2 Paws 1 Job Blog

The Nocom Exploit Exposed: 2b2t's Biggest Scandal

How a Paper patch let Nerds Inc track loaded chunks on 2b2t for three years, locate about 15,000 bases, and how Hausemaster patched Nocom on 15 July 2021.

Updated 8 min read 2 Paws 1 Job Staff

You spent weeks, maybe months, building a hidden base far from spawn. Obsidian walls, hidden stashes, farms that could supply an army. You log in after a break, and it is gone. Not just griefed, but systematically looted. Every dupe stash emptied, every build burned. No random TNT raid. No obvious coordinate leak.

That story was familiar to thousands of 2b2t players, and in July 2021 it got an explanation. Nocom was a server-wide tracking system that ran for roughly three years, located about 15,000 bases, and was finally patched on July 15, 2021. Days later the group behind it published the technical write-up themselves.

This archive covers what Nocom was, how it worked, who built it, how it ended, and why it changed how players thought about privacy on the oldest anarchy server in Minecraft.

Nocom in one paragraph

Nocom, short for “no comment,” let a small group ask the 2b2t server whether any chunk anywhere on the map was currently loaded, and get an answer. Loaded chunks mean nearby players. Run that query millions of times with bots and you get a live map of where everyone is. The group behind it, Nerds Inc, used it from 2018 until July 15, 2021, built a 1.7-terabyte database of 13.5 billion rows, and located roughly 15,000 bases.

2b2t: where anarchy was supposed to mean freedom

For those still catching up, 2b2t is Minecraft’s wild west. No rules. No bans for hacking, griefing, or duping. Spawn is a crater of obsidian and lava. Bases get built in secret, only to be hunted down eventually. It has been running since December 2010, and its history is full of wars, backdoors, and coordinate leaks.

But even in pure anarchy, there had always been an unspoken rule: if you hid your coordinates well enough and did not slip up, your base might survive. Players relied on that fragile privacy. Until Nocom.

The birth of Nocom: a fix that opened the floodgates

The story starts with PaperMC, the server software 2b2t ran on. Paper carried a patch named “Fix block break desync,” the 196th patch in its 1.12.2 series, intended to stop players from crashing the server through block-break desync. The group’s own write-up, nocom-explanation, identifies that patch as the origin.

The fix changed how the server answered a specific packet, CPacketPlayerDigging. Send it at any coordinates on the map and the server would answer one of two ways:

  • If the chunk was loaded, meaning a player was nearby, it sent back the block data at that spot.
  • If the chunk was not loaded, it stayed silent.

No distance limit. No obvious red flags. Just silent intelligence. What started as a lag exploit became a player radar.

How Nocom worked without the tech overload

Imagine the server as a giant map. Players load chunks around them. That is normal Minecraft behavior. Nocom did not need exact coordinates up front. It only needed to know whether a random location in the middle of nowhere was currently loaded.

Send the packet. Get a reply? A player was within render distance. No reply? Empty wilderness.

Early versions used simple spiral scans, run through a Forgehax module: slow but effective. From 2018 until late 2019 there was no rate limit on the packet at all, so a fast connection could saturate the query rate. Do this across the whole map with bots and player positions become trackable in real time across the Overworld, Nether, and End.

Rate limits and the arms race

Hausemaster tightened the packet limits in stages, and the write-up records each one: a 500-packets-per-second cap in late 2019, a sharper reduction in late May 2020, another the following day, and a final clamp in July 2021.

Each clamp made brute-force scanning weaker, so the group made the maths smarter instead. In 2020 they brought in leijurv, lead developer of the Baritone pathfinding project, to replace spiral scanning with Monte Carlo localization, the same particle-filter technique robots use to work out where they are from sparse sensor readings. Fewer queries, better tracking.

The group behind it

Nocom was not a solo project. Nerds Inc, a crew connected to 2b2t drama for years, ran it. The write-up is signed by leijurv and names fr1kin and Babbaj among the people involved, alongside bot accounts used to feed the scan.

The group ran accounts around the clock, wrote results into a database, and mapped bases remotely by probing chunks. They did not need to walk there and risk being seen. They could map, catalogue, and strike later. For three years, when players got close to the truth, the explanations pointed at lag, random griefers, or other exploits.

Three years of silent carnage

The scale is the part that is hard to absorb. Community documentation and later press coverage put it at roughly 15,000 bases located, around 300,000 players tracked, and more than 200 million items stolen.

