TimoVMs ACE GuidesThis video guide demonstrates a newly developed arbitrary code execution (ACE) setup for the English releases of Pokémon Crystal. This can be performed right after first obtaining Poké Balls with very little material requirements.
This setup can be performed on cartridge, virtual console and most competent emulators such as BGB, Mesen, mGBA and Delta. Please note that the setup does not work when the game is played via the GB tower in pokémon stadium due to emulation inaccuracies.
Arbitrary Code Execution (ACE) occurs when glitches cause the game to start executing code in areas of RAM memory that can be manipulated by the player. Essentially, this allows us to write and execute our own code, allowing us to achieve various exotic effects that would normally be impossible without the use of a cheating device.
Applications include, but are not limited to: - Directly editing pokémon data - Giving yourself any item at any quantity - Edit player attributes such as name, gender, story progression, etc. - Force trade evolutions to occur without trading - Reset static encounters - Set up more persistent effect, such as the use of a run button and allowing walk through walls. - and many more
In this video guide, I won't just demonstrate how to set up your first ACE execution, I'll also guide you on the process to install a 50-byte program (written using TM quantities) that is capable of quickly writing and execute any code. In essence, you will be installing a cheat engine. Lastly I'll guide you through the cleanup process, allowing you to use this program without any party/item/box name/TM count requirements.
Useful links:
- The written version of this guide can be found at https://glitchcity.wiki/wiki/Guides:Fast_0x1500_ACE - Additional mail codes can be found at https://glitchcity.wiki/wiki/Guides:Mail_Writer_Codes - Instructions on how to activate the clock reset debug function, as well as a calculator that can generate the required password, can be found at bl4cksh4rk.github.io/Pokemon-GSC-Clock-Password-Generator - Guides for other languages and versions of gen 2 can be found linked at https://glitchcity.wiki/wiki/Guides:TimoVM%27s_gen_2_ACE_setups
If you're interested, feel free to also check out the modernized setups I made for Red, Blue and Yellow, which can be found at https://glitchcity.wiki/wiki/Guides:TimoVM%27s_gen_1_ACE_setups
If you need support when following this guide, you can always contact me via the Glitch City Research Institute discord linked here: discord.gg/EA7jxJ6
Frequently asked questions:
- I've gotten a bad clone, but its name shows up as blank instead of showing a bunch of question marks.
This issue is likely caused by usage of older versions of PKHex, which used to overwrite unused nicknames with text terminators, making it impossible to obtain unnamed clones. To revolve this, put any pokémon with a nickname consisting of 10 characters into party slot 1, then use gameshark code 01004BDE. This overwrites the text terminator right at the end of the name, allowing party pokémon 1 to act as an unnamed clone.
Acknowledgements:
Thanks to LuckyTyphlosion, who initially documented 0x1500 control code ACE alongside developing an early rough setup outline.
Thanks to Flag3 and other members of the JP glitching community, whose guides not only lead to several improvements in this guide, but also demonstrated the full potential of more complicated ACE setups.
Thanks to diabl0w. for inspiring me to develop several improvements in the NickWriter's code, making it both shorter and more functional.
Thanks to Popcorn, ShinySkitty and Rebsillycon for reviewing the video and providing feedback that allowed me to fully polish up the guide.
Thanks to the Glitch City Research Institute for both hosting my written guide and for providing feedback and support during the development of these guides.
Special thanks to What is Life Anyways?, SlimeSpawner, Popcorn and Plushie for providing valuable feedback and corrections.
Thanks to the Glitch City Research Institute Discord for support and feedback, as well as hosting my written guides on the wiki.
