[PSA] User "PokeAcer", who stole a developer's exploit and reported it to Nintendo for money has done the same with NbaYoh's Flipnote 3D exploit as we

TLDR: PokeAcer (who also stole ihaveamac's exploit) stole and reported a new exploit to Nintendo: the yet unreleased Flip Note 3D exploit by MrNbaYoh for userland homebrew on 11.5. The money has already been paid out so it's likely it'll be patched very soon - I highly advice you download it now.

In one of the Flipnote-related Discord chats recently, someone posted a ZIP containing the ugopwn exploit (an exploit for the DSi version of Flip Note), the SHA256 hash matching the one pinned in a certain private Discord server. It became obvious when looking around where it came from - ryanrocks's twitter.

Ryan was asked to take it down, and immediately complied (he also claimed that twitter analytics showed no one saw the tweet, but there's no way to verify that). Around the same time, a GBAtemp thread was posted with the files. At this point, several DCMA requests were filed on the sites to get the files taken down.

The Discord group the files came from only had 8 members, plus it was given to a few people outside of the discord. A total of around 10 people had access to the exploit files, all fairly trustworthy; there was initially no obvious leaker. Everyone was asked to think hard about who might have leaked it and messages were sent out.

Later hints were given that whoever leaked it had posted in the GBAtemp thread. After a bit of thinking we decided to ask PokeAcer (aka Billy Humphreys - this is public information available on his website and Twitter) about it. He eventually admitted to impersonating ryanrocks on Nintendo's HackerOne bug bounty to report this exploit. Eventually, he confessed to stealing the session token of one of the members of the Discord.

He's also admitted to having reported the Flipnote Studio 3D vulnerability to the HackerOne program and recently received a significant amount of money from the report. He's admitted to buying a new Macbook and other accessories with this money.

Additionally, this isn't the first time he's done this. He also reported ihaveamac's browser exploit to Nintendo for a significant amount of money as well, as seen here. Then he had the gall to write an apology post begging for forgiveness saying he'd "apology [for it] until the day [he] dies," then went around and did it again.

Additionally, he says not to judge one of the projects he works on, Project Kaeru (a custom server for Flipnote Studio 3D) as the rest of team doesn't condone his actions, but later on he admitted that he was reading and stealing information from people's notes on the Project Kaeru server.

To sum it up, PokeAcer has stolen three exploits that were not his. Two he reported to Nintendo for profit and one he leaked. He is not to be trusted, and did all this after profusely apologizing for the first time. Please avoid associating and sharing anything sensitive with him unless you want it leaked and/or reported to Nintendo for money.

Until now, this entire post until now has been serious and fact oriented, so allow me to insert some of my opinion here. PokeAcer or Billy, you seem to have some legitimate mental issues. I really hope you get those sorted out, both because you seem like a talented guy, and no one will (or should) trust you right now; but also because I'm seriously concerned about your well being.

Finally screenshots, because no good callout post is complete without proof: http://imgur.com/a/FNUMx
(I'm not the user in any of these screenshots)

EDIT: Archived his twitter, just in case: http://archive.is/JdRwP

DOUBLE EDIT: ihaveamac disclosed the amount that PokeAcer got when he sold his exploit:
[12:21 AM] ihaveahax: the amount was $1,382
Combined with the 2048 dollars from this one, that's a total of 3430 dollars
  • Like
Reactions: 25 people
Status
Not open for further replies.

Comments

This mob mentality though. Hm. Also, how did he get access to the user's discord token? Hm.
 
@jupiteer - the vomiting? That's me, different user name. I just felt more inspired to go long winded here. Is he really 14 though? I can see pointing out the age as an indication of his poor, immature character, but I just think pure scum is scum regardless of age.
 
  • Like
Reactions: 1 person
I would have forgiven him but he had to go out and blow his money on a macbook. A macbook. Literally the most overpriced underpowered computer out there. He could have gotten something great. Nope. He gets a fucking mac.
 
  • Like
Reactions: 16 people
This is where I slam my head into a table. Why mate..
I almost feel like you bought a Mac just for the irony of it. AT LEAST BUY SOME CHIPS WITH IT (Inside joke heh)
 
  • Like
Reactions: 2 people
He stole someone's discord user token to report two exploits to Nintendo. I don't care how what his age is, that's unforgivable.
 
