ÉTAT HER

25 Years Later, PS2's Original SPC970 Security Chip Finally Gives Up Its Secrets

After a four-year effort, developer DiscoStarslayer and collaborator Libby exploited an EEPROM write flaw to extract firmware from the original PS2's MechaCon security chip, posting 22 image files to GitHub.

25 Years Later, PS2's Original SPC970 Security Chip Finally Gives Up Its Secrets

Making an EEPROM rated for just 1,000 write cycles last until the very end was the key to pulling off this crack. In a Bluesky post, developer DiscoStarslayer revealed that the exploit he and collaborator Libby discovered finally allowed the full firmware of the SPC970 MechaCon chip — the component responsible for disc verification and most security functions on the original "fat" PlayStation 2 — to be completely read out. This marks the first time anyone has seen the code inside this chip since it was born back in 2000.

Before this, a group had spent roughly four years going the slower route: physically decapping the chip package and reading its contents directly, but only managing to pull rough, incomplete dumps. Libby's exploit took a different path — first triggering an EEPROM configuration write process and telling the chip the number of data blocks to be written next is zero, causing an internal counter to underflow. Then, by sending data exceeding the buffer's capacity, the overflow spills into the RAM region storing the EEPROM write task, overwriting that task's source address to point it at the chip's own ROM. The result: MechaCon mistakenly copies its own 256-byte firmware into EEPROM, after which the PS2 can read it back out using standard commands. Repeating this process roughly 1,000 times eventually assembles the complete 256KB firmware image, saved onto a USB drive.

The catch is that EEPROM has no wear leveling, and its write endurance is far lower than flash — every dump chips away at its remaining lifespan. To account for this, the dump tool first backs up the EEPROM's contents, restores them byte-for-byte afterward, and verifies against the chip's boot-time checksum routine for confirmation. Even so, Libby's original dumper documentation spells out the risk plainly: the process could leave the PS2 "non-functional or in need of hardware-level repair," with users assuming the risk themselves.

PS2 Original Security Chip SPC970 Fully Cracked, 25-Year-Sealed Code Exposed for the First Time

22 Image Files Fill in the Pieces MechaPwn Left Behind

All the results have now been uploaded to GitHub, including 22 firmware image files spanning everything from the Japan-exclusive SCPH-15000 from 2000 to the 39000-series fat PS2 from 2002, as well as the Namco System 246 and 256 arcade boards that use the same chip. The later "Dragon" version of the MechaCon chip, adopted after 2003, had actually already been read back in 2021, giving rise a month later to the MechaPwn exploit that let PS2 units be region-unlocked and read backup discs. But MechaPwn's README made clear at the time that earlier models not using the Dragon chip were unsupported, with no plans to support them — affecting roughly 20 models released between 2000 and 2003. While these early units could still run backups through memory card and hard drive exploits, the chip itself remained unlockable at the hardware level, simply because no one had ever seen its code — until now.

Since PS2 game discs themselves were never encrypted, this firmware dump won't "unlock" anything for game piracy purposes. What it actually exposes is the code behind Sony's "MagicGate" memory card encryption scheme, along with the logic underlying KELF, the executable file format the PS2 uses to boot from discs and memory cards. Contributor uyjulian notes that this information could eventually feed into "full system-level low-level emulation." Currently, emulators like PCSX2 don't actually execute MechaCon's code — instead, they reimplement its instruction set in C++ and read a 1KB NVRAM file along with a four-byte version number as stand-in data. DiscoStarslayer himself maintains a PCSX2 fork called Reliquary, dedicated to PS2's verification processes, and its README acknowledges that when security checks need to match console identity, the generated stand-in data cannot substitute for genuine hardware values.

The next goal, according to uyjulian, is to find a MechaPwn-style exploit capable of unlocking the SPC970 — though progress won't come as fast as it did with the Dragon chip. Researchers back then cracked the Dragon chip in just a month because Sony had designed it to accept firmware updates, effectively leaving behind a weakness that could be found and exploited. SPC970 is nothing like that — its code was burned into mask ROM back in 2000 and has never been altered since, meaning there's no equivalent update mechanism to attack.

Related

Apple Admits iPhone 18 Pro Max Glitch Leaves AT&T Users Stuck on 'SOS'
lifestyle

Apple Admits iPhone 18 Pro Max Glitch Leaves AT&T Users Stuck on 'SOS'

A signal bug on some iPhone 18 Pro Max devices running AT&T has been confirmed by Apple. While iOS 27.0.1 fixes the issue going forward, phones already affected will need a hardware swap.

Ellison Personally Reveals Skydance as Official Name for Paramount-Warner Bros. Merger
lifestyle

Ellison Personally Reveals Skydance as Official Name for Paramount-Warner Bros. Merger

In the very first post on his newly created X account, CEO David Ellison himself disclosed that the $110 billion Paramount-Warner Bros. merger has officially been named Skydance, with the deal expected to close by the end of this month.

Stuck in a Subscription You Can't Escape? NYC Just Made That Illegal
lifestyle

Stuck in a Subscription You Can't Escape? NYC Just Made That Illegal

As of October 1, New York City enforces the nation's first "click-to-cancel" ordinance, forcing companies to let you exit a subscription as easily as you joined. Non-compliant businesses risk fines starting at $525 and must issue refunds.

What to know | A24 Crosses the SCP Community's Red Line, Neon Steps In with Open-License Promise for Horror Anthology
lifestyle

What to know | A24 Crosses the SCP Community's Red Line, Neon Steps In with Open-License Promise for Horror Anthology

The key details: A24 sparked controversy after announcing an SCP Foundation adaptation without community consent. Neon, the studio behind "Parasite" and "Anora," has since stepped in with plans for a similar project, promising to follow CC BY-SA licensing for a horror anthology film set for 2027.

What to know | Amazon's New Fire TV Stick 4K Touts Faster Boot Times, Slimmer Body, While New Remote Goes by Feel
lifestyle

What to know | Amazon's New Fire TV Stick 4K Touts Faster Boot Times, Slimmer Body, While New Remote Goes by Feel

The key details: Amazon has launched its next-gen Fire TV Stick 4K, claiming boot and launch speeds 20% to 40% faster than similarly priced competitors. It's priced at $60, dropping to $30 during Prime Big Deal Days.

Mythic Achievements Arrives on Xbox, Answering a Decade-Plus Wish for Platinum Trophy-Style Recognition
lifestyle

Mythic Achievements Arrives on Xbox, Answering a Decade-Plus Wish for Platinum Trophy-Style Recognition

A new Xbox system, Mythic Achievements, rewards players who unlock every achievement originally listed for a game. Its coverage stretches retroactively back to Xbox 360-era releases, though for now only Xbox Insider testers can access it.