00:00 Intro 01:19 Part 1: Gathering all the requirements 03:00 Part 2: Getting an unnamed clone 04:21 Part 3: Setting up initial ACE 10:27 Part 4: Installing a program by selling TMs 18:59 Part 5: Using mail codes 20:35 Part 6: Using other codes 24:28 Final notes and acknowledgements
Pokémon Crystal: Using arbitrary code execution glitches to quickly set up a powerful cheat engineTimoVMs ACE Guides2024-06-05 | This video guide demonstrates a newly developed arbitrary code execution (ACE) setup for the English releases of Pokémon Crystal. This can be performed right after first obtaining Poké Balls with very little material requirements.
This setup can be performed on cartridge, virtual console and most competent emulators such as BGB, Mesen, mGBA and Delta. Please note that the setup does not work when the game is played via the GB tower in pokémon stadium due to emulation inaccuracies.
Arbitrary Code Execution (ACE) occurs when glitches cause the game to start executing code in areas of RAM memory that can be manipulated by the player. Essentially, this allows us to write and execute our own code, allowing us to achieve various exotic effects that would normally be impossible without the use of a cheating device.
Applications include, but are not limited to: - Directly editing pokémon data - Giving yourself any item at any quantity - Edit player attributes such as name, gender, story progression, etc. - Force trade evolutions to occur without trading - Reset static encounters - Set up more persistent effect, such as the use of a run button and allowing walk through walls. - and many more
In this video guide, I won't just demonstrate how to set up your first ACE execution, I'll also guide you on the process to install a 50-byte program (written using TM quantities) that is capable of quickly writing and execute any code. In essence, you will be installing a cheat engine. Lastly I'll guide you through the cleanup process, allowing you to use this program without any party/item/box name/TM count requirements.
Useful links:
- The written version of this guide can be found at https://glitchcity.wiki/wiki/Guides:Fast_0x1500_ACE - Additional mail codes can be found at https://glitchcity.wiki/wiki/Guides:Mail_Writer_Codes - Instructions on how to activate the clock reset debug function, as well as a calculator that can generate the required password, can be found at bl4cksh4rk.github.io/Pokemon-GSC-Clock-Password-Generator - Guides for other languages and versions of gen 2 can be found linked at https://glitchcity.wiki/wiki/Guides:TimoVM%27s_gen_2_ACE_setups
If you're interested, feel free to also check out the modernized setups I made for Red, Blue and Yellow, which can be found at https://glitchcity.wiki/wiki/Guides:TimoVM%27s_gen_1_ACE_setups
If you need support when following this guide, you can always contact me via the Glitch City Research Institute discord linked here: discord.gg/EA7jxJ6
Frequently asked questions:
- I've gotten a bad clone, but its name shows up as blank instead of showing a bunch of question marks.
This issue is likely caused by usage of older versions of PKHex, which used to overwrite unused nicknames with text terminators, making it impossible to obtain unnamed clones. To revolve this, put any pokémon with a nickname consisting of 10 characters into party slot 1, then use gameshark code 01004BDE. This overwrites the text terminator right at the end of the name, allowing party pokémon 1 to act as an unnamed clone.
Acknowledgements:
Thanks to LuckyTyphlosion, who initially documented 0x1500 control code ACE alongside developing an early rough setup outline.
Thanks to Flag3 and other members of the JP glitching community, whose guides not only lead to several improvements in this guide, but also demonstrated the full potential of more complicated ACE setups.
Thanks to diabl0w. for inspiring me to develop several improvements in the NickWriter's code, making it both shorter and more functional.
Thanks to Popcorn, ShinySkitty and Rebsillycon for reviewing the video and providing feedback that allowed me to fully polish up the guide.
Thanks to the Glitch City Research Institute for both hosting my written guide and for providing feedback and support during the development of these guides.
Special thanks to What is Life Anyways?, SlimeSpawner, Popcorn and Plushie for providing valuable feedback and corrections.
Thanks to the Glitch City Research Institute Discord for support and feedback, as well as hosting my written guides on the wiki.
