TIDEZINE.

PS2 Original Security Chip SPC970 Fully Cracked, 25-Year-Sealed Code Exposed for the First Time

Developer DiscoStarslayer and collaborator Libby found an EEPROM write exploit, spending four years to finally read out the original PS2's MechaCon security chip firmware. 22 image files have now been uploaded to GitHub.

PS2 Original Security Chip SPC970 Fully Cracked, 25-Year-Sealed Code Exposed for the First Time

Making an EEPROM rated for just 1,000 write cycles last until the very end was the key to pulling off this crack. In a Bluesky post, developer DiscoStarslayer revealed that the exploit he and collaborator Libby discovered finally allowed the full firmware of the SPC970 MechaCon chip — the component responsible for disc verification and most security functions on the original "fat" PlayStation 2 — to be completely read out. This marks the first time anyone has seen the code inside this chip since it was born back in 2000.

Before this, a group had spent roughly four years going the slower route: physically decapping the chip package and reading its contents directly, but only managing to pull rough, incomplete dumps. Libby's exploit took a different path — first triggering an EEPROM configuration write process and telling the chip the number of data blocks to be written next is zero, causing an internal counter to underflow. Then, by sending data exceeding the buffer's capacity, the overflow spills into the RAM region storing the EEPROM write task, overwriting that task's source address to point it at the chip's own ROM. The result: MechaCon mistakenly copies its own 256-byte firmware into EEPROM, after which the PS2 can read it back out using standard commands. Repeating this process roughly 1,000 times eventually assembles the complete 256KB firmware image, saved onto a USB drive.

The catch is that EEPROM has no wear leveling, and its write endurance is far lower than flash — every dump chips away at its remaining lifespan. To account for this, the dump tool first backs up the EEPROM's contents, restores them byte-for-byte afterward, and verifies against the chip's boot-time checksum routine for confirmation. Even so, Libby's original dumper documentation spells out the risk plainly: the process could leave the PS2 "non-functional or in need of hardware-level repair," with users assuming the risk themselves.

PS2 Original Security Chip SPC970 Fully Cracked, 25-Year-Sealed Code Exposed for the First Time

22 Image Files Fill in the Pieces MechaPwn Left Behind

All the results have now been uploaded to GitHub, including 22 firmware image files spanning everything from the Japan-exclusive SCPH-15000 from 2000 to the 39000-series fat PS2 from 2002, as well as the Namco System 246 and 256 arcade boards that use the same chip. The later "Dragon" version of the MechaCon chip, adopted after 2003, had actually already been read back in 2021, giving rise a month later to the MechaPwn exploit that let PS2 units be region-unlocked and read backup discs. But MechaPwn's README made clear at the time that earlier models not using the Dragon chip were unsupported, with no plans to support them — affecting roughly 20 models released between 2000 and 2003. While these early units could still run backups through memory card and hard drive exploits, the chip itself remained unlockable at the hardware level, simply because no one had ever seen its code — until now.

Since PS2 game discs themselves were never encrypted, this firmware dump won't "unlock" anything for game piracy purposes. What it actually exposes is the code behind Sony's "MagicGate" memory card encryption scheme, along with the logic underlying KELF, the executable file format the PS2 uses to boot from discs and memory cards. Contributor uyjulian notes that this information could eventually feed into "full system-level low-level emulation." Currently, emulators like PCSX2 don't actually execute MechaCon's code — instead, they reimplement its instruction set in C++ and read a 1KB NVRAM file along with a four-byte version number as stand-in data. DiscoStarslayer himself maintains a PCSX2 fork called Reliquary, dedicated to PS2's verification processes, and its README acknowledges that when security checks need to match console identity, the generated stand-in data cannot substitute for genuine hardware values.

The next goal, according to uyjulian, is to find a MechaPwn-style exploit capable of unlocking the SPC970 — though progress won't come as fast as it did with the Dragon chip. Researchers back then cracked the Dragon chip in just a month because Sony had designed it to accept firmware updates, effectively leaving behind a weakness that could be found and exploited. SPC970 is nothing like that — its code was burned into mask ROM back in 2000 and has never been altered since, meaning there's no equivalent update mechanism to attack.

Related

iPhone 18 Pro Max Hit by SOS Signal Bug — Apple Confirms AT&T Users Need Update or Replacement
Tech

iPhone 18 Pro Max Hit by SOS Signal Bug — Apple Confirms AT&T Users Need Update or Replacement

Apple has confirmed that some iPhone 18 Pro Max units on AT&T's network are losing signal and showing "SOS" instead. An iOS 27.0.1 patch is out now, but devices already affected will need a hardware swap.

Paramount-Warner Bros. Merger Officially Named Skydance, Ellison Announces Personally
Tech

Paramount-Warner Bros. Merger Officially Named Skydance, Ellison Announces Personally

The $110 billion Paramount-Warner Bros. merger has officially been named Skydance, with CEO David Ellison announcing the news himself in the very first post on his newly created X account. The deal is expected to close by the end of this month.

NYC Rolls Out America's First "Click-to-Cancel" Rule, Violators Face Minimum $525 Fine
Tech

NYC Rolls Out America's First "Click-to-Cancel" Rule, Violators Face Minimum $525 Fine

Starting October 1, New York City is implementing the nation's first city-level "click-to-cancel" law, requiring businesses to make canceling subscriptions as easy as signing up — or face civil penalties and mandatory refunds.

A24 Crosses the SCP Community's Red Line, Neon Steps In with Open-License Promise for Horror Anthology
Tech

A24 Crosses the SCP Community's Red Line, Neon Steps In with Open-License Promise for Horror Anthology

A24 sparked controversy after announcing an SCP Foundation adaptation without community consent. Neon, the studio behind "Parasite" and "Anora," has since stepped in with plans for a similar project, promising to follow CC BY-SA licensing for a horror anthology film set for 2027.

Amazon's New Fire TV Stick 4K Touts Faster Boot Times, Slimmer Body, While New Remote Goes by Feel
Tech

Amazon's New Fire TV Stick 4K Touts Faster Boot Times, Slimmer Body, While New Remote Goes by Feel

Amazon has launched its next-gen Fire TV Stick 4K, claiming boot and launch speeds 20% to 40% faster than similarly priced competitors. It's priced at $60, dropping to $30 during Prime Big Deal Days.

Xbox Launches Mythic Achievements, Finally Scratching That Decade-Long Platinum Trophy Itch
Tech

Xbox Launches Mythic Achievements, Finally Scratching That Decade-Long Platinum Trophy Itch

Xbox has unveiled a new system called Mythic Achievements, awarded to players who fully complete a game's original achievement list. The system retroactively applies all the way back to Xbox 360-era titles, though it's currently only available to Xbox Insider testers.