Yep, just a very simple nRF52840 BLE sniffer :)
05.02.2026 22:50 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0@stacksmashing.bsky.social
Security researcher with a focus on hardware & firmware. I occasionally publish stuff on YouTube. Co-founder of hextree.io. Contact: contact@stacksmashing.net
Yep, just a very simple nRF52840 BLE sniffer :)
05.02.2026 22:50 โ ๐ 1 ๐ 0 ๐ฌ 0 ๐ 0Fancy, the board-house sent me x-rays of my PCBs!
05.02.2026 18:03 โ ๐ 22 ๐ 0 ๐ฌ 1 ๐ 0We were able to find some minor correlations, but by far not enough to leak the key successfully.
If you think you found something - even if it's not a full attack - send an e-mail, it's about making the implementation more secure, not about building the best attack.๐ก๏ธ
My first post on the RaspberryPi Blog ๐
We've extended the RP2350 side-channel hacking challenge to April 30 - and even better: To make attacks for the challenge easier, we decided to disable the random chaffing and some more mitigations!
www.raspberrypi.com/news/rp2350-...
The one on the stands is just a random QFP carrier i had on my desk - the one on the bottom is my PCBite plate :)
01.02.2026 13:12 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0Yeah I have a script that takes multiple dumps and then creates one "true" dump with the most likely bytes from multiple dumps.
It also logs out outliers which is helpful!
The PCB is suuuper sensitive. I ripped off three pads so far... To get to chip-select I had to solder onto the tiny tiny tiny via barrel๐ตโ๐ซ
28.01.2026 20:25 โ ๐ 9 ๐ 0 ๐ฌ 0 ๐ 09d3e36fc632d77f24c810cb89892dd1959dfb05b output.bin
(Created from multiple dumps, something is messing with the signal)
lfg
28.01.2026 17:25 โ ๐ 17 ๐ 0 ๐ฌ 1 ๐ 0Pokey dokey
28.01.2026 17:24 โ ๐ 15 ๐ 0 ๐ฌ 2 ๐ 0For those playing along at home: Preliminary flash pin-out!
13 - SPI Flash CLK
16 - SPI Flash DI / MOSI
18 - SPI Flash DO / MISO
19 - SPI Flash VCC
20 - SPI Flash CS
Pulled off the flash and soldered on some magnet-wire on all of the pins to get a decent pin-out. This stuff is smol! ๐ค
28.01.2026 13:22 โ ๐ 20 ๐ 0 ๐ฌ 1 ๐ 0Numbered the test-pins on the back of the device - let's try to document the signals!
28.01.2026 12:11 โ ๐ 19 ๐ 0 ๐ฌ 1 ๐ 0But there's at least something to dump - the SPI flash chip seems to be a Winbond W25Q64
28.01.2026 12:03 โ ๐ 21 ๐ 0 ๐ฌ 2 ๐ 0Apple proprietary 339M00340
28.01.2026 12:00 โ ๐ 2 ๐ 0 ๐ฌ 0 ๐ 0Now interestingly this chip variant - CKABD0 - does not appear in the official datasheet.
Package variant: CK (WLCSP)
Function variant: AB - not listed in the datasheet
Hardware revision: D
Production device identifier: 0
Likely that this version has enhanced AP protection ๐ญ
Now, the question we've all been wondering: Which microcontroller did they use this time?
It's the NRF52840 - a chip very similar to the one in the first AirTag - and that, at least in earlier revisions, is vulnerable to the same fault-injection attack!
Time to dive in!
On the other side we have again have a plastic cover - and we can already see the UWB shine through (the silver thing) and a nice antenna connection!
28.01.2026 11:41 โ ๐ 17 ๐ 0 ๐ฌ 2 ๐ 0Not much new on the backside! The accelerometer (black blob on top) seems to still be there, and otherwise just caps.. And a lot of test-points that look quite similar to the ones from the first AirTag (see second picture of the first generation by Colin O'Flynn)
28.01.2026 11:38 โ ๐ 20 ๐ 0 ๐ฌ 1 ๐ 0The new AirTags 2 just arrived!