00:00 Intro 01:19 Part 1: Gathering all the requirements 03:00 Part 2: Getting an unnamed clone 04:21 Part 3: Setting up initial ACE 10:27 Part 4: Installing a program by selling TMs 18:59 Part 5: Using mail codes 20:35 Part 6: Using other codes 24:28 Final notes and acknowledgementsPokémon Gold/Silver: Using the Coin Case Glitch to set up a cheat engineTimoVMs ACE Guides2024-09-08 | This video guide demonstrates a newly developed arbitrary code execution (ACE) setup for the English releases of Pokémon Gold & Silver. This can be performed right after reaching Goldenrod City, which requires obtaining at least two badges.
This setup can be performed on cartridge, virtual console and most competent emulators such as BGB, Mesen, mGBA and Delta. Please note that the setup does not work when the game is played via the GB tower in pokémon stadium due to emulation inaccuracies.
Arbitrary Code Execution (ACE) occurs when glitches cause the game to start executing code in areas of RAM memory that can be manipulated by the player. Essentially, this allows us to write and execute our own code, allowing us to achieve various exotic effects that would normally be impossible without the use of a cheating device.
Within this video I'll demonstrate the usage of the Coin Case Glitch. This glitch is exclusive to the English releases of Gold & Silver. Due to a translation error, using the Coin Case always causes the game to execute code in a region that buffers sound data. By carefully setting up buffered sound data, buffered tile data and buffered mail data, we can redirect this effect to execute box names as if they're code.
In this video guide, I won't just demonstrate how to set up your first ACE execution, I'll then guide you on the process to install a 50-byte program (written using TM quantities) that is capable of quickly writing and execute any code. In essence, you will be installing the equivalent of a cheat engine. Lastly, I'll guide you through the cleanup process, allowing you to use this program without any party/item/box name/TM count requirements.
Applications include, but are not limited to: - Directly editing pokémon data - Giving yourself any item at any quantity - Edit player attributes such as name, gender, story progression, etc. - Force trade evolutions to occur without trading - Reset static encounters - Set up more persistent effect, such as the use of a run button and allowing walk through walls. - And many more
Useful links:
- The written version of this guide can be found at https://glitchcity.wiki/wiki/Guides:Coin_Case_ACE - Additional mail codes can be found at https://glitchcity.wiki/wiki/Guides:Mail_Writer_Codes - Guides for other languages and versions of gen 2 can be found linked at https://glitchcity.wiki/wiki/Guides:TimoVM%27s_gen_2_ACE_setups
If you're interested, feel free to also check out the modernized setups I made for Red, Blue and Yellow, which can be found at https://glitchcity.wiki/wiki/Guides:TimoVM%27s_gen_1_ACE_setups
If you need support when following this guide, you can always contact me via the Glitch City Research Institute discord linked here: discord.gg/EA7jxJ6
Acknowledgements:
Thanks to Crystal_, who initially documented an advanced Coin Case Glitch setup for Gold & Silver. This video guide is what inspired me to look into ACE glitches in pokémon games, which eventually led to me developing completely new ACE setups.
Thanks to Flag3 and other members of the JP glitching community, whose guides not only lead to several improvements in this guide, but also demonstrated the full potential of more complicated ACE setups.
Thanks to Popcorn, Rebsillycon and Plushie for reviewing the video and providing feedback that allowed me to fully polish up the guide.
Thanks to the Glitch City Research Institute for both hosting my written guide and for providing feedback and support during the development of these guides.
Special thanks to Popcorn, Rebsillycon and Plushie for providing valuable feedback and corrections.
Thanks to the Glitch City Research Institute Discord for support and feedback, as well as hosting my written guides on the wiki.
00:00 - Intro 01:12 - Prerequisites 02:15 - Part 1: Setting up initial ACE 05:55 - Part 2: Executing COIN CASE ACE 06:52 - Part 3: Installing a program by selling TMs 13:56 - Part 4: Using mail codes 16:14 - Part 5: Using other codes 18:09 - Final notes and acknowledgementsPokémon Gold/Silver/Crystal: Improved Celebi Egg GlitchTimoVMs ACE Guides2024-08-05 | We're diverging a bit from the usual subject of Arbitrary Code Execution (ACE) with this guide!
