Installing boot9strap (HBL-USM)

若需英語支援,請於 Discord 上的 Nintendo Homebrew 伺服器發問。

Technical Details (optional)

In order to exploit the SAFE_MODE firmware of our system, we need to inject an exploited WiFi profile.

As we already have Homebrew access, we can use slotTool to do this.

Once the WiFi profile has been injected, we will use SAFE_MODE, which is a recovery feature present on all 3DS consoles, to activate the exploited WiFi profile.

For a more technical explanation, see here for information about the unSAFE_MODE exploit.


If your (Right/Left Shoulder), (D-Pad Up) or (A) buttons do not work, join Nintendo Homebrew on Discord and ask, in English, for help.


第一節 — 準備工作

In this section, you will use Homebrew Launcher to launch slotTool, which will overwrite your Wi-Fi slots with hacked data. Then, you will copy the files needed to trigger the unSAFE_MODE exploit onto your device’s SD card. Your Wi-Fi connection settings will be temporarily overwritten while the exploit is active.

  1. 啟動您的主機
  2. Open the Homebrew Launcher through your method of choice (likely the Internet Browser)
  3. Launch slotTool from the list of homebrew
    • If you get stuck on a red screen, forcefully power off the console by holding the power button for fifteen seconds, then retry this section
  4. Select the “INSTALL exploit to wifi slots 1,2,3 & shutdown” option
    • You will see some on-screen text and then your system will shut down
  5. Remove your SD card from your console and connect it to your computer
  6. 在 SD 卡的根目錄底下建立一個新的資料夾 boot9strap
  7. 解壓 boot9strap .zipboot9strap.firmboot9strap.firm.sha 檔案至 SD 卡的 /boot9strap/ 資料夾中
  8. 將 SafeB9SInstaller .zip 中的 SafeB9SInstaller.bin 複製到 SD 卡的根目錄
  9. Copy usm.bin to the root of your SD card
  10. Put your SD card back into your console

第二節 — unSAFE_MODE

In this section, you will enter Safe Mode (a feature available on all 3DS family devices) and navigate to a menu where unSAFE_MODE will be triggered, which will launch you into the boot9strap (custom firmware) installer.

  1. With your device still powered off, hold the following buttons: (Left Shoulder) + (Right Shoulder) + (D-Pad Up) + (A), and while holding these buttons together, power on your device
    • Keep holding the buttons until the device boots into Safe Mode (a “system update” menu)
  2. Press “OK” to accept the update
    • There is no update. This is part of the exploit
  3. Press “I accept” to accept the terms and conditions
  4. The update will eventually fail, with the error code 003-1099. This is intended behaviour
  5. When asked “Would you like to configure Internet settings?”, select “Yes”
  6. On the following menu, navigate to Connection 1 -> Change Settings -> Next Page (right arrow) -> Proxy Settings -> Detailed Setup (image)
  7. If the exploit was successful, your device will have booted into SafeB9SInstaller
    • If your device instead freezes on a white screen, hold the POWER button until it turns off, then retry this section
    • If your device instead freezes on a red screen, you are missing usm.bin from the root of your SD card
    • If you get a different error, follow this troubleshooting guide

第三節 — 安裝 boot9strap

In this section, you will install custom firmware onto your device.

  1. When prompted, input the key combo given on the top screen to install boot9strap
  2. Once it is complete, press (A) to reboot your device
  3. Your device should have booted into the Luma3DS configuration menu
    • Luma3DS configuration menu are settings for the Luma3DS custom firmware. Many of these settings may be useful for customization or debugging
    • For the purpose of this guide, leave these options on the default settings (do not check or uncheck anything)
    • If your device shuts down when you try to power it on, ensure that you have copied boot.firm from the Luma3DS .zip to the root of your SD card
  4. 按『Start』鍵以存檔並重新啟動系統

At this point, your console will boot to Luma3DS by default.

  • Luma3DS does not look any different from the normal HOME Menu. If your console has booted into the HOME Menu, it is running custom firmware.
  • On the next page, you will install useful homebrew applications to complete your setup.

第四節 — 還原 WiFi 設定檔

In this section, you will enter the Homebrew Launcher (using custom firmware) so that you can restore the Wi-Fi connection slots that were overwritten in Section I.

  1. 啟動『下載通信 (Download Play)』程式
  2. 等到你看到兩個按鍵
    • Do not press either of the buttons
  3. 同時按下『L』+『下』+『Select』鍵以啟動 Rosalina 選單
  4. 選擇『Miscellaneous options』
  5. 選擇『Switch the hb. title to the current app.』
  6. 按『B』繼續
  7. 按『B』回到 Rosalina 主選單
  8. 按『B』退出 Rosalina 選單
  9. 按『Home』鍵,並關閉『下載通信 (Download Play)』程式
  10. Relaunch the Download Play application
  11. 您的主機應該就會啟動 Homebrew Launcher 了
  12. Launch slotTool from the list of homebrew
  13. Select “RESTORE original wifi slots 1,2,3”
  14. Your device will then reboot