[PSA] User "PokeAcer", who stole a developer's exploit and reported it to Nintendo for money has done the same with NbaYoh's Flipnote 3D exploit as we

TLDR: PokeAcer (who also stole ihaveamac's exploit) stole and reported a new exploit to Nintendo: the yet unreleased Flip Note 3D exploit by MrNbaYoh for userland homebrew on 11.5. The money has already been paid out so it's likely it'll be patched very soon - I highly advice you download it now.

In one of the Flipnote-related Discord chats recently, someone posted a ZIP containing the ugopwn exploit (an exploit for the DSi version of Flip Note), the SHA256 hash matching the one pinned in a certain private Discord server. It became obvious when looking around where it came from - ryanrocks's twitter.

Ryan was asked to take it down, and immediately complied (he also claimed that twitter analytics showed no one saw the tweet, but there's no way to verify that). Around the same time, a GBAtemp thread was posted with the files. At this point, several DCMA requests were filed on the sites to get the files taken down.

The Discord group the files came from only had 8 members, plus it was given to a few people outside of the discord. A total of around 10 people had access to the exploit files, all fairly trustworthy; there was initially no obvious leaker. Everyone was asked to think hard about who might have leaked it and messages were sent out.

Later hints were given that whoever leaked it had posted in the GBAtemp thread. After a bit of thinking we decided to ask PokeAcer (aka Billy Humphreys - this is public information available on his website and Twitter) about it. He eventually admitted to impersonating ryanrocks on Nintendo's HackerOne bug bounty to report this exploit. Eventually, he confessed to stealing the session token of one of the members of the Discord.

He's also admitted to having reported the Flipnote Studio 3D vulnerability to the HackerOne program and recently received a significant amount of money from the report. He's admitted to buying a new Macbook and other accessories with this money.

Additionally, this isn't the first time he's done this. He also reported ihaveamac's browser exploit to Nintendo for a significant amount of money as well, as seen here. Then he had the gall to write an apology post begging for forgiveness saying he'd "apology [for it] until the day [he] dies," then went around and did it again.

Additionally, he says not to judge one of the projects he works on, Project Kaeru (a custom server for Flipnote Studio 3D) as the rest of team doesn't condone his actions, but later on he admitted that he was reading and stealing information from people's notes on the Project Kaeru server.

To sum it up, PokeAcer has stolen three exploits that were not his. Two he reported to Nintendo for profit and one he leaked. He is not to be trusted, and did all this after profusely apologizing for the first time. Please avoid associating and sharing anything sensitive with him unless you want it leaked and/or reported to Nintendo for money.

Until now, this entire post until now has been serious and fact oriented, so allow me to insert some of my opinion here. PokeAcer or Billy, you seem to have some legitimate mental issues. I really hope you get those sorted out, both because you seem like a talented guy, and no one will (or should) trust you right now; but also because I'm seriously concerned about your well being.

Finally screenshots, because no good callout post is complete without proof: http://imgur.com/a/FNUMx
(I'm not the user in any of these screenshots)

EDIT: Archived his twitter, just in case: http://archive.is/JdRwP

DOUBLE EDIT: ihaveamac disclosed the amount that PokeAcer got when he sold his exploit:
[12:21 AM] ihaveahax: the amount was $1,382
Combined with the 2048 dollars from this one, that's a total of 3430 dollars
  • Like
Reactions: 25 people
Status
Not open for further replies.

Comments

User reports Nintendo with exploit info, gets huge wad of cash
Spends cash on an Apple product and not on something useful like Nintendo games

How I weep for the future.
 
For all of you just joining us, here's what this flash mobs comments have consisted of so far:
10% memes
40% people cussing out pokeacer and calling him scum
50% saying "why'd he go blow his money on a MacBook of all things?"
 
  • Like
Reactions: 7 people
I'm wondering how Y'all would react if he did something that actually hurt someone. It's half beautiful and half disturbing.
 
  • Like
Reactions: 2 people
And he is probably gonna make an apology post like this
I-I am so sorry I am a terrible person it was all because of the mafias they wanted money from my parents I had to do it if you harrass me I will report you to FBI I will be sorry till the end of my life and everyday I will make an apology post from my new shiny MacBook but I will probably do it again
-PokeAcer
 
  • Like
Reactions: 10 people
I'm more surprised by people actually defending his actions, I think, curious to say the least. I'm indifferent about it, I admit, but Apple products, lol.
 
@Sonic Angel Knight Nothung you can really do about this. People do this every. With Presidents, Musicians, People like Mj, or just normal people in general.
 
Here's my take on it.

It's a pretty shitty thing to do.
- The original exploit creators get nothing from it
- their exploits are patched so they're now completely useless
- and the kid gets money to blow on stupid shit for himself.

Then the kid does it again, getting access to someone else trustworthy's account, steals more exploits, and cashes them in for more money, having not learned his lesson.

It's a very shitty thing to do to the people who put their time and effort into an exploit they plan to release for free for the community, screwing all of them over, and then getting money for it. That's extremely fucking selfish and it makes my blood boil.
 
  • Like
Reactions: 8 people
Status
Not open for further replies.

Blog entry information

Author
astronautlevel
Views
1,748
Comments
241
Last update
Rating
1.00 star(s) 1 ratings

More entries in Personal Blogs

More entries from astronautlevel

General chit-chat
Help Users
  • No one is chatting at the moment.
    K3Nv2 @ K3Nv2: https://overclock3d.net/news/cases_cooling/cooler-master-had-multi-coloured-ai-cryofuze-5-thermal... +1