The Celebi Egg Glitch is a fairly old setup that allows a player to obtain any pokémon, using just repeated cloning and party overloading. Traditionally, this was done by transplanting the move id of an egg's third move to the species value.
There were some minor issues with the old setup, though. - Certain moves are very difficult to get as the third move on an egg, meaning that not all pokémon are easily available. - Since this setup would transplant PP values onto DVs, it also wasn't really possible to obtain any shiny pokémon through the setup. - Lastly, while all valid species could theoretically obtained through move IDs, it wasn't easily possible to obtain glitch pokémon through the setup.
This video outlines an improved version of the Celebi Egg Glitch setup. This setup transplants a donor pokémon's Sp. Def. stat to an egg's internal species value, while also preserving the remaining data of the egg.
In short, it allows you to get any species from an egg, while also inheriting the DVs and moveset of the original egg.
Applications for this improved setup include hatching a shiny Ditto from an egg, obtaining any legendary or mythical pokémon or obtaining a normal pokémon that has normally illegal moves.
This setup also happens to be compatible with the VC releases. Do keep in mind that poké transporter will refuse to transfer pokémon with illegal movesets, so make sure to visit the move deleter prior to transferring pokémon.
Many thanks to Dove for inspiring this setup.
Many thanks to Paco81 for the development of the original setup (March 2007).
Thanks to Popcorn, Rebsillycon and Mat2 for proofreading the video.
00:00 Summary 00:34 Prerequisites 01:13 Part 1: Obtaining a Bad Clone 02:04 Part 2: Overloading the Party 03:17 Part 3: Manipulating the Party 04:08 Part 4: "Fixing" the Party 05:21 Part 5: Actually Fixing the Party 07:38 Final NotesPokémon Yellow - Using glitches to quickly set up a versatile cheat engineTimoVMs ACE Guides2024-04-15 | This video guide demonstrates a new and modernized arbitrary code execution (ACE) setup for the English releases of Pokémon Yellow. It is intended to be set up starting from a new game and can easily be performed within 1 to 2 hours.
Along the way, I'll show a fast way to obtain glitch item 4F and guide you through the installation of the NickWriter program. This small but versatile program, stored within unused memory, allows you to quickly write and execute code. In essence, we're installing a cheat engine into Pokémon Yellow, then using it to easily get anything we want, such as a Bank compatible shiny Mew.
The main improvements of this approach, aside from a faster setup time, come from using glitch item 4F and the incorporation of a NickWriter program.
- Unlike ws m, 4F doesn't require any item setup or active box setup to use, with the only requirement being that you can't use the day-care. - The NickWriter, due to its ability to quickly write and execute arbitrary code, removes the need for item codes, leading to faster, larger and more convenient ACE codes.
This is part of a 1.5 year long effort across all gen 1 and gen 2 pokémon games to bring the ACE capabilities of the international releases more in line with the Japanese releases. More technical details on the glitches used in the setup, as well as further explanation on the code I developed as part of this setup, can be found within the written version of this guide.
The written version of this guide, along with alternative setups for other languages and versions, can be found linked at https://glitchcity.wiki/wiki/Guides:TimoVM%27s_gen_1_ACE_setups
Additional codes that can be used with the NickWriter can be found at https://glitchcity.wiki/wiki/Guides:Nickname_Writer_Codes
The written guide technically also supports existing saves in addition to new saves. Be warned though that setting up inventory underflow on an existing save of Yellow isn't an easy process, hence the recommendation to start from a new save.
If you're interested, feel free to also check out the modernized setups I made for Gold, Silver and Crystal, which can be found at https://glitchcity.wiki/wiki/Guides:TimoVM%27s_gen_2_ACE_setups
If you need support when following this guide, you can always contact me via the Glitch City Research Institute discord linked here: discord.gg/EA7jxJ6
Thanks to @ChickasaurusGL , whose earlier 4F guides served as a large inspiration for my own setups.
