Every time a major PlayStation jailbreak appears, an interesting theory returns: does Sony secretly benefit from jailbreaks?
Some versions of the theory go even further. People speculate that Sony employees could leak vulnerabilities, that Sony deliberately waits before stopping exploits, or that jailbreak publicity helps sell consoles.
There are pieces of truth around some of these ideas, but they are often connected in ways the available evidence does not support.
We investigated the history from PS3 to PS5, Sony's finances, its relationship with security researchers, major PlayStation exploits and Sony's own actions against hacking.
The evidence points to a much more interesting explanation.
Sony makes much more than money from selling consoles
The first question is financial.
If jailbreaks encourage people to buy PlayStations, could Sony actually make money from them?
Sony's own financial reports show why this argument is difficult to support.
For FY2025, Sony's Game & Network Services business reported approximately ¥4.69 trillion in sales. Hardware accounted for roughly ¥944 billion.
But digital full-game sales generated about ¥1.06 trillion, add-ons such as DLC and in-game purchases generated approximately ¥1.36 trillion, and network services generated another ¥763 billion.
Sony defines network services as including services such as PlayStation Plus and advertising.
The figures are available in "Sony's official Game & Network Services financial information" (https://www.sony.com/en/SonyInfo/IR/library/presen/er/pdf/26q1_supplement.pdf).
That means PlayStation is not simply a business where Sony sells someone a console once.
A customer can continue generating revenue through games, PlayStation Plus, DLC, microtransactions and other PlayStation Store purchases for years.
A permanently offline jailbroken console may participate much less in that ecosystem.
Jailbreaks do increase the value of some consoles
There is still a real economic effect — just not necessarily for Sony.
When an exploit supports only older firmware, consoles that have not been updated can become significantly more valuable.
This has happened with PS4 and is happening with PS5.
Second-hand marketplaces regularly contain consoles advertised specifically as low firmware, jailbreak-ready or already jailbroken.
The problem with the theory is simple: when someone buys a five-year-old PS5 from another person for a high price because it contains rare firmware, Sony does not receive that money.
The seller does.
Jailbreak demand can therefore increase the value of PlayStation hardware without producing equivalent revenue for Sony.
Jailbreaks definitely create publicity
This part of the theory is more believable.
Major PlayStation exploits generate enormous attention.
When the PS5 Relapse exploit became public in September 2026, technology publications quickly reported that PS5 systems through firmware 13.60 had become exploitable.
"Ars Technica covered the Relapse breakthrough" (https://arstechnica.com/gaming/2026/09/ps5-jailbreaks-just-got-a-lot-more-useful/), while the "official Relapse repository" (https://github.com/ntfargo/Relapse-Exploit) gave researchers and developers access to the actual project.
The same thing happened during major PS3 and PS4 breakthroughs.
YouTube videos appear. Reddit discussions grow. Old consoles suddenly become interesting again. People begin searching for particular firmware versions.
That is undeniably free attention for PlayStation.
What we could not find is convincing evidence that this attention produces enough additional PlayStation sales to create a meaningful financial benefit for Sony.
Publicity exists.
A measurable net commercial benefit remains unproven.
What about the insider-job theory?
This is where evidence becomes much weaker.
Sony has suffered genuine internal leaks.
Official PlayStation development tools, SDK material and internal information have appeared online over the years.
For example, a PS4 SDK leaked publicly in 2017. Sony responded with copyright complaints attempting to remove copies and discussion of the leaked material. "Ars Technica documented Sony's response to the PS4 SDK leak" (https://arstechnica.com/gaming/2017/07/sony-using-copyright-requests-to-remove-leaked-ps4-sdk-from-the-web/).
An official PS Vita SDK also appeared online through an anonymous leak.
There have even been confirmed cases of Sony employees leaking unrelated game material.
But none of this proves that Sony employees supplied the vulnerabilities behind major PS3, PS4 or PS5 jailbreaks.
During this investigation, we could not find independently verified evidence showing a Sony employee or contractor secretly providing a console vulnerability to a jailbreak developer.
No authenticated communication.
No verified internal instruction.
No confirmed whistleblower.
No access logs demonstrating that an employee extracted a vulnerability and passed it to hackers.
The insider theory therefore remains exactly that: a theory.
