[PSA] User "PokeAcer", who stole a developer's exploit and reported it to Nintendo for money has done the same with NbaYoh's Flipnote 3D exploit as we

TLDR: PokeAcer (who also stole ihaveamac's exploit) stole and reported a new exploit to Nintendo: the yet unreleased Flip Note 3D exploit by MrNbaYoh for userland homebrew on 11.5. The money has already been paid out so it's likely it'll be patched very soon - I highly advice you download it now.

In one of the Flipnote-related Discord chats recently, someone posted a ZIP containing the ugopwn exploit (an exploit for the DSi version of Flip Note), the SHA256 hash matching the one pinned in a certain private Discord server. It became obvious when looking around where it came from - ryanrocks's twitter.

Ryan was asked to take it down, and immediately complied (he also claimed that twitter analytics showed no one saw the tweet, but there's no way to verify that). Around the same time, a GBAtemp thread was posted with the files. At this point, several DCMA requests were filed on the sites to get the files taken down.

The Discord group the files came from only had 8 members, plus it was given to a few people outside of the discord. A total of around 10 people had access to the exploit files, all fairly trustworthy; there was initially no obvious leaker. Everyone was asked to think hard about who might have leaked it and messages were sent out.

Later hints were given that whoever leaked it had posted in the GBAtemp thread. After a bit of thinking we decided to ask PokeAcer (aka Billy Humphreys - this is public information available on his website and Twitter) about it. He eventually admitted to impersonating ryanrocks on Nintendo's HackerOne bug bounty to report this exploit. Eventually, he confessed to stealing the session token of one of the members of the Discord.

He's also admitted to having reported the Flipnote Studio 3D vulnerability to the HackerOne program and recently received a significant amount of money from the report. He's admitted to buying a new Macbook and other accessories with this money.

Additionally, this isn't the first time he's done this. He also reported ihaveamac's browser exploit to Nintendo for a significant amount of money as well, as seen here. Then he had the gall to write an apology post begging for forgiveness saying he'd "apology [for it] until the day [he] dies," then went around and did it again.

Additionally, he says not to judge one of the projects he works on, Project Kaeru (a custom server for Flipnote Studio 3D) as the rest of team doesn't condone his actions, but later on he admitted that he was reading and stealing information from people's notes on the Project Kaeru server.

To sum it up, PokeAcer has stolen three exploits that were not his. Two he reported to Nintendo for profit and one he leaked. He is not to be trusted, and did all this after profusely apologizing for the first time. Please avoid associating and sharing anything sensitive with him unless you want it leaked and/or reported to Nintendo for money.

Until now, this entire post until now has been serious and fact oriented, so allow me to insert some of my opinion here. PokeAcer or Billy, you seem to have some legitimate mental issues. I really hope you get those sorted out, both because you seem like a talented guy, and no one will (or should) trust you right now; but also because I'm seriously concerned about your well being.

Finally screenshots, because no good callout post is complete without proof: http://imgur.com/a/FNUMx
(I'm not the user in any of these screenshots)

EDIT: Archived his twitter, just in case: http://archive.is/JdRwP

DOUBLE EDIT: ihaveamac disclosed the amount that PokeAcer got when he sold his exploit:
[12:21 AM] ihaveahax: the amount was $1,382
Combined with the 2048 dollars from this one, that's a total of 3430 dollars
  • Like
Reactions: 25 people
Status
Not open for further replies.

Comments

This mob mentality though. Hm. Also, how did he get access to the user's discord token? Hm.
 
@jupiteer - the vomiting? That's me, different user name. I just felt more inspired to go long winded here. Is he really 14 though? I can see pointing out the age as an indication of his poor, immature character, but I just think pure scum is scum regardless of age.
 
  • Like
Reactions: 1 person
I would have forgiven him but he had to go out and blow his money on a macbook. A macbook. Literally the most overpriced underpowered computer out there. He could have gotten something great. Nope. He gets a fucking mac.
 
  • Like
Reactions: 16 people
This is where I slam my head into a table. Why mate..
I almost feel like you bought a Mac just for the irony of it. AT LEAST BUY SOME CHIPS WITH IT (Inside joke heh)
 
  • Like
Reactions: 2 people
He stole someone's discord user token to report two exploits to Nintendo. I don't care how what his age is, that's unforgivable.
 
