Nintendo

Nintendo Is Paying Hackers $20K To Search For Nintendo 3DS Vulnerabilities

Nintendo has launched a new initiative which involves paying hackers up to $20,000 USD for finding major vulnerabilities in the Nintendo 3DS system. The program is called the Nintendo Bug Bounty Program and you can find more information on it, right here.

Nintendo will pay rewards to the first reporter of qualifying vulnerability information ranging from $100 USD to $20,000 USD. Only one reward per qualifying piece of vulnerability information will be awarded. Nintendo will determine at its discretion whether the vulnerability information qualifies for a reward as well as the amount of any such reward. Nintendo does not disclose how the reward amount is calculated. Vulnerability information that is already known to Nintendo or the public, for example, does not qualify for a reward. Rewards will not be issued to individuals who are on sanction lists, or who are in countries on sanction lists.

The reward amount depends on the importance of the information and the quality of the report. In general, the importance of the information is higher if the vulnerability is severe, easy-to-exploit, etc.

A report is evaluated to be high quality if you show that the vulnerability is exploitable by providing a proof of concept (functional exploit code is even better). If you don’t yet have a proof of concept, or functional exploit code, we still encourage you to report to us sooner rather than later such that you do not to lose the opportunity to become the first reporter; you can then submit a proof of concept or functional exploit code later (within three (3) weeks of the initial report) and it will be considered to be a part of the report.

The reward will be paid after the reported vulnerability has been fixed by Nintendo, but no later than four (4) months after Nintendo has confirmed the reported vulnerability.

Nintendo will not disclose to the public the amount of any reward distributed by Nintendo.

Source

Thanks to MasterPikachu6 for the tip

68 comments

  1. ||New orders have been given, it’s time to improve our forces…||

    1. I never got to ask, what are your feelings on the current state of the 2D Mario’s? I mean, what do you make of some of the bad press?

      1. You’ll never get a real answer from Nintendo dating sim accountant tri-axis, but my response is that the recent new super Mario games felt iffy and stale, so I’m glad that they have the Mario maker series on both consoles and handhelds so users can continue making their own innovative versions and create endless material. I feel like the 2d Mario series is in a dead state and if anything they should just press forward with updates adding new content to the Mario maker games.

        1. ||I only respond to those that are civilized and don’t attack at first glimpse like you did way back boy…||

      2. ||The New Super Mario Series are dreadful at their current state, same worlds, same music and same old everything…||

        ||They need new villains and music…||

  2. Google has been using this kind of tactic with Android for a while now and it’s worked out pretty well for them. I’d say this is a good move from Nintendo too. People are going to find vulnerabilities anyway, may as well put those people to work. And if someone finds something having the offer of up to $20k will make people lean more towards giving the info to Nintendo instead of someone else. Who knows, if someone is consistently finding vulnerabilities they could end up with a job offer too I’d wager.

  3. lol, the 3ds has been around for 6 years now. hacking 3ds have been around for… 6 years now.

    the 3ds lifespan is about to end, and just NOW nintendo wants to find its vulnerabilities? if anyone can google “how to hack 3ds” and there are hundreds of websites dedicated to it as well as posting illegal downloads of games… how come Nintendo doesn’t do the same and ask the law to shut it down?

    1. Yeah, I guess I don’t get it either. I really like the idea of working with and paying hackers, but the timing is odd.

      And if the 3DS Is on the way out, they should ease up and let it be hacked for fun and entertainment. :]
      That said, I don’t believe the 3DS will be dead, even when the switch comes out. I’m guessing it has a couple more years left… Somehow.

      And I am going to miss the 3DS terribly. I love the 3D. :( I will be buying one or two extra systems when the prices drop initially. Keep one sealed and game with the other. It really is an amazingly innovative product.

  4. Nintendo will pay rewards to the first reporter of qualifying vulnerability information ranging from $100 USD to $20,000 USD. Only one reward per qualifying piece of vulnerability information will be awarded. Nintendo will determine at its discretion whether the vulnerability information qualifies for a reward as well as the amount of any such reward

    Yeah…right, no guarantee that your exploit is worth jack.