  • Like
Reactions: 10 people
How did he get access to the token?

Stupid is as stupid does. Still some undefined here.
 
  • Like
Reactions: 1 person
He released a trojan horse BetterDiscord plugin which sent the token of anyone who installed it to him. This included people in the private chat
 
  • Like
Reactions: 13 people
Two wrongs don't make a right, being a goody two-shoes after stealing personally identifiable information is a douche move no matter who it is or what their reasons are. This can only end badly for the perp.
 
  • Like
Reactions: 2 people
People insulting him are not being any much better than he is, please stop doing that. It was done and we are aware of it. Not saying he should be left without consequences of stealing but don't start becoming worst than what you was prior to this problem before it begins.

Don't treat this like a salem witch trial and try burning him at the steak. Just don't associate with him if you "strongly dislike him." Why does it have to turn into some hate crime?

@astronautlevel thank you for bringing this to our attention and I will consider being more careful with things I share online. I don't know the person personally nor talk as much as you have, but sorry he has hurt you and some others in the "scene" I hope things are resolved. :(
 
Status
Not open for further replies.

Blog entry information

Author
astronautlevel
Views
1,718
Comments
241
Last update
Rating
1.00 star(s) 1 ratings

More entries in Personal Blogs

More entries from astronautlevel

General chit-chat
Help Users
  • Xdqwerty @ Xdqwerty:
    dualbooth
  • SylverReZ @ SylverReZ:
    @Xdqwerty, Yeah, I'd recommend having another OS just in-case you want to play games.
  • SylverReZ @ SylverReZ:
    At least Linux doesn't contain spyware than what Windows has.
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, cuz of lag?
  • SylverReZ @ SylverReZ:
    @Xdqwerty, No. Whenever you use the internet on Windows, Microsoft collects personal data and installs bloatware that isn't necessarily needed, such as Edge.
  • SylverReZ @ SylverReZ:
    Speaking of which
  • Xdqwerty @ Xdqwerty:
    @SylverReZ,
    I recall @impeeza mentioned some trick about not having bloatware when installing windows where you set up your country to "world" or smh like that
    +1
  • SylverReZ @ SylverReZ:
    Yes, you can debloat the operating system, but in some cases for me it just reinstalls them.
    +1
  • Xdqwerty @ Xdqwerty:
    @SylverReZ,
    I also recall my brother downloded a "non bloated" version of windows 11 on his pc
    +1
  • BigOnYa @ BigOnYa:
    "Why debloat? Why not embrace and enjoy my bloat?" - Gates
    +3
  • impeeza @ impeeza:
    @Xdqwerty yes, when you are installing Windows on the first steps you are asked for your current location, you MUST to select «international» so no bloatware is installed, because the bloatware is location based. if this night I have some time I will setup a VM and take screenshots.
    +2
  • BigOnYa @ BigOnYa:
    User Gates "Disliked" your answer.
    +3
  • Psionic Roshambo @ Psionic Roshambo:
    Damn cleaned up 348GB's of crap I wasn't using with that lol
    +2
  • BigOnYa @ BigOnYa:
    But can it completely remove RealPlayer? Lol jk
    +2
  • Psionic Roshambo @ Psionic Roshambo:
    I remember at one point it being pretty much labeled as malware lol
  • Psionic Roshambo @ Psionic Roshambo:
    I think my favorite one was that dancing purple gorilla... I uninstalled that thing from sooo many machine people would be like "Why is my computer so slow?" lol because this thing is using like 30% of your system resources.....
  • Psionic Roshambo @ Psionic Roshambo:
    This one lady... her son kept installing Kazaa... OK no problem the issue is he would download DBZ movies and they where amazing usually like 2-8KB in size lol can't remember how many times I had to format and reinstall windows over his stupidity. I even explained to him about file sizes multiple times...
  • Psionic Roshambo @ Psionic Roshambo:
    yeah Bonzi buddy was malware sort of... It was borderline lol
  • Psionic Roshambo @ Psionic Roshambo:
    At minimum it was nothing anyone should have ever installed lol
    +1
    Psionic Roshambo @ Psionic Roshambo: At minimum it was nothing anyone should have ever installed lol +1