Thanks to Flag3 and other members of the JP glitching community, whose guides not only lead to several improvements in this guide, but also demonstrated the full potential of more complicated ACE setups.
Thanks to diabl0w. for inspiring me to develop several improvements in the NickWriter's code, making it both shorter and more functional.
Thanks to Popcorn, ShinySkitty and Rebsillycon for reviewing the video and providing feedback that allowed me to fully polish up the guide.
Thanks to the Glitch City Research Institute for both hosting my written guide and for providing feedback and support during the development of these guides.
Timestamps:
00:00 Intro 00:38 Part 1: SRAM Glitch 02:21 Part 2: Reaching CELADON 03:08 Part 3: Enabling FLY 04:22 Part 4: Assembling an item code 16:32 Part 5: Executing nicknames as code 23:50 Part 6: Cleaning up side effects 26:31 Part 7: Obtaining a shiny VC transferable Mew 28:27 Part 8: Acknowledgments
#pokemonyellow #pokemonglitch #shinypokemon #glitchPokémon Red/Blue - Using a fast 4F setup for Bank compatible Mew and almost any other purposeTimoVMs ACE Guides2024-03-30 | This video guide demonstrates a new and modernized arbitrary code execution (ACE) setup for the English releases of Pokémon Red/Blue.
Within this video, I'll demonstrate a fast way to obtain glitch item 4F and guide you to the installation of the NickWriter program (yes, we're actually installing full-blown programs in Pokémon games now) . This small but versatile program, stored within unused memory, allows you to quickly write and execute code. In essence, we're installing a cheat engine into Pokémon Red and Blue, then using it to easily get anything we want, such as a Bank compatible shiny Mew.
The main improvements of this approach, aside from a faster setup time, come from using glitch item 4F and the incorporation of a NickWriter program.
- Unlike 8F, 4F doesn't require any item setup or party setup to use, with the only requirement being that you can't use the day-care. - The NickWriter, due to its ability to quickly write and execute arbitrary code, removes the need for item codes, leading to faster, larger and more convenient ACE codes.
This is part of a 1.5 year long effort across all gen 1 and gen 2 pokémon games to bring the ACE capabilities of the international releases more in line with the Japanese releases. More technical details on the glitches used in the setup, as well as further explanation on the code I developed as part of this setup, can be found within the written version of this guide.
The written version of this guide, along with alternative setups for other languages and versions, can be found linked at https://glitchcity.wiki/wiki/Guides:TimoVM%27s_gen_1_ACE_setups
Additional codes that can be used with the NickWriter can be found at https://glitchcity.wiki/wiki/Guides:Nickname_Writer_Codes
If you're interested, feel free to also check out the modernized setups I made for Gold, Silver and Crystal, which can be found at https://glitchcity.wiki/wiki/Guides:TimoVM%27s_gen_2_ACE_setups
If you need support when following this guide, you can always contact me via the Glitch City Research Institute discord linked here: discord.gg/EA7jxJ6
Thanks to @ChickasaurusGL, whose earlier 4F guides served as a large inspiration for my own setups.
Thanks to Flag3 and other members of the JP glitching community, whose guides not only lead to several improvements in this guide, but also demonstrated the full potential of more complicated ACE setups.
Thanks to diabl0w. for inspiring me to develop several improvements in the NickWriter's code, making it both shorter and more functional.
Thanks to @RETIREglitch for help and advice, especially when I just starting out with the idea to create a video guide.
Thanks to ShinySkitty and Rebsillycon for reviewing the video and providing feedback that allowed me to fully polish up the guide.
Many thanks to Ophylia, whose positivity and feedback was invaluable when making this guide.
Thanks to the Glitch City Research Institute for both hosting my written guide and for providing feedback and support during the development of these guides.