I gained the ability to steal any username
Hey Mojang team, I'm gonna tell you a little story about how I discovered an exploit which allowed me to claim any username I wanted.
It began with a quick read through TOS, when I discovered you would remove a previous name if it contained personal info. This information is long known within the community,
This has been used recently by Ethan, who appropriately got his full name removed. Then a couple others, who maybe removed less appropriate to that rule usernames.
I won't delve into everyone who used this system, but some of the names removed were obscene.
That's when I realised, your support's not properly moderated and would most likely buy anything I told them. (and I mean that in the politest way possible, I don't expect them to understand why anyone would try accomplish this for ulterior motives)
That's when I formulated a plan, and at this point I'll clarify:
I in no way did this with intent to steal, sell, or other to anyone's account.
I did this as a test as I was already aware people were investigating the possibilities and I could already see multiple people figuring this out and abusing it.
I created an inbox bearing the name of 'Ilovecats9998' and began composing.
I needed a convincing narrative, so I whipped up:
"hey so I've had the username 'cat' for years now and while I enjoyed it, I've always had abuse from people jealous of the username. I'd try go past it, but it escalated to the extent where people were threatening to dox me or hack me unless I handed them the account. I've been tired of this for a long time now and considered deleting it and buying a new account just so I could play peacefully again, without all the negative attention. I instead changed my username, but the name 'cat' is still attached and the abuse hasn't ended. I'd rather not have to pay for a whole new account and I read in your terms and conditions that you'd remove this association if it contained personal information or was a danger to myself, and since Cat is my real name and combined with the rest of my account's history shares my full real name I'd rather it not be publicly visible.
Could you please remove 'cat' from my name history so I can finally get rid of it? The curse follows me everywhere...
If that's not possible then please just delete my entire account.
Thank you!"
I'd like to clarify I don't feel comfortable lying to your support team but it was for the greater good in this situation and I hope you won't be too mad at me ![]()
Then I got my friend running a turbo, which tries to claim a username every second to avoid a random person getting it if it were to go available. This would block the username and prevent anyone from taking it, which prevents selling.
Then your lovely employee WelTall (bless him, I don't fault him in any way) removed the name 'cat' from the current account's username history and bam, it's mine now. I blocked the name and tied it to my account, and the community went wild.
Since, the name got accidentally unblocked by an associate of mine and somebody random kicked in and claimed the username - I got in contact with them and told them not to sell the account, and they're getting a good bit of unwanted attention from accidentally taking the username.
So yeah, TL;DR your support team will allow anyone to change anything about anyone's account without any information or using the correct email address, this is obviously a flaw and if discovered by the minecraft community would result in mass abuse of the system and robbery left right and centre.
What I need from you guys now is to undo the change, meaning move the username 'cat' back to the original owner and remove 'ilovecats9999988' from their name history to resolve this mess, and restore their account back to how it was before I messed with it.
I'd like to state a final time that I did not intend to do this maliciously and I messed up and released the username publicly, and it was always my intention to revert the change I made. I only did this to expose the state of support, and help you guys avoid this being misused in the future.
Thank you again for your time and attention.