But Sony really does pay PlayStation hackers
This is where things become interesting.
Sony openly pays security researchers who discover PlayStation vulnerabilities.
In 2020, Sony announced its public PlayStation bug-bounty programme through HackerOne. Sony also revealed that it had already been operating a private programme with selected researchers.
Critical vulnerabilities could receive substantial rewards.
Sony explained the reason clearly: security researchers help make PlayStation safer.
You can read "Sony's original PlayStation Bug Bounty announcement" (https://blog.playstation.com/2020/06/24/announcing-the-playstation-bug-bounty-program/).
This relationship can create situations that look suspicious if you only follow the jailbreak scene.
A researcher discovers a serious PlayStation vulnerability.
Instead of immediately publishing it, the researcher privately reports it to Sony.
Sony pays the researcher.
Sony fixes the vulnerability.
Months later, details become public.
Jailbreak developers then use that research against the older firmware where the vulnerability still exists.
From outside, someone might ask:
“Why did Sony pay the hacker who gave us the jailbreak?”
The answer is that Sony paid the researcher for telling Sony how to stop the vulnerability before publicly explaining it.
TheFlow is one of the best examples
Security researcher Andy Nguyen, better known as TheFlow, has discovered several important PlayStation vulnerabilities.
His work has influenced both PS4 and PS5 security research.
One famous example is BD-JB, which exploited vulnerabilities in the Blu-ray Java environment used by PlayStation.
The vulnerability was privately reported before becoming public.
Sony received time to address the problem, and the technical details became available later.
The same basic pattern appears with PPPwn.
PPPwn became one of the most important modern PS4 exploits because it provided kernel remote-code execution on systems including firmware 11.00.
But the "official PPPwn repository" (https://github.com/TheOfficialFloW/PPPwn) explicitly states:
“The vulnerability was responsibly reported to PlayStation.”
That sentence explains much of what can otherwise appear suspicious about PlayStation jailbreak timing.
Sony patches first — jailbreak developers arrive later
PS4 firmware 9.00 provides another interesting example.
The famous pOOBs4 exploit uses a filesystem vulnerability.
The developers specifically noted that the vulnerability had already been fixed in firmware 9.03.
You can examine the "original pOOBs4 project" (https://github.com/ChendoChap/pOOBs4).
This creates an unusual situation.
When Sony patches a vulnerability, researchers can compare the old and new firmware.
Those differences can sometimes help reveal what Sony changed.
Researchers may effectively ask:
“What changed between the vulnerable firmware and the patched firmware?”
Finding the answer can help identify the original weakness.
That does not mean Sony deliberately showed researchers the exploit.
It is a normal consequence of software patching and reverse engineering.
PS3 provides some of the strongest evidence against the conspiracy
If Sony secretly wanted PlayStation systems jailbroken, its behaviour during the PS3 era would be difficult to explain.
The PS3 originally supported installing another operating system through a feature called OtherOS.
Sony later removed OtherOS from regular PS3 systems, citing security concerns.
Sony's "official PS3 firmware 3.21 announcement" (https://blog.playstation.com/2010/03/28/ps3-firmware-v3-21-update/) explained that users could refuse the update, but doing so would mean losing access to PlayStation Network and potentially newer games and Blu-ray content requiring later firmware.
Then came the famous PS3 security breakthroughs.
Researchers including fail0verflow exposed serious weaknesses in the PS3's cryptographic security.
George Hotz, better known as Geohot, also published PS3 security work.
Sony's response was not cooperation.
Sony sued Hotz.
The case eventually ended with a settlement and permanent injunction. Sony published an "official statement about the George Hotz settlement" (https://blog.playstation.com/2011/04/11/settlement-in-george-hotz-case/).
Sony also warned PS3 owners that systems using unauthorized circumvention devices or pirated software could lose access to PlayStation Network.
That history is difficult to reconcile with a theory that Sony secretly wanted jailbreaks for publicity or hardware sales.
PS4 tells a similar story
The PS4 jailbreak scene developed through many independent pieces of research.
WebKit vulnerabilities provided browser entry points.
Kernel vulnerabilities provided higher privileges.
Developers then combined those vulnerabilities into practical exploit chains.
For firmware 6.72, community developers combined WebKit and kernel research into working jailbreak implementations.
