[PSA] User "PokeAcer", who stole a developer's exploit and reported it to Nintendo for money has done the same with NbaYoh's Flipnote 3D exploit as we

TLDR: PokeAcer (who also stole ihaveamac's exploit) stole and reported a new exploit to Nintendo: the yet unreleased Flip Note 3D exploit by MrNbaYoh for userland homebrew on 11.5. The money has already been paid out so it's likely it'll be patched very soon - I highly advice you download it now.

In one of the Flipnote-related Discord chats recently, someone posted a ZIP containing the ugopwn exploit (an exploit for the DSi version of Flip Note), the SHA256 hash matching the one pinned in a certain private Discord server. It became obvious when looking around where it came from - ryanrocks's twitter.

Ryan was asked to take it down, and immediately complied (he also claimed that twitter analytics showed no one saw the tweet, but there's no way to verify that). Around the same time, a GBAtemp thread was posted with the files. At this point, several DCMA requests were filed on the sites to get the files taken down.

The Discord group the files came from only had 8 members, plus it was given to a few people outside of the discord. A total of around 10 people had access to the exploit files, all fairly trustworthy; there was initially no obvious leaker. Everyone was asked to think hard about who might have leaked it and messages were sent out.

Later hints were given that whoever leaked it had posted in the GBAtemp thread. After a bit of thinking we decided to ask PokeAcer (aka Billy Humphreys - this is public information available on his website and Twitter) about it. He eventually admitted to impersonating ryanrocks on Nintendo's HackerOne bug bounty to report this exploit. Eventually, he confessed to stealing the session token of one of the members of the Discord.

He's also admitted to having reported the Flipnote Studio 3D vulnerability to the HackerOne program and recently received a significant amount of money from the report. He's admitted to buying a new Macbook and other accessories with this money.

Additionally, this isn't the first time he's done this. He also reported ihaveamac's browser exploit to Nintendo for a significant amount of money as well, as seen here. Then he had the gall to write an apology post begging for forgiveness saying he'd "apology [for it] until the day [he] dies," then went around and did it again.

Additionally, he says not to judge one of the projects he works on, Project Kaeru (a custom server for Flipnote Studio 3D) as the rest of team doesn't condone his actions, but later on he admitted that he was reading and stealing information from people's notes on the Project Kaeru server.

To sum it up, PokeAcer has stolen three exploits that were not his. Two he reported to Nintendo for profit and one he leaked. He is not to be trusted, and did all this after profusely apologizing for the first time. Please avoid associating and sharing anything sensitive with him unless you want it leaked and/or reported to Nintendo for money.

Until now, this entire post until now has been serious and fact oriented, so allow me to insert some of my opinion here. PokeAcer or Billy, you seem to have some legitimate mental issues. I really hope you get those sorted out, both because you seem like a talented guy, and no one will (or should) trust you right now; but also because I'm seriously concerned about your well being.

Finally screenshots, because no good callout post is complete without proof: http://imgur.com/a/FNUMx
(I'm not the user in any of these screenshots)

EDIT: Archived his twitter, just in case: http://archive.is/JdRwP

DOUBLE EDIT: ihaveamac disclosed the amount that PokeAcer got when he sold his exploit:
[12:21 AM] ihaveahax: the amount was $1,382
Combined with the 2048 dollars from this one, that's a total of 3430 dollars
  • Like
Reactions: 25 people
Status
Not open for further replies.

Comments

How is this possible? The exploit is known by the public, therefore is invalid in the exploit reporting. Nintendo stated that you need to prove that the exploit isn't knowned by the public.
 
  • Like
Reactions: 6 people
G
my favorite part has to be:
PokeAcer: I got it
Anonymous: ?
PokeAcer: The $2048
PokeAcer: I'm getting a mac

not only did he do it again, he bought a mac with the money
 
  • Like
Reactions: 20 people
You want my honest opinion? Trust no one. I've said it in the other post. The dev scene is messed up. Also "stolen" isn't entirely the right word here.. Not for the money anyway.
 
  • Like
Reactions: 4 people
@blujay and he bought a switch with the money he stole from ihaveamac

@Memoir this time no one gave him an exploit, he stole someone's discord user token to get access to it.
 
  • Like
Reactions: 6 people
About an hour ago I vomited a significant portion of the dinner I myself made. I must say this is more disgusting than that puke, and in one way makes me feel better physically, you know how one thing cancels out another? Yeah, this cancels out the fatigue and uneasiness from vomiting (for the most part). In the other way, it makes me feel horrible and take back what I said in that apologetic blog post, which was basically "It's the past, what he did was wrong, blah blah blah." To go and do this after that sobfest, just, disgusting. But, I do wonder if this person does actually have a mental disorder, but I'm cynical and just find him to be as big a fraud as...Martin Shkreli. Guess what happened to him recently, today in fact? Convicted on multiple counts of securities fraud. Fraud. @PokeAcer is a fucking fraud. Something about that sickens me as much as the general celebrity Jesus figures (Kanye West and Justin Bieber), and with Shkreli, I know what he looks like. Thus I can imagine punching him in the face, that body part is just so punchable, even warrants getting dog shit thrown at, which did actually happen to the fucker. PokeAcer now joins that very exclusive class for me.

Without this blog post, it could've very well been a cyclical thing, he does reprehensible shit, apologizes and asks for no judgement to be cast, does reprehensible shit again, apologizes and asks for no judgement to be cast again. Someone thankfully gave a strong case of breaking what could've been a cycle. Kind of goes into "No honor among thieves," since hackers that discover these exploits, are, to us, Robin Hood style thieves. Here's the snake, here's Jafar. Sigh.
 
  • Like
Reactions: 8 people
G
Until now, this entire post until now has been serious and fact oriented, so allow me to insert some of my opinion here. PokeAcer or Billy, you seem to have some legitimate mental issues. I really hope you get those sorted out, both because you seem like a talented guy, and no one will (or should) trust you right now; but also because I'm seriously concerned about your well being.

I'm leaving the online world, and I love you all. Yes, I am messed up, and thank you for being concerned about me, but I no longer know what to do. I'm going to be hated for life now, and I'm going to never get that away from me. I love this community, and you can all hate me.
<3
 
  • Like
Reactions: 1 person
Status
Not open for further replies.

Blog entry information

Author
astronautlevel
Views
1,621
Comments
241
Last update
Rating
1.00 star(s) 1 ratings

More entries in Personal Blogs

More entries from astronautlevel

General chit-chat
Help Users
    K3Nv2 @ K3Nv2: https://youtube.com/shorts/NGOSybO-5R4?si=SmiQ0UaynHR80xC9