Valerian is the clearest documented case. Construction on the group base began on March 23, 2018. Its coordinates were leaked on June 1, 2019 using Nocom, and the base was griefed on July 22, 2019. Community wikis connect several other 2019 and 2020 griefs to the same method.

Most victims never knew why. They assumed bad luck or a coordinate leak from a trusted friend. The paranoia that created across the community became one of the scandal’s lasting effects.

Nocom was not the only exploit hitting 2b2t

The same period included a separate authentication exploit. On February 28, 2020, Nerds Inc used it to log into other players’ accounts directly, and megabases including Mu, Equilibrium II, and Poseidon were griefed over the following weeks.

Players experiencing both at once had no way to tell them apart. That is part of why the community spent 2020 and early 2021 unable to agree on what was actually happening.

The 2021 wake-up call: how it finally got exposed

In mid-2021 another group, the Infinity Incursion, recreated the exploit and built it into their cheat clients. Their version was far cruder: it could follow only one player at a time, where the original tracked the whole server. The player they chose to follow was FitMC, and they attempted to sell his logout coordinates for real money.

They were also less careful. Griefs piled up, packet logs circulated, and the pattern became obvious. Old griefs that had never made sense suddenly looked deliberate.

How it ended

On July 15, 2021, Hausemaster shipped the fix: the server stopped returning chunk information for distant coordinates, which closed both Nocom and the copycat versions at once.

Days later, Nerds Inc published nocom-explanation on GitHub with the packet details, the rate-limit timeline, and the database statistics, and on July 7, 2021 leijurv started the community Nocom wiki page. The story then travelled well outside Minecraft: Windows Central covered it on July 25, 2021, PC Gamer followed, and Kotaku ran it on July 30, 2021 under the headline “Minecraft’s ‘Worst’ Server Was Exploited So Hard, Griefers Could See The Future.”

Why this was one of 2b2t’s biggest scandals

2b2t had already seen backdoors, dupes, priority queue drama, and spawn wars.

Nocom felt different because it attacked a basic survival assumption: that effort and secrecy could protect a base. It turned the entire server into a panopticon for a small group and did so for three years without most players noticing.

This was not just another hack. It was an information imbalance that changed how players judged every old grief, every unexplained stash loss, and every supposedly private build.

The anarchy dream got a reality check

Nocom did not kill 2b2t. It exposed how fragile privacy could be in a server where anything goes.

In a world where TNT, withers, and crystals were obvious threats, the most dangerous weapon turned out to be invisible information. The scandal changed how players treated travel routes, stash behavior, base trust, and long-term secrecy, and it is the reason modern anarchy servers get asked about chunk-loading behaviour at all.

Current 2paws1job.org context

This article is preserved as a historical anarchy archive on 2paws1job.org. The active 2 Paws 1 Job server launched on January 1, 2026 with no queue, no world resets, and one shared world for Java, Bedrock, MCPE, and cracked clients. For current server data, see live statistics, server commands, and the player gallery. For a present-day comparison with the server in this story, read 2b2t vs 2p1j.

FAQ

What was the Nocom exploit?

Nocom was a 2b2t tracking exploit that used server packet responses to test whether distant chunks were loaded. If a chunk responded, a player was nearby. By scanning many coordinates with bots, Nerds Inc inferred player locations, tracked movement, and found bases without normal exploration. It ran from 2018 until July 15, 2021.

How many bases did Nocom find?

Community documentation and press coverage put it at roughly 15,000 bases located and around 300,000 players tracked, with more than 200 million items stolen. The group’s own write-up describes a supporting database of 1.7 terabytes holding 13.5 billion rows of chunk-observation data.

When was Nocom patched?

Hausemaster patched it on July 15, 2021 by limiting the range over which the server would return chunk information. Days later, Nerds Inc published a full technical explanation on GitHub, which is how most of the confirmed detail about the exploit became public rather than rumour.

Why did Nocom matter for 2b2t bases?

Nocom weakened the core defensive habit of anarchy players: hiding far from spawn and guarding coordinates. Because it identified loaded chunks anywhere on the map, remote bases and stashes were exposed by server behaviour rather than by travel trails, screenshots, betrayals, or public coordinate leaks.

Who was behind the Nocom exploit?

Nerds Inc, a long-running 2b2t group. Their published write-up is signed by leijurv, lead developer of the Baritone pathfinding project, and names fr1kin and Babbaj among the participants. A separate group, the Infinity Incursion, built a cruder copy in 2021 that could track only one player at a time.