Firmware 9.00 later became one of the most popular PS4 jailbreak versions through pOOBs4.
Firmware 11.00 eventually received PPPwn.
These exploits appeared at different times, involved different researchers and used very different attack surfaces.
There is no evidence of a single hidden source inside Sony feeding vulnerabilities to the scene.
PS5 follows the same pattern
The PS5 scene initially progressed much more slowly.
Researchers discovered browser vulnerabilities, Blu-ray Java weaknesses and kernel vulnerabilities, while Sony continued patching firmware.
Projects such as "PS5 IPv6 Kernel Exploit" (https://github.com/Cryptogenic/PS5-IPV6-Kernel-Exploit) built on previously disclosed security research.
BD-JB provided another entry route.
Hypervisor research later demonstrated deeper compromises on very early firmware.
Projects such as etaHEN and Kstuff then built useful homebrew environments around available exploitation methods.
More recently, SlopKit combined vulnerabilities for newer systems.
Then came Relapse.
The "official Relapse Exploit repository" (https://github.com/ntfargo/Relapse-Exploit) currently targets PS5 firmware 7.00 through 13.60.
Relapse combines browser exploitation with kernel exploitation involving "aiomultiwait", eventually reaching kernel read/write and allowing ELF payloads to be loaded.
Again, the pattern looks familiar:
Vulnerability → research → patching → public exploit → jailbreak implementation → homebrew ecosystem.
Could Sony simply tolerate jailbreaks once firmware becomes old?
This is probably the strongest version of the theory.
It does not require Sony to help hackers.
Imagine someone owns a PS5 on firmware 13.20.
They want to preserve Relapse compatibility, so they refuse to update.
Over time, newer games begin requiring newer firmware.
PlayStation Network may also require current system software.
New features appear only on later firmware.
The console effectively separates itself from Sony's current ecosystem.
This creates a natural containment mechanism.
Sony does not need to magically remove the vulnerability from every PS5 already running old firmware.
It needs to patch current firmware and encourage normal users to update.
This behaviour goes back at least as far as PS3.
Sony's old PS3 firmware documentation explicitly warned that refusing an update could remove PSN access and compatibility with future software.
That same basic pressure still exists today.
That does not mean Sony intentionally allows old jailbreaks
There is an important distinction.
Sony may have less incentive to aggressively fight an exploit once it is permanently trapped on obsolete firmware.
That is plausible.
But saying Sony intentionally leaves the vulnerability there is different.
Once vulnerable firmware has been installed on millions of consoles, Sony cannot go back in time and rewrite those systems.
Its practical solution is to patch future firmware.
Users who deliberately refuse those patches remain vulnerable.
That is not cooperation.
It is simply how software security works.
Sony is not unusual
Other technology companies have almost identical relationships with hackers.
Microsoft operates an "Xbox Bounty Program" (https://www.microsoft.com/en-us/msrc/bounty-xbox) that pays researchers for reporting Xbox vulnerabilities.
Nintendo also runs a vulnerability disclosure programme through HackerOne.
Apple's "Security Bounty programme" (https://security.apple.com/bounty/) can pay researchers millions of dollars for serious exploit chains.
Yet Apple strongly discourages iPhone jailbreaking.
There is no contradiction.
Apple benefits from jailbreak-class security research because it learns how attackers can break iOS.
That does not mean Apple benefits from customers actually jailbreaking their phones.
Sony's relationship with PlayStation hackers works in much the same way.
Android shows what real permission would look like
Android provides an interesting comparison.
Some Android devices officially support bootloader unlocking.
Google's "Android Open Source Project documentation" (https://source.android.com/docs/core/architecture/bootloader/locking_unlocking) even defines how supported devices should implement locking and unlocking.
Users receive warnings, unlocking normally wipes the device, and the system clearly records that the bootloader is unlocked.
That is what official permission looks like.
PlayStation provides no equivalent option.
There is no Sony-supported setting saying:
“Unlock my PS5 for homebrew.”
If Sony genuinely wanted PlayStation owners to modify their consoles, it could provide an official development or bootloader-unlock mechanism.
It does not.
Does Sony benefit from security research?
Absolutely.
This is the part of the theory that is actually confirmed.
