April 1, 2012

The 2012 April Fools incident was a large hack of the Roblox website, resulting in the website being taken offline for a brief period of time. This was an actual hacking of the website, the incident was widely referred to as such both during and after it occurred.

It was orchestrated by "Group 29", their members are: Svenler, escanses and Nikki Klyukin. They also encouraged people to ask them questions on Discord. Their tags are: svenler and escanses.

Nikki Klyukin has been inactive since 2013.

Information
The hacker group "Group 29", having been created in 2011 by Svenler, gained 2 additional hackers: escanses and NikkiKlyukin. Their first hack was on this day. The hack was thought to have begun when user Svenler gained access to Roblox's admin panel by creating an account on SiteTest3 using a Roblox Administrator's Roblox username.

Svenler was responsible for the website's most notable hacking on April 1, 2012. Svenler gained access by logging into an admin account on SiteTest3 (because not all admins were on the testing sites). escanses using the .ROBLOSECURITY cookie, NikkiKlyukin using the warning banner and unauthorized user promotions are all examples of hacks that day. In a 2017 Reddit comment, former Roblox moderator Gordonrox24 stated that "It was nothing... You won't see it happen again".

However, in 2023, the Blox Fruits hack by Group 29 was a successful hacking attack where they successfully hacked Blox Fruits and gained access to their servers. From this point onward, Group 29 has been known not only as top hackers but even as the best ROBLOX hackers.

Account Hacking and Controlling
A suspected precursor to the incident was a forum] discussion that devolved into an argument between Minish and Merely about money and Roblox's economy. escanses allegedly took over Minish's account, and Minish purchased Merely's famous Domino Crown, which was Merely's personal favorite avatar shop item. The forums quickly became inundated with threads debating the events. As a result, the two users were banned. This would also result in Merely briefly leaving Roblox.

Soon after, Svenler-controlled accounts Pheedy and are17 were promoted to moderators and used their newfound authority to unban Minish. During this time, the user NikkiKlyukin (real name Nikita Klyukin), the creator of the notorious scam site bab.lab, dropped the prices of hats in the avatar shop tremendously, and hats were released by the minute for 1 Robux. Some hat names were changed, such as Explosive Hair]] was renamed to "Rocket Hair", Hooded Spacelord was renamed to "Noob Hood", and Memento Mori was renamed to "Candle Skull".

It is believed that 1dev2's account was one of the compromised accounts. During the event, many items were added to their inventory, and their avatar was changed several times. This led to a moderator subsequently deleting their account. This ban was never lifted, but 1dev2 may have been granted temporary access to their account after the event, during which time they uncopylocked their game "Welcome to the Town of Robloxia".

Assets
During this time, the perpetrator released multiple Roblox assets on the official Roblox account. They first released a new face with the title "c:" into the avatar shop for 100 Robux. Stickmasterluke's account was the only account that bought it (or one of the breachers added it through their avatar), and anyone else who tried to buy it received an error message. The image asset for the face can be retrieved on the Roblox website. Another "c:" face was created and can be also be retrieved on the website. A third face, "hai guize derp" was also released and can be accessed on the Roblox website as well.

Other accounts affected during this incident include:
 * Qman1245 obtaining the Dominus Empyreus, Domino Crown, Ban Hammer, and the Admin Badge. Their account was later terminated.
 * Rippinz obtained multiple items released during the incident, including two copies of the Scary Hood.
 * Misteroe traded away and laundering an estimated 100,000 to 350,000 Robux.
 * ExFamous obtained Dominus Frigidus #16 and #59 Ghostwalker, which were worth approximately eight million Robux at the time.
 * Mattmlm11 was given the Sinister Fedora along with other items, but were later removed from their inventory.
 * ScorpioPilot was also compromised and terminated for 6 years.
 * ReeseMcBlox was among the users hacked during the incident, as shown in a forum post. When she was hacked, the exploiters wrote extremely inappropriate comments using her account, and it has been reported that she could not get access to her account until the event was over.

