[PSA] User "PokeAcer", who stole a developer's exploit and reported it to Nintendo for money has done the same with NbaYoh's Flipnote 3D exploit as we

TLDR: PokeAcer (who also stole ihaveamac's exploit) stole and reported a new exploit to Nintendo: the yet unreleased Flip Note 3D exploit by MrNbaYoh for userland homebrew on 11.5. The money has already been paid out so it's likely it'll be patched very soon - I highly advice you download it now.

In one of the Flipnote-related Discord chats recently, someone posted a ZIP containing the ugopwn exploit (an exploit for the DSi version of Flip Note), the SHA256 hash matching the one pinned in a certain private Discord server. It became obvious when looking around where it came from - ryanrocks's twitter.

Ryan was asked to take it down, and immediately complied (he also claimed that twitter analytics showed no one saw the tweet, but there's no way to verify that). Around the same time, a GBAtemp thread was posted with the files. At this point, several DCMA requests were filed on the sites to get the files taken down.

The Discord group the files came from only had 8 members, plus it was given to a few people outside of the discord. A total of around 10 people had access to the exploit files, all fairly trustworthy; there was initially no obvious leaker. Everyone was asked to think hard about who might have leaked it and messages were sent out.

Later hints were given that whoever leaked it had posted in the GBAtemp thread. After a bit of thinking we decided to ask PokeAcer (aka Billy Humphreys - this is public information available on his website and Twitter) about it. He eventually admitted to impersonating ryanrocks on Nintendo's HackerOne bug bounty to report this exploit. Eventually, he confessed to stealing the session token of one of the members of the Discord.

He's also admitted to having reported the Flipnote Studio 3D vulnerability to the HackerOne program and recently received a significant amount of money from the report. He's admitted to buying a new Macbook and other accessories with this money.

Additionally, this isn't the first time he's done this. He also reported ihaveamac's browser exploit to Nintendo for a significant amount of money as well, as seen here. Then he had the gall to write an apology post begging for forgiveness saying he'd "apology [for it] until the day [he] dies," then went around and did it again.

Additionally, he says not to judge one of the projects he works on, Project Kaeru (a custom server for Flipnote Studio 3D) as the rest of team doesn't condone his actions, but later on he admitted that he was reading and stealing information from people's notes on the Project Kaeru server.

To sum it up, PokeAcer has stolen three exploits that were not his. Two he reported to Nintendo for profit and one he leaked. He is not to be trusted, and did all this after profusely apologizing for the first time. Please avoid associating and sharing anything sensitive with him unless you want it leaked and/or reported to Nintendo for money.

Until now, this entire post until now has been serious and fact oriented, so allow me to insert some of my opinion here. PokeAcer or Billy, you seem to have some legitimate mental issues. I really hope you get those sorted out, both because you seem like a talented guy, and no one will (or should) trust you right now; but also because I'm seriously concerned about your well being.

Finally screenshots, because no good callout post is complete without proof: http://imgur.com/a/FNUMx
(I'm not the user in any of these screenshots)

EDIT: Archived his twitter, just in case: http://archive.is/JdRwP

DOUBLE EDIT: ihaveamac disclosed the amount that PokeAcer got when he sold his exploit:
[12:21 AM] ihaveahax: the amount was $1,382
Combined with the 2048 dollars from this one, that's a total of 3430 dollars
  • Like
Reactions: 25 people
Status
Not open for further replies.

Comments

Blindly trusting someone near something so sensitive really makes me question the scene as a whole. Honestly.
 
  • Like
Reactions: 3 people
Crap, Im a teen and I cant get a job and my family has troubles with me an my medical bills but I don't do this shit. Its stealling others pride and work. I hope his macbook burns him.
 
  • Like
Reactions: 5 people
Made an account here just to add to the "Fuck Pokeacer"
Enjoy your macbook you little shit.
I hope 3430 dollars was worth bringing yourself to the lowest point in the community.
 
  • Like
Reactions: 6 people
Made an account just to bash someone? Whether or not they deserve doesn't change how petty that is.

@kprovost shoulda built a monster Gaming PC
 
  • Like
Reactions: 2 people
Geez, this flash mob is so powerful I can't even navigate parts of the site because I time out when my connection is fine!
 
  • Like
Reactions: 4 people
Out of all the things he spent money on, he got a f*cking Macbook? Really? If I was him, I would spend it on something that can actually play games :lol:
 
  • Like
Reactions: 7 people
I actually agree with Sonic. There are actual problems out in the world.. And you all band together to hate on some alleged teen over this? Eh.
 
  • Like
Reactions: 1 person
Fucking really though, I'd probably buy some more Switch games since I have no money because I'm 14 and then the rest would go to savings like a college fund. I can't believe he wasted his money on a macbook.
 
  • Like
Reactions: 5 people
I can't believe anyone would waste money on a MacBook. I feel like you could do much more.
 
  • Like
Reactions: 4 people
Oh yeah, $3430 combined, I spent $3600 for parts to build a PC completely. Smarter investment than an Apple product. I could've said "overly expensive Apple product," but that would be redundant.
 
  • Like
Reactions: 5 people
Okay, Yes i understand he stole information, that is wrong, yes he should be punished, but insulting someone doesn't solve anything does it? Just shows how bad another person can be when someone else is bad. Does one person being bad mean someone else should be just as bad even if is not on a same level? :unsure:

I'm not defending him, just saying that is unnecessary to just insult him for something that was done. All we can do now is not trust him and make sure to protect our privacy. Let moderators take care of the rest if they feel the need to step into this situation, though I said before, by the looks of the pictures @astronautlevel shared, none of this happened on this site so I dunno if they will have anything to do with it.
 
  • Like
Reactions: 4 people
Status
Not open for further replies.

Blog entry information

Author
astronautlevel
Views
1,649
Comments
241
Last update
Rating
1.00 star(s) 1 ratings

More entries in Personal Blogs

More entries from astronautlevel

General chit-chat
Help Users
    Xdqwerty @ Xdqwerty: Traps