in there and be named dec_savedata_CUSA[GAME ID]).
    7. Using REMOTE LUA LOADER, open the savedata folder, copy the 20 files within into your encrypted save folder on your desktop.
    8. Upload the encrypted save folder (now with 24 files in) to your Google Drive. It should be named "dec_savedata_CUSA[GAME ID]" where GAME ID is your games 5 digit number, and set it to editor mode, share with anyone, and then click "copy the link".
    9. Go back to the HTOS discord server, and type "/encrypt", hit "FALSE" for uploading individually, and "FALSE" to include SCE_SYS. Finally, hit shared_gd_link and paste in your link to the original save (4 files) folder. (If it doesn't, paste in the link again.)
    10. When this is done, paste the link to the decrypted save (24 files) folder, and the bot will encrypt the files.
    11. Resign the files by typing "/resign" followed by your account name on the console, or PSN ID associated with that account if using the latest OFW.
    12. Download the resigned files, extract the files to your USB drive and overwrite them into the savedata folder on your USB or external drive.
    13. Copy the saves back to your console [SETTINGS] > [SAVE DATA AND GAME/APP SETTINGS] > [SAVE DATA PS4] > [COPY OR DELETE FROM USB] > [COPY TO CONSOLE STORAGE] > select your game save folder from the USB drive and copy/overwrite old save data.
    14. Load LUA game again, and you should see the LUA LOADER screen.
    15. You can use "SEND_LUA.PY" to send the UMTX files to the loader.
    (NOTE: Some games require manual loading of save game)

    On firmware up to 7.61, you can now load UMTX/2 followed by etaHEN by sending the files to your console IP on PORT 9026.
    On firmware 8.00-LATEST, you can connect with the REMOTE LUA LOADER APP to send debug notifications or FTP on port 1337.

    LUA Loader: HERE or HERE

    Auto LUA Loader Fork: HERE

    Compatible LUA games:
    Aerial Life (CUSA17122)
    Aibeya (CUSA17068)
    Aikagi 2 (CUSA19556)
    Aikagi Kimi to Issho ni Pack (CUSA16229)
    Aikano Yukizora no Triangle (CUSA19370)
    Boku to Nurse no Kenshuu Nisshi (CUSA12049)
    Boku to Joi no Shinsatsu Nisshi (CUSA18107)
    Fuyu Kiss (CUSA29745)
    Hamidashi Creative (CUSA27389)
    Hamidashi Creative Demo (CUSA27390 requires the latest OFW to download from PSN)
    Haruoto Alice (CUSA14324)
    IxSHE Tell (CUSA17112)
    IxSHE Tell Demo (CUSA17126)
    Jinki Resurrection (CUSA25179)
    Jinki Resurrection Demo (CUSA25180 requires the latest OFW to download from PSN)
    Maid-san no Iru Kurashi (CUSA18106)
    Nora Princess and Stray Cat Heart HD (CUSA13303: Rename save9999.dat into nora_01.dat)
    Nora Princess and Strat Cat Heart 2 (CUSA13586)
    Raspberry Cube (CUSA16074)
    Winter Guest (CUSA11977)

    WARNING: using demos is free but can become corrupt, and you cannot upgrade your internal HDD either. If you lose the demo you can no longer use the exploit.Disc recommended.

    Incompatible LUA games:

    Dokyusei Remake Csver (CUSA47117)
    Dōkyūsei: Bangin' Summer - Home Edition Demo (CUSA47132)
    Kiss Trilogy (CUSA19341)
    Love Clear Demo (CUSA18109)
    Mikagami Sumika no Seifuku Katsudou (CUSA11481)
    Sen no Hatou, Arazone no Hime (CUSA09647)
    Tonari ni Kanojo no Iru Shiawase: Two Farce (CUSA09825)
    Tonari ni Kanojo no Iru Shiawase Summer Surprise (CUSA18998)

  4. PS2 Classics > Userland via CTurt:
    (Implementation by McCaulay)
    Note: this is currently limited to swapping the loaded PS2 iso, or loading PS2 elf homebrew on PS5 (or PS4) for emulators or basic PS2 brew.