Every serious vulnerability teaches Sony something about its security architecture.
A WebKit exploit can reveal browser weaknesses.
A kernel use-after-free can expose memory-safety problems.
A hypervisor exploit can reveal weaknesses between security boundaries.
Cryptographic research can reveal mistakes in key management.
Sony can use that information to strengthen later firmware and future PlayStation hardware.
In other words, Sony benefits because hackers show it how PlayStation security can be defeated.
Sony then uses that information to make defeating it harder next time.
Does piracy change the equation?
Jailbreaking itself should not automatically be treated as piracy.
People use jailbroken consoles for homebrew software, emulation, preservation, security research, debugging and experimentation.
Many exploit developers explicitly distance their work from piracy.
The Relapse developers, for example, describe their project as being intended for educational and security research.
But jailbreaks can also make unauthorized software easier to run.
Sony explicitly identified piracy as a concern during the PS3 era.
That gives Sony another strong financial reason to prevent current PlayStation systems from being compromised.
So, does Sony secretly benefit?
The answer depends entirely on what we mean by “benefit.”
Sony financially benefits from jailbreaks
🔴 UNLIKELY
Jailbreaks can increase demand for particular consoles, but much of that demand exists in the second-hand market.
Meanwhile, Sony earns enormous revenue from digital games, DLC, PlayStation Plus and other services that depend on its controlled ecosystem.
Jailbreaks give Sony free publicity
🟡 PLAUSIBLE
Major jailbreaks clearly generate PlayStation coverage, searches, YouTube videos and community discussion.
But there is insufficient evidence showing that this publicity produces a meaningful net financial benefit for Sony.
Sony benefits from jailbreak security research
🟢 CONFIRMED
Sony openly pays researchers through its bug-bounty programme.
Finding vulnerabilities allows Sony to patch them and strengthen PlayStation security.
Sony intentionally allows jailbreaks on old firmware
🟡 UNPROVEN
Old firmware naturally becomes isolated as PSN, games and features move forward.
Sony may have less reason to worry about an exploit permanently trapped on obsolete firmware.
But there is no evidence showing Sony deliberately keeps those vulnerabilities available.
Sony employees secretly give hackers vulnerabilities
🟡 UNPROVEN
Sony has experienced genuine internal leaks.
But we found no independently verified evidence tying a Sony employee or contractor to secretly supplying vulnerabilities behind major PS3, PS4 or PS5 jailbreaks.
Sony deliberately releases PlayStation jailbreaks
🔴 UNLIKELY
The evidence points strongly in the opposite direction.
Sony patches vulnerabilities, restricts outdated firmware from current services, has fought leaked development material and has historically taken legal action against circumvention.
The most surprising finding
The most interesting discovery is that Sony and PlayStation hackers can effectively be partners and opponents at the same time.
A researcher such as TheFlow can discover a vulnerability and privately help Sony fix it.
Sony can pay that researcher.
Months later, the same vulnerability can become public.
The jailbreak community can then use the research against old firmware.
Sony benefited from the research.
The jailbreak community benefited from the eventual disclosure.
Both statements can be true without Sony secretly supporting the jailbreak.
What would prove an insider job?
An insider claim would require much stronger evidence than suspicious timing.
We would need authenticated communication showing a verified Sony employee or contractor intentionally supplied a non-public vulnerability.
The person would need demonstrable access to that information.
Timestamps would need to show that jailbreak developers received the information before independent discovery or public disclosure.
Ideally, there would also be supporting evidence such as internal documents, access logs, court records or independently verified witnesses.
An anonymous Discord message would not be enough.
A leaked SDK would not be enough.
A researcher knowing unusual details about PlayStation internals would not be enough.
And an exploit appearing after Sony already patched the vulnerability would certainly not be enough.
The evidence points to a simpler explanation
Across PS3, PS4 and PS5, the pattern is remarkably consistent.
Researchers find weaknesses.
Sometimes they tell Sony privately.
Sony patches them.
Technical information eventually becomes public.
Developers combine that research into jailbreaks for old firmware.
Homebrew tools grow around those jailbreaks.
New PlayStation firmware continues forward.
There is no credible evidence that Sony secretly creates this cycle.
The irony is that Sony does benefit from the people breaking PlayStation security — just not in the way the con
