Here's How the Cheat Scene Actually Works for Ultra Moon
Pokemon Ultra Moon cheats fall into three main buckets: AR codes (now called Action Replay codes or just code lists), GameShark entries, and modern CTR/EmuMMC save editors. The approach you take depends entirely on whether you're running the game on original hardware or an emulator, because the methods are completely different and not interchangeable. If you're on real hardware, you're looking at RRD (Retro Revolution Device) or a CTR flashcart loaded with a code database. These read from text-based code lists that were originally reverse-engineered from the game's memory addresses. The most common ones people use are the item duplication codes, the friendship max code, and the encounter manipulation codes for shiny hunting. The shiny randomizer is particularly useful since Ultra Moon has a base shiny rate of 1 in 4096, same as the previous generation, so having a reliable randomizer saves you from throwing away hours of encounter-based hunting. For emulator users, the situation is simpler but also more limited in scope. Yuzu and Ryujinx both support cheat engines that load .txt code files directly, and ppSSPP isn't relevant here since this is a 3DS title. With Yuzu specifically, you drop the cheat file into the cheats folder matching your game's title ID, which for the US version is 0004000000112302. The emulator reads it each time you launch. No reboot, no cart swap, just load and go.
The tricky part most people miss is that not every code works on every revision of the game. Ultra Moon had a 1.1 update that patched several memory addresses, which broke a significant number of the older AR code listings. If you're pulling codes from a 2017 forum thread and they're not applying, check your game version first before blaming the cheat tool. Go to the HOME Menu on your 3DS, highlight the game, press X, and look at the version number. Anything below 1.1 is vulnerable to save corruption from certain codes, and anything at 2.0 or later has additional patches that shift where items and Pokémon data live in memory.
Setting Up Codes on Real Hardware
Using an RRD device, you insert the cartridge, power on, and access the cheat menu through the device's overlay. You select the code, enable it, then launch the game. The codes activate immediately. For item duplication, the standard procedure is to save, go to a PC, withdraw the item you want to copy, enable the duplication code, return to the item box, duplicate the item, save again, and reload. That last reload is critical because some codes only write their changes to RAM, not to the save file itself until you trigger a full save cycle. With a CTR cart, the process is similar but you're loading a different code database. The CTR's code list tends to be more up-to-date because the community has been maintaining it longer than the RRD lists. I've found that RRD code sets for Ultra Moon often contain duplicates and outdated entries that conflict with each other, which can cause the game to soft-lock or produce corrupted save data. When this happens, the game either freezes mid-save or your box data becomes unreadable on the next boot. The workaround I ended up using was to strip the code list down to only the entries I actually needed. I kept maybe thirty codes total, removed any that had version notes attached, and tested them one at a time in a fresh save file before relying on them. This took about twenty minutes of setup but saved me from losing a six-month save file. I learned that after my first corrupted save from enabling a full code dump without filtering.
Get the Full Details

Encounter and Shiny Codes
The encounter manipulation codes work by overwriting the PID (Personality ID) generation routine in memory. When you trigger an encounter with the code active, the game pulls a modified PID that determines species, IVs, nature, and shininess. The most reliable method is the PID roll code, which lets you cycle through possible PIDs until you get the result you want. It's slower than a randomizer but gives you actual control over the outcome rather than relying on probability. For IV manipulation, there are codes that let you set individual IV values before encountering a wild Pokémon or hatching an egg. These target specific memory addresses where the IV calculation happens. The code writes the values into RAM, and when the game generates the encounter, it reads from those addresses instead of the random seed. This is how people get perfect IV spreads without the usual breeding grind. The bottleneck is that these codes only affect the next encounter, so you have to enable the code, trigger the encounter, and hope the game processes it correctly before the next random event overwrites the memory. Friendship codes are simpler. They target the friendship value stored in the Pokémon data structure and write a specific number to it. Setting it to 255 means any evolution that requires high friendship will trigger immediately. The code works by writing directly to the save buffer in RAM, which persists through saves as long as you don't trigger another friendship-modifying event like using a happiness-boosting item, which would overwrite your manual entry.
Common Problems and What Actually Breaks
The biggest issue with Pokemon Ultra Moon cheats on real hardware is save file corruption, and it's not rare. I had a case where using an item duplication code while the game was mid-animation caused the save to become unreadable. The code wrote partial data to the save buffer, and when the game tried to commit it, the CRC check failed. The save was gone. You need to make sure the game is in a static state before activating any code that writes to save memory. Pause in a menu, not during a battle animation or cutscene. Another problem is code conflicts. When two codes target the same memory address, one overwrites the other unpredictably. This is especially common with codes that modify the same subsystem, like two different item codes trying to manipulate the same item storage pointer. If you enable multiple codes, make sure they're from different categories and don't share address ranges. Most code databases list the address for each entry, so you can cross-reference them manually. Emulator cheats have their own set of issues. Yuzu's cheat implementation occasionally misaligns addresses when the game's memory layout changes due to dynamic allocation. This is rare but happens more frequently when you're using a custom build of the emulator rather than the stable release. If your codes seem to apply but nothing changes in-game, try a different emulator build or switch to the raw cheat format instead of the enhanced format.
There's also the issue of online play. Using cheats on a modified save when connecting to any online service will flag your save data. Nintendo's servers don't actively scan for cheat-modified Pokémon Ultra Moon saves the way they do for Switch titles, but community-run services and trading platforms can and do reject suspicious IV spreads or event distributions. If you're trading or battling with cheat-altered Pokémon, expect to be flagged or banned from third-party ladders.

What You Should Know Before Starting
Cheats are not a substitute for understanding the game's mechanics. Knowing how PID randomization works, how IV inheritance is calculated, and how the friendship system tracks values will help you use codes more effectively than blindly enabling everything in a code list. The codes are just shortcuts to memory manipulation. If you understand what each code is doing at the memory level, you can troubleshoot when something goes wrong instead of just reloading from backup. Backup your save file before enabling any code for the first time. On a 3DS, you can use Homebrew Launcher tools like Checkpoint to dump the save to your SD card. On emulator, just save the savestate before making any changes. Both methods take under thirty seconds and prevent you from losing progress when a code corrupts your file, which happens more often than the code databases admit. The most practical advice is to start small. Enable one code at a time, test it in a non-critical save, verify it works as expected, and only then move to more complex modifications. Rushing through code setup with multiple active codes is how people end up with soft-locked games or corrupted saves that take hours to recover from, if recovery is even possible.