Pre-requisites: Working shoulder buttons; USA/EUR/JPN region; eShop access; movable.sed
- The game "Pokemon Picross" (free on Nintendo eShop)
- movable.sed
- The latest release archive for Luma3DS
- The v1.2 release archive for unSAFE_MODE
- Insert your SD card into your computer
- If you do not see the
.bin
extension, do not add it to the end of the filename
- If you do not see the
- Create a folder named
3ds
on the root of your SD card if it does not already exist- This folder is not the same as the
Nintendo 3DS
folder that you probably already have
- This folder is not the same as the
- Copy
boot.firm
andboot.3dsx
from the Luma3DS.zip
to the root of your SD card - Copy
usm.bin
from the unSAFE_MODE.zip
to the root of your SD card - Copy the otherapp payload for your region/version from the unSAFE_MODE
.zip
'sotherapps_with_CfgS
folder and rename it tootherapp.bin
- Copy the
slotTool
folder from the unSAFE_MODE.zip
to the3ds
folder on your SD card - Put your SD card back into your console
- Open the PicHaxx Injector website on your computer
- Select your
movable.sed
file - Select "Build and Download"
- Wait for the process to complete
- Navigate to
Nintendo 3DS
-><ID0>
-><ID1>
->title
->00040000
->0017c100
->data
on your SD card- The
<ID0>
will be the same one that you specified when bruteforcing yourmovable.sed
- The
<ID1>
is a 32 character long folder inside of the<ID0>
- The
- Copy the newly downloaded
00000001.sav
file to thedata
folder on your SD card- Overwrite the old save file when prompted
- Reinsert your SD card into your device
- Power on your device
- Launch "Pokemon Picross"
- If the exploit was successful, your device will have loaded the Homebrew Launcher
- Launch slotTool from the list of homebrew
- If you get stuck on a red screen, delete
slotTool.xml
from the/3ds/slotTool/
directory, then retry this section
- If you get stuck on a red screen, delete
- Select the "INSTALL exploit to wifi slots 1,2,3 & shutdown" option
- You will see some on-screen text and then your system will shut down
- With your system still powered off, hold the following buttons: (Left Shoulder) + (Right Shoulder) + (D-Pad Up) + (A), then press (Power)
- Keep holding the buttons until the console boots into Safe Mode
- Press "OK" to accept the update
- There is no update. This is part of the exploit
- Press "I accept" to accept the terms and conditions
- The update will eventually fail, with error code
003-1099
. This is intended behaviour - When asked "Would you like to configure Internet settings?", select "Yes"
- On the following menu, navigate to
Connection 1
->Change Settings
->Next Page (right arrow)
->Proxy Settings
->Detailed Setup
- Here is a visual representation
- Once you see
B9S install SUCCESS
on the top screen, press any button to reboot to Luma Configuration
- Your device should automatically show the Luma Configuration menu
- Use the (A) button and the D-Pad to turn on the following:
- "Show NAND or user string in System Settings"
- Press (Start) to save and reboot
- Your device should load the Home Menu after a short delay
- Launch the Download Play application
- Wait until you see the two buttons
- Do not press either of the buttons
- Press (Left Shoulder) + (D-Pad Down) + (Select) at the same time to open the Rosalina menu
- Select "Miscellaneous options"
- Select "Switch the hb. title to the current app."
- Press (B) to continue
- Press (B) to return to the Rosalina main menu
- Press (B) to exit the Rosalina menu
- Press (Home), then close Download Play
- Relaunch the Download Play application
- Your device should load the Homebrew Launcher
- Launch slotTool from the list of homebrew
- Select "RESTORE original wifi slots 1,2,3"
- Your device will then reboot