  5. What a bullshit !
    And you ppls here really think that Nifty couldn’t use the same money to pay a real worker to search for exploits ?
    So why they are doing this ?
    To crush ANY human right that hackers are pretending when exploiting the device.
    And you fools scream for “Yea ! Nifty PLEASE take our human rights away from us !”
    How stupid can the mass be ?

    1. Hacking is actually a real job. It’s “cracking” that’s bad. Hackers are actually good for tech. People need to learn the difference between hackers and “crackers.”

    2. “a bullshit”

      “ppls”

      “Nifty”

      “pretending”

      … “Nifty” again

      “mass”

      This is hard to take seriously

  6. no hacker will do this now if they made a region free eshop I maybe willing to aid them but that wont happen so sorry nintendo we are smarter than you think.

    1. free money from Nintendo or free games off the eShop I smart person would go for the money you silly human

      1. And a real hacker would realize the gimmick they are pulling here. Don’t you get it you muppet? They only want to hire the hackers to do that so they can prevent any region free patches in future updates keeping region lock a thing, So use your head before opening that waste of air you call a mouth. End of conversation !

          1. i don’t play a character you little ingrate, I’m a modder and hacker myself so watch your mouth kid. But if you want to live by the rules by all means carry on, Just don’t contaminate this site with your autism! Thank you.

              1. Aww, how cute. Trying to piss me off that’s just adorable! But I won’t waste time trying to reason with you

        1. its people like you that make the internet bad you don’t even know anything because you are nothing but a stupid dumbass robot so you can go take your mom’s dick and suck it bye shitty robot. End of conversation!

          1. Lmao is that really the best insult you got you sad excuse for a troll? learn to write a better taunt before trying to insult me you presumptuous little maggot!

                  1. You my young child are very amusing to say the least. And you’re taking the time to respond to little old me? Wow,I’m honored. And I believe that Sickr is the boss around here so You cannot go saying things like that. please do your research before saying things like that.

                    1. Yea both of you should just stop right now you are doing nothing but spamming the site

  7. Lol this is Nintendo being Nintendo. Always late in the game. In just a few months noone will be using the 3DS anymore because everyone Switched.

        1. I sure did, I couldn’t get my hands on a DS until 2009.
          Not everyone buys new consoles on day one.

  8. How about Nintendo use that money to investigate why the quality of the new 3ds screen is shit, you’re either lucky and find ips screen or get unlucky and have a tn.

  9. I want to laugh about this xDD but at the same time it’s a good but LATE move Nintendo. WAKE UP!

    You know, i would love Gameshark bring back those good times. I want unlimited lives/level up/and inf money in some games. What i don’t support it’s piracy, or playing with clone games.

    and because games right now are not like in the past when you play in hard and obtain some codes Inside the game itself and use it to play on Hard mode or something; that was awesome, a real reward, not stupid achievement things that doesn’t gave me anything for enhanced the gameplay.

    Do you remember those glory days?

    1. ||We are the only ones that still practice those days, the Xbot filth and Sonyan scum are the ones using that flawed and pointless achievement garbage with no real rewards for playing…||

      1. Yes, i don’t care which one, is just the program to hack things that i want. I want to able to CHEAT when I want.
        That doesn’t mean i don’t play without them, i always play videogames at normal/hard difficulty, end the game; and then what? Devs don’t give a shit about a menu with cheat codes so we can have fun in the game, so a Gameshark/Action Replay could be awesome for 3DS/Switch/Wiiu. :(

  10. I don’t understand why people think that Nintendo simply won’t add the Switch to this when it at least comes out. If we want to say “late in the game”, Apple has only started doing this bounty thing a few months ago. And it’s only covering iPhones and iPads (not Macs, watches, or Apple TVs):

    (http://www.theverge.com/2016/8/4/12380036/apple-bug-bounty-program-vulnerability-security)

    They’re only mentioning the 3DS because I don’t think Nintendo thinks it’s worth covering the Wii U, since that one is pretty much on its way out to some extent. So when the Switch comes out, they’ll probably extend the bounty to the Switch after a few months.

  11. Who here thinks this “Nick” Is a butthurt fanboy that thinks Nintendo are doing the right thing? And not understanding that the region free exploit is actually a good thing. Alright piracy is not good for developers but the region free should be implemented as Japan have some very good games that never made it over seas and having the system region free will fix that.

Leave a Reply

%d bloggers like this: