Drag the artwork to explore. Use the arrow keys when it is focused.

Security & ExploitsProfile Signing Exploit

Halloween Cape Leak Is Actually a Profile-Signing Exploit

The MinecraftCapes mod creator says the mysterious new cape does not come from Mojang. A cracked Polish server has figured out how to forge valid Mojang signatures on arbitrary player profiles, an impossibility that has the Java cape community reeling today.

2 min read

Minecraft players woke up today to a quiet bombshell from the one person who knows Java capes better than anyone. James090500, creator of the MinecraftCapes mod and its accompanying gallery, just declared the hyped Halloween cape is not real. It is the output of an exploit running on a cracked Polish server that can sign arbitrary Minecraft profiles with valid Mojang signatures.

The original leak dropped four days ago: two clean screenshots of a pumpkin-themed cape that looked exactly like something Mojang would drop for the season. Plenty of creators and servers started planning events around it. Then the MinecraftCapes account followed the trail and hit a wall that should not exist.

This entire Halloween Cape situation is MENTAL. We no longer believe this is a real cape but instead a cracked polish Minecraft server has instead found an exploit to sign Minecraft profiles with a valid signature. This should NOT be possible!

The linked texture packet uses a profile UUID that produces a perfectly signed response from Mojangs own systems. If this holds, the server has bypassed the exact cryptographic check that keeps fake capes and skins out of the official ecosystem. That is not a skin leak. That is a protocol-level break.

The exploit appears limited to that one cracked server for now, but the implications stretch across every Java launcher, every cape mod, and every server that trusts signed profile data. If signatures can be forged, the line between official cosmetics and player-made fakes just dissolved. Mojang has not commented yet; the usual cape-drop channels remain silent.

James090500 has been mapping official, creator, and leaked capes since 2015. When he says the signature chain is wrong and points to a public endpoint that proves it, the Java community listens. The original leak post already sits at over 100k views. Todays reversal is spreading just as fast.

For now the advice is simple: treat any new Halloween cape downloads or events as unverified. The texture works, the signature validates, but the source is a server that has no business holding Mojangs private keys. Exactly how they pulled it off is the question everyone is asking tonight.

Did you enjoy this story?