PS2 Original Security Chip SPC970 Fully Cracked, 25-Year-Sealed Code Exposed for the First Time
Developer DiscoStarslayer and collaborator Libby found an EEPROM write exploit, spending four years to finally read out the original PS2's MechaCon security chip firmware. 22 image files have now been uploaded to GitHub.
Making an EEPROM rated for just 1,000 write cycles last until the very end was the key to pulling off this crack. In a Bluesky post, developer DiscoStarslayer revealed that the exploit he and collaborator Libby discovered finally allowed the full firmware of the SPC970 MechaCon chip — the component responsible for disc verification and most security functions on the original "fat" PlayStation 2 — to be completely read out. This marks the first time anyone has seen the code inside this chip since it was born back in 2000.
Before this, a group had spent roughly four years going the slower route: physically decapping the chip package and reading its contents directly, but only managing to pull rough, incomplete dumps. Libby's exploit took a different path — first triggering an EEPROM configuration write process and telling the chip the number of data blocks to be written next is zero, causing an internal counter to underflow. Then, by sending data exceeding the buffer's capacity, the overflow spills into the RAM region storing the EEPROM write task, overwriting that task's source address to point it at the chip's own ROM. The result: MechaCon mistakenly copies its own 256-byte firmware into EEPROM, after which the PS2 can read it back out using standard commands. Repeating this process roughly 1,000 times eventually assembles the complete 256KB firmware image, saved onto a USB drive.
The catch is that EEPROM has no wear leveling, and its write endurance is far lower than flash — every dump chips away at its remaining lifespan. To account for this, the dump tool first backs up the EEPROM's contents, restores them byte-for-byte afterward, and verifies against the chip's boot-time checksum routine for confirmation. Even so, Libby's original dumper documentation spells out the risk plainly: the process could leave the PS2 "non-functional or in need of hardware-level repair," with users assuming the risk themselves.
22 Image Files Fill in the Pieces MechaPwn Left Behind
All the results have now been uploaded to GitHub, including 22 firmware image files spanning everything from the Japan-exclusive SCPH-15000 from 2000 to the 39000-series fat PS2 from 2002, as well as the Namco System 246 and 256 arcade boards that use the same chip. The later "Dragon" version of the MechaCon chip, adopted after 2003, had actually already been read back in 2021, giving rise a month later to the MechaPwn exploit that let PS2 units be region-unlocked and read backup discs. But MechaPwn's README made clear at the time that earlier models not using the Dragon chip were unsupported, with no plans to support them — affecting roughly 20 models released between 2000 and 2003. While these early units could still run backups through memory card and hard drive exploits, the chip itself remained unlockable at the hardware level, simply because no one had ever seen its code — until now.
Since PS2 game discs themselves were never encrypted, this firmware dump won't "unlock" anything for game piracy purposes. What it actually exposes is the code behind Sony's "MagicGate" memory card encryption scheme, along with the logic underlying KELF, the executable file format the PS2 uses to boot from discs and memory cards. Contributor uyjulian notes that this information could eventually feed into "full system-level low-level emulation." Currently, emulators like PCSX2 don't actually execute MechaCon's code — instead, they reimplement its instruction set in C++ and read a 1KB NVRAM file along with a four-byte version number as stand-in data. DiscoStarslayer himself maintains a PCSX2 fork called Reliquary, dedicated to PS2's verification processes, and its README acknowledges that when security checks need to match console identity, the generated stand-in data cannot substitute for genuine hardware values.
The next goal, according to uyjulian, is to find a MechaPwn-style exploit capable of unlocking the SPC970 — though progress won't come as fast as it did with the Dragon chip. Researchers back then cracked the Dragon chip in just a month because Sony had designed it to accept firmware updates, effectively leaving behind a weakness that could be found and exploited. SPC970 is nothing like that — its code was burned into mask ROM back in 2000 and has never been altered since, meaning there's no equivalent update mechanism to attack.