    Mast1c0re PS2 exploit for PS2 homebrew:
    https://cturt.github.io/mast1c0re.html

    Mast1c0re part 2:
    https://cturt.github.io/mast1c0re-2.html

    Mast1c0re payload framework:
    https://github.com/McCaulay/mast1c0re

    Okrager save game exploit generator for Okage:
    https://github.com/McCaulay/okrager

    Mast1c0re payloader TCP Client GUI for PS5 6.50:
    https://github.com/Master-s/PS4-PS5-Mast1c0re-Payloader/releases

    TCP network ISO loader:
    https://github.com/McCaulay/mast1c0re-ps2-network-elf-loader/releases

    ExFat USB ISO loader:
    https://github.com/McCaulay/mast1c0re-ps2-usb-game-loader/releases

  5. coming soon

  6. coming soon

  7. coming soon

  8. coming soon

  9. This method modifies the BD-J stack to allows BDJB to be re-enabled on your higher firmware console up to 12.40.

    This requires your console to be hacked via another method first to gain access to alter the files.
    (For example 12.00 needs SWRR disc to hack it first)

    https://github.com/Gezine/BD-UN-JB

    DO NOT REINSTALL FW, IT WILL WIPE THE PATCH AND LOSE BD-JB


Additional Information:


PS4 GAME INFORMATION:
OFW 1.xx cannot run PS4 games.
OFW 2.xx runs PS4 games up to 8.03

OFW 3.xx runs PS4 games up to 8.52
OFW 4.xx runs PS4 games up to 9.04
OFW 5.xx runs PS4 games up to 9.60
OFW 6.xx runs PS4 games up to 10.50

OFW 7.xx runs PS4 games up to 11.00
OFW 8.xx/9.xx runs PS4 games up to 11.50
OFW 10.xx runs PS4 games up to 12.00

OFW 11.xx runs PS4 games up to 12.50
OFW 12.xx runs PS4 games up to 13.00


(Note: PS4 backported FPKGs also work perfectly on an exploited PS5 with Kstuff)


You can install free/demo PKGS (legit pkgs) via the debug pkg installer, provided you have all the files/json/licences required.
(Astro’s Playroom has no licences and can be installed and played from official pkgs and updated inline with your firmware)

Warnings:


1: Never enable IDU mode.
If you do, you will need to enter staff mode by holding L1 + L2 and tapping this combo: circle, cross, square, triangle, right D-Pad. Release L1 + L2, and you can access settings to exit IDU.

2: Try to stay on the lowest FW possible and wait for hacks on that firmware.

3: PS5 FPKGs do not work. A hack for the A53 processor does not publicly exist to enable installing PS5 content as FPKG/PKG.

4: Installing legit game PKGs you do not own will never work, even if spoofed.

5: If you get stuck in a boot loop at the PS logo, the SNVS is corrupted (if the hash check fails on boot, this causes a “soft brick”). It’s not “bricked”. Simply reinstall your current firmware RECOVERY PUP in safe mode from USB: PS5 > UPDATE > PS5UPDATE.PUP.

Archived Information


 
Last edited by KiiWii,
what firmware you on using the python script with?

I don't know if that is better than the Backport Kitchen because if I remember right, the downgrade sdk method was just 1 below. I have to say that I was on 4.03 2 weeks ago and I updated to 7.61 and been using the Backpork Kitchen app and everything been 100% working for me ever since. Now when I tried using the Backport app with 4.03 on games like Black Myth Wukong, Silent HIll 2, etc... they wouldn't load unfortunately.....
I don't see how the firmware being targeted has anything to do with the python script aborting because the eboot.bin was signed and not unsigned. The script allows you to choose what minimum firmware it targets so it changes all the required files to that selected firmware. The problem with backpork kitchen is that it only patches the library files, it doesn't downgrade the targeted firmware in the param and eboot.bin as is stated in the backpork repository. In order for things to work properly both things must be done. Backpork kitchen is the last step, the first step is to change the target firmware version before the fake lib patches.
 
  • Like
Reactions: solitaire4eva
Anyone tested out ffpkg files with shadowmount?

ShadowMountPlus (PS5)​

Version: 1.5beta
Thanks for ffpkg support: @Gezine, @earthonion and @VoidWhisper for ShadowMount
ShadowMountPlus is a fully automated, background "Auto-Mounter" payload for Jailbroken PlayStation 5 consoles. It streamlines the game mounting process by eliminating the need for manual configuration or external tools (such as DumpRunner or Itemzflow). ShadowMount automatically detects, mounts, and installs game dumps from both internal and external storage.
Compatibility: Supports all Jailbroken PS5 firmwares running Kstuff v1.6.7.

Current image support​

PFS support is experimental.

ExtensionMounted FSAttach backendStatus
.exfatexfatfsLVD or MD (configurable)Stable
.ffpkgufsLVD or MD (configurable)High performance
.ffpfspfsLVDExperimental
Notes:
  • Backend, read-only mode, and sector size can be configured via /data/shadowmount/config.ini.

https://github.com/drakmor/ShadowMountPlus/releases/tag/1.15-beta
 
I7
I don't see how the firmware being targeted has anything to do with the python script aborting because the eboot.bin was signed and not unsigned. The script allows you to choose what minimum firmware it targets so it changes all the required files to that selected firmware. The problem with backpork kitchen is that it only patches the library files, it doesn't downgrade the targeted firmware in the param and eboot.bin as is stated in the backpork repository. In order for things to work properly both things must be done. Backpork kitchen is the last step, the first step is to change the target firmware version before the fake lib patches.
I only use "Duplex" releases for them higher firmware games. Never had a problem. Duplex rules!
 
  • Like
Reactions: sudeki300
I7

I only use "Duplex" releases for them higher firmware games. Never had a problem. Duplex rules!
Yeah. That's all I would ever get back in the ps3 custom firmware days. I figured it out though, there's a program that will decrypt the fake signed files into .elf files to be downgraded. Now I can test it out when I get back home.
 
  • Like
Reactions: solitaire4eva
Quick question please...

I appreciate that the recommended way to run dumps is via an nvme through usb....

However I would like to know if anyone has any first hand experience of using a SATA SSD through usb and how has it performed????

I'd like to find out if games such as Astro, Wukong, FC 26 and Cyberpunk would run without issues via sata
 
np-fake-signin.... Don't get me started on this little exploit.... Sure it may work for some and guess what, it definetly will not work as intended for others! I found that it would revert back by itself... with some boot cycles it was applied then with other boot cycles it was mysteriously reverted! And then there was the constant failures in lapse or the kernel exploit...and yes, ps4 saves were unlocked and i thought yippee.. until i rebooted and zip! I rebuiilt my console probsbly 4 maybe 5 times that week and all i can say is never again!!!

The prerequisites are:

  • Offline activation via offact (account must have a non-zero account ID) >>> THIS WAS PRESENT FOR ME
  • PS4 Payload SDK or PS5 Payload SDK >> I ASSUME I NEEDED TO DO NOTHING HERE
  • HMAC-MD5 key for dat file signing (replace the zeroes in source files with the real key) >>> NO IDEA WHAT THIS MEANS JUST ASSUME I DIDN'T NEED TO DO ANYTHING
Post automatically merged:

I have an activated PSN PS5 JB (10.01) and no I cannot export PS4 saves. You will get the message that you need to sign in / update your console :)

Actually, the same was for me... On my 9.20 system i had a PSN account which was activated (np) but usb saves would not work. I'm trying to figure out how i activated it as it was definetly my PSN id with the same hex number and the same avatar. I think i made an image from my 11.60 system which was used for PSN at the time. So when i restored that image to the digital 9.05/9.20 console i had an activated account however the USB saves were not unlocked!
Post automatically merged:

Wait it does? I applied the fake-signin and then after a few reboots, it now says I'm signed out, and I can't use ps4 save transfer anymore.
I haven't tried to reapply the payload, so hopefully it still works and doesn't give me an issue, but if it's gonna keep reverting, I'll just wait until I need to transfer saves etc before sending the payload again.
This kept on happening to me! I explained this to earthonion and frankly he was at a loss to why that was happening... I think there is something about the user accounts thats causing this behaviour... Now, if one has a totally virgin account I'm wondering if the same issue would persist..?
 
