MikhbarMIKHBAR
Computing

Original PlayStation 2 Security Chip Reverse Engineered

The final unmapped hardware component of the original fat PlayStation 2 has finally been successfully decoded after a multi-year effort.

Original PlayStation 2 Security Chip Reverse Engineered

Decoding the Stubborn SPC970 Chip

More than 25 years after the fat PlayStation 2 launched, a developer known as DiscoStarslayer has successfully pulled firmware from the stubborn SPC970 MechaCon chip, which is responsible for authorizing discs and handling most of the console's security. This achievement represents a major milestone for retro hardware fans and modders.

In a Bluesky post, the developer credited Libby, a collaborator who discovered the exploit that made the extraction possible. According to the dump tool's docs, that exploit tricked the chip by claiming an incoming batch of settings data would be empty, while sending more data than the chip's buffer had room to hold. Prior to this, researchers spent about four years struggling with a slower packaging-stripping method that only produced rough dumps.

GitHub Release and Firmware Coverage

The extracted data has been published on GitHub by the "spc970-dumper-union" enthusiast group alongside 22 firmware images. These images cover fat PlayStation 2 consoles ranging from the Japan-only SCPH-15000 model released in 2000 up to the 39000-series models from 2002. They also cover the Namco System 246 and 256 arcade boards that utilized the same chip.

These early machines represented some of the final unread parts of the console hardware following the successful 2021 dump of the 2003 "Dragon" MechaCon. Because the SPC970 chip stores its code in mask ROM that cannot be written or patched—maintaining only calibration and config data in a separate 1KB EEPROM—researchers had to find an alternative technical pathway to extract the data.

An original "fat" PlayStation 2 console.
Image related to the report from Engadget · Source: Engadget

Exploiting the EEPROM Write Mechanism

To bypass the read limitations, the enthusiast group abused the way the chip writes to its EEPROM storage. By opening a config write session with a block count of zero, the internal counter underflowed, allowing data exceeding the seven-block buffer to overflow into the RAM holding the EEPROM write task.

This action redirected the task's source address toward the chip's ROM, prompting the MechaCon to copy 256 bytes of its firmware into the EEPROM. Once stored there, the console could read it back using a standard command. Repeating this process roughly 1,000 times successfully placed a full 256KB image onto a connected USB stick.

Closeup of a Sony Computer Entertainment, Inc. chip.
Image related to the report from Engadget · Source: Engadget

Hardware Risks and Preservation Warnings

Because each of the 1,000 passes rewrites the EEPROM, the process shortens the hardware's lifespan due to a smaller write budget and a lack of wear leveling. To mitigate this risk, Libby's original dumper backs up the EEPROM beforehand, restoring it word by word after completion and verifying the result against the chip's power-on checksum routine.

Despite these safeguards, a risk remains. The original dumper documentation warns that the process can leave a console unable to operate normally or require hardware-level repair, advising users to proceed entirely at their own risk.

Implications for Emulation and Modding

While Dragon MechaCon firmware images were released back in 2021 alongside the MechaPwn exploit that made later consoles region-free, older machines lacked support because nobody could inspect their code. These new dumps make searching for hardware weaknesses possible for the first time on early model numbers manufactured between 2000 and 2003.

Contributor uyjulian noted that while the images alone are insufficient to build an optical drive emulator, they could support a modchip that replaces the MechaCon while retaining the drive's digital signal processor to read discs. The firmware also exposes code behind Sony's MagicGate encryption for memory cards and KELF executables.

Sources

  • EngadgetThe original PlayStation 2 security chip has been reverse engineered

Continue chronologically

Related entity coverage