Hats
Several avatar shop items, mainly hats that were never intended to be released were during this update with altered names. These hats were quickly taken off sale after Roblox gained control. These included:
 * Crazy Skull
 * Toxic Nemisis
 * SteamPunk Elephant
 * Dino Bandit
 * Ice Law

Hacker Banners
Banners were added to the top of the website by Svenler and NikkiKlyukin and frequently changed colors and displayed questionable content. In chronological order, all banners are below:
 * "Hi, we are having issues with our publishing system. Hang tight yo!"
 * "Bro chill we get it"
 * "Yo dog y'all need to chill it"
 * "Do A Barrel Roll"
 * "thank you minish for messing up the economy. nub."
 * "these aren't the droids you're looking for!"
 * "Go out and buy some peanut butter yo"
 * "You put the peanut butter in the potato and stir it all up"
 * "jaredvaldez4 best builder on roblox kthxbai"
 * "WHO IS IT 1x1x1x1, Dignity, Minish, Jared, The Admins? The World May Never know :o"
 * "minish is climbin in yo windows. snatchin yo people up."
 * "WII GUNNA FIN WII GUNNA FIN U"
 * "Oh you like these headers? Tell me how you've always been such a fan"
 * "OMG lik srsly becky?"
 * "JOIN BUILDERS CLUB! ITS FREEEEEEEEEEEEEE!!!!"
 * "Minish, I need you boo. I gotta see you boo. But yea this isn't Minish."
 * "Yo RT stop yo ranting homies"
 * "Haha these are so funny lets go spam the forums about them :D"
 * "is anybody here besides minish a huge chris brown fan??"
 * "Remember kids tell your parents to vote for Ron Paul"
 * "Playing roblox is always better then going outside!"
 * "Yo gonna give a shout out to the homies in dah hood"
 * "pink. it's my new obsession. pink. it not even a question."
 * "Abcedfghikjlmnoqprstuvwzyx"
 * "I'm the annoying orange banner. AHHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHAHHAHAHAHAHA"
 * "NO TOMATO IS ALWAYS BEST SILLY ORANGE"
 * "minish is a stupid noob. nah not rly"
 * "remember kids trust anyone with your password"
 * "APRIL FEWLS"
 * "Ten bux says we do roll back on today"
 * "hai itz pheedy mcnoobster and minish and we taken over"
 * "McNoobster in dah houze"
 * "McNoobster!!!!!!"
 * "Proscribe stop posting your gonna get proscribed BROOOOOOO"

Roblox's Response
After all the activity occurring, Roblox staff brought the site offline and reported that they were attempting to patch up the currency system. The website was brought back online during the late evening of that day. The site test admin panel was updated and the Roblox avatar shop was offline until the following evening.

In a Roblox Blog post on April 2, 2012, it was announced that "Roblox experienced a site issue the evening of April 1st..., and they took the site offline". They noted that "Several assets were released from the avatar shop backlog that were not ready for production", and "Several accounts were incorrectly granted large amounts of Robux; some of these Robux were subsequently traded with other accounts." Some avatar shop items and currency transactions were audited and rollbacked, and they estimated the rollbacks occurred in fewer than 0.01% of Roblox accounts. Some items were updated with new pricing, while other items were taken off-sale. The "c:" item was changed to Dr. Smyth Face and was temporarily available for purchase after April 2, 2012.

Confession
In a recent interview, Group 29's leaders Svenler and Escanses in Discord detailed their hacking of ROBLOX's servers and how they successfully managed to go to the ROBLOX test site and gain access to the servers to hack Roblox. In detail, they explained how the hacking involved multiple layers of security, and how they used their skills to bypass them with ease and talked about their group. Group 29 used several methods to bypass ROBLOX's system, including some methods to bypass their encryption and authentication protocols. They also used advanced techniques of reverse engineering to understand the ROBLOX's system and develop their own methods to bypass it.

When asked about Nikki Klyukin, they said that they haven't heard about him since 2013.

They also told people their Discord tag, and that they would love to talk with their fans. Their tags are: svenler and escanses.

Trivia
Trivia section
 * If the ID of the "c:" face is put into a face changer or mannequin the Dr. Smyth Face displays instead.
 * Some of the items prices were changed to 666 Robux.
 * It is also speculated that the Blox Fruits hack was by them, however, it is not fully confirmed, as NikkiKlyukin hasn't said anything since 2013, and it is highly unlikely that they would do hack anything without him.

Source
Roblox Wiki