  • Like
Reactions: 10 people
How did he get access to the token?

Stupid is as stupid does. Still some undefined here.
 
  • Like
Reactions: 1 person
He released a trojan horse BetterDiscord plugin which sent the token of anyone who installed it to him. This included people in the private chat
 
  • Like
Reactions: 13 people
Two wrongs don't make a right, being a goody two-shoes after stealing personally identifiable information is a douche move no matter who it is or what their reasons are. This can only end badly for the perp.
 
  • Like
Reactions: 2 people
People insulting him are not being any much better than he is, please stop doing that. It was done and we are aware of it. Not saying he should be left without consequences of stealing but don't start becoming worst than what you was prior to this problem before it begins.

Don't treat this like a salem witch trial and try burning him at the steak. Just don't associate with him if you "strongly dislike him." Why does it have to turn into some hate crime?

@astronautlevel thank you for bringing this to our attention and I will consider being more careful with things I share online. I don't know the person personally nor talk as much as you have, but sorry he has hurt you and some others in the "scene" I hope things are resolved. :(
 
Status
Not open for further replies.

Blog entry information

Author
astronautlevel
Views
1,794
Comments
241
Last update
Rating
1.00 star(s) 1 ratings

More entries in Personal Blogs

More entries from astronautlevel

Share this entry

General chit-chat
Help Users
  • Sicklyboy @ Sicklyboy:
    I used to drink alcohol fairly often. Never to the point of it being a problem, but like 2-3 beers with dinner each night, or a few cocktails or glasses of Scotch or something. Started smoking/vaping weed a lot a few years back which killed 90% of my interest in booze. Now I stopped smoking/vaping weed as much and just deal with life the boring way most of the time
    +1
  • Xdqwerty @ Xdqwerty:
    I only drank alcohol once and it was by accident
  • Xdqwerty @ Xdqwerty:
    I didnt know it was beer, it was on a juice bottle
  • SylverReZ @ SylverReZ:
    Yeah, I'm addicted to smoking, sadly. It's very addictive but I wish I didn't start.
  • K3Nv2 @ K3Nv2:
    May just order a 5700g for a nas/emulation set up tbh
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, atleast you were asleep on 4/20
    +1
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, you played that Mario flash game called Mario 63?
  • SylverReZ @ SylverReZ:
    @Xdqwerty, No, but I've seen it on Vinesauce's stream.
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, that game is one of the reasons i met newgrounds bc the full versión of it is in that site
  • Xdqwerty @ Xdqwerty:
    Also somebody is remaking it
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, the other game where I found newgrounds is new york shark
    +1
  • SylverReZ @ SylverReZ:
    Spoke to Tom Fulp the other day, if he can find his old Newgrounds site content like the mini Flash animations from the 2000's that played on the portal.
  • SylverReZ @ SylverReZ:
    So far no response, but he did say that he'll find them. Wayback Machine doesn't have em.
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, atleast the 1999 versión of pico's school is avaliable (the difference between it, the 2006 versión and the 2016 versión is that the speed of the game depends of the speed of your computer and that it had the og soundtrack)
  • SylverReZ @ SylverReZ:
    @Xdqwerty, Another being Pico VS Bear, the original 1999 version before Jim Henson filed a DMCA takedown.
    +1
  • Xdqwerty @ Xdqwerty:
    The 2006 versión was made when the flash portal was made
  • SylverReZ @ SylverReZ:
    Many people thought it was lost, but was discovered that he hid it on the same page.
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, although the "secrets" system where the game was has been removed. Also pico vs uberkids had a netplay versión that was shutdown, although the swf file has been found
  • SylverReZ @ SylverReZ:
    @Xdqwerty, Nope. There are two download buttons on the same page, where you can download the original under a file called "bear.exe". "bear2.exe", however, is the updated game in a Flash projector. P.s. this was on the archived Pico page from 2000.
  • SylverReZ @ SylverReZ:
    @Xdqwerty, That's been there for a long time, too. People who search for lost media don't look hard enough lmao.
    +1
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, also the pico 2 demos used to be only for the newgrounds patrons but they are on internet archive too (https://archive.org/download/picos_school_2)
    +1
  • Xdqwerty @ Xdqwerty:
    Iirc the demos were removed from newgrounds in 2022
    Xdqwerty @ Xdqwerty: Iirc the demos were removed from newgrounds in 2022