· · Single source ·Updated

DiscoStarslayer reverse engineers original PlayStation 2 security chip firmware

Developer DiscoStarslayer has successfully dumped the last unmapped firmware from the original PlayStation 2 SPC970 security chip.

The original PlayStation 2 security chip has been reverse engineered
File photo The original PlayStation 2 security chip has been reverse engineered Photo: Engadget

New exploit enables data extraction

The developer used a collaborator named Libby to find an exploit that allowed the extraction process. This method sent more data than the chip could hold to trick it into dumping settings. Previous attempts over four years produced only rough dumps using slower physical methods.

Files cover multiple console models

The released dump tool includes 22 firmware images for fat PS2 units made between 2000 and 2002. The collection also covers arcade boards like the Namco System 246 that used the same chip. These files represent the final unread parts of the console after the 2003 Dragon model was dumped in 2021.

Technical details on memory storage

The SPC970 chip stores its code in mask ROM which cannot be patched or written. Only calibration and configuration data reside in a separate 1KB EEPROM within the device. The enthusiast group abused how the chip writes to that specific memory area.

Reported by one outlet

Only one outlet has published this. Nothing here has been checked against a second report, so read it as that outlet's account and follow the link below for the original.

Reported by

1 independent outlet. Headline as published. Links open the original report.