Last edited by BobaFett_UK,
This kept on happening to me! I explained this to earthonion and frankly he was at a loss to why that was happening... I think there is something about the user accounts thats causing this behaviour... Now, if one has a totally virgin account I'm wondering if the same issue would persist..?
You can try np-fake-signin without risk if you want (of course the last version, not the beta lol).
Because now is working only on the active account, so you can create many accounts as you like, do your tests and after delete the account if you want.
Always you don't installed it on your main account there is not risk at all.
 
This kept on happening to me! I explained this to earthonion and frankly he was at a loss to why that was happening... I think there is something about the user accounts thats causing this behaviour... Now, if one has a totally virgin account I'm wondering if the same issue would persist..?

Do you have multiple accounts? I'm using my offact account on an itsPLK backup, so it has two accounts on it. After using the payload, I noticed the console always auto selects the itsPLK profile first even if I haven't used it. (I believe the console is supposed to select the last used profile, but could be wrong).

I tried loading the itsPLK profile, but that isn't signed in either, not sure if the payload has issues with multiple user consoles maybe?
 
Wait it does? I applied the fake-signin and then after a few reboots, it now says I'm signed out, and I can't use ps4 save transfer anymore.
I haven't tried to reapply the payload, so hopefully it still works and doesn't give me an issue, but if it's gonna keep reverting, I'll just wait until I need to transfer saves etc before sending the payload again.
Yes, seems that is not active but is not true, even you cannot do the save transfer, the PS5 think that you are online, and on PS4 is worst, you cannot go to settings if you have a Internet hard-lock on the console.

reverse sign in (sign out):

Settings > Users and Accounts > Other > Sign out

7.61 with m.2. Before etaHEN 2.5 constant KPs when trying to load etaHEN+toolbox from autoloader. as workaround I used the no_kstuff-file and loaded kstuff with a delay of 7sec. Sadly np-fake-signin reintroduced the KPs for me. I managed to get toolbox loading using previous method, but the 'launch itemzflow' option in toolbox remained unusable. After 'np-sign-out' I'm back to near100% successrate: y2jb-etaHEN(kstuff incl.)+toolbox-itemzflow

Don't sure if I understand you, What I know is that you have the winning combination y2jb autoload+etaHEN(kstuff incl.)+toolbox+ np-sign+m.2... so you are having KP randomly I am sure about that..

The only thing that you are in a lower firmware, lucky of that because if you were in FW 10.xx, you will have 3 KP in a row with this wining combination...

All this because np-fake-signin is permanent no matter if you do a singn-off like said the doc...

Anyway there is an easy workaround, create a new user, configure your autoload like before you said that was perfect for you and boot the console with your new user...
That's have to work like before you ran the np-fake-signin..
Post automatically merged:

Do you have multiple accounts? I'm using my offact account on an itsPLK backup, so it has two accounts on it. After using the payload, I noticed the console always auto selects the itsPLK profile first even if I haven't used it. (I believe the console is supposed to select the last used profile, but could be wrong).

I tried loading the itsPLK profile, but that isn't signed in either, not sure if the payload has issues with multiple user consoles maybe?
No, you have the control to set on the console which ones of your user has to login automatically..
 
Another weird thing, I was doing the database edit for y2jb, then like a dumbass I launched a game before rebooting and it corrupted the database. It wiped everything, luckily I had the database on my usb, so I physically restored it and got my games back.

They boot fine and everything. However, as you can see below, some of the games don't have tile icons anymore, included the youtube app on the media tab (which never had the modified y2jb icon despite it being there in the files).

So my question, is there any way to get the icons back? I think they're still there in the files, is there a way to force a kinda refresh or something on the icons?

20260217_223613.jpg
 
Another weird thing, I was doing the database edit for y2jb, then like a dumbass I launched a game before rebooting and it corrupted the database. It wiped everything, luckily I had the database on my usb, so I physically restored it and got my games back.

They boot fine and everything. However, as you can see below, some of the games don't have tile icons anymore, included the youtube app on the media tab (which never had the modified y2jb icon despite it being there in the files).

So my question, is there any way to get the icons back? I think they're still there in the files, is there a way to force a kinda refresh or something on the icons?


Sorry, i got side tracked.. what was your question again? :D

Screenshot 2026-02-18 at 00.50.38.png
 
Sorry, i got side tracked.. what was your question again? :D
Uh, yeah that's my thing I've been working on... I think the custom icon turned out well. That's why a while back I was trying to modify the fullscreen image the ps5 shows, but I never found it's actual location, just the launch screen one.
...and it's a lot more than just a custom icon...
So yeah, it was something about the icons going poof...
 
Last edited by Rasa39,
  • Like
Reactions: BobaFett_UK
np-fake-signin.... Don't get me started on this little exploit.... Sure it may work for some and guess what, it definetly will not work as intended for others! I found that it would revert back by itself... with some boot cycles it was applied then with other boot cycles it was mysteriously reverted! And then there was the constant failures in lapse or the kernel exploit...and yes, ps4 saves were unlocked and i thought yippee.. until i rebooted and zip! I rebuiilt my console probsbly 4 maybe 5 times that week and all i can say is never again!!!

The prerequisites are:

  • Offline activation via offact (account must have a non-zero account ID) >>> THIS WAS PRESENT FOR ME
  • PS4 Payload SDK or PS5 Payload SDK >> I ASSUME I NEEDED TO DO NOTHING HERE
  • HMAC-MD5 key for dat file signing (replace the zeroes in source files with the real key) >>> NO IDEA WHAT THIS MEANS JUST ASSUME I DIDN'T NEED TO DO ANYTHING
Post automatically merged:



Actually, the same was for me... On my 9.20 system i had a PSN account which was activated (np) but usb saves would not work. I'm trying to figure out how i activated it as it was definetly my PSN id with the same hex number and the same avatar. I think i made an image from my 11.60 system which was used for PSN at the time. So when i restored that image to the digital 9.05/9.20 console i had an activated account however the USB saves were not unlocked!
Post automatically merged:


This kept on happening to me! I explained this to earthonion and frankly he was at a loss to why that was happening... I think there is something about the user accounts thats causing this behaviour... Now, if one has a totally virgin account I'm wondering if the same issue would persist..?
Maybe because you use 20 payloads a day 🤣. My hacked ps5 only has one user not 11 😂

My hacked ps4 with activated account via apollo app failed at first for few times to read you ps4 save files from ps5 from ps4 system settings so I just enter and exit that option until it reads ps4 save files from ps5

I didn’t use fake sign payload on ps4 at all.
 
Uh, yeah that's my thing I've been working on... I think the custom icon turned out well. That's why a while back I was trying to modify the fullscreen image the ps5 shows, but I never found it's actual location, just the launch screen one.
...and it's a lot more than just a custom icon...
So yeah, it was something about the icons going poof...
I just thought you had the normal everyday LUA exploit game when I saw the icon.
 
https://github.com/drakmor/ShadowMountPlus/releases/tag/1.5beta2

Completely refactored

  • Working with a large number of folders
  • Eliminating duplicate operations
  • Correct game registration
  • Mounting images as read-only by default
  • Correct unmounting and deleting folders on shutdown/restart
  • The ability to customize folders for scanning
 
Star Wars Outlaws still does not work on 9.20! I tried a backpork and totally messed things up.. The credits load, the cut scene loads but when you get to the actual gameplay it's a pseudo-blank screen where you can move around in open world but you can't see any graphics....other than a few random dots whcih look like dead pixels moving around the screen... Oh you can still hear the audio mind you...

So, is this a job for Backpork Kitchen? Not really cooked pork in a while lol . Too much red meat is bad for you they say lol...
 

Site & Scene News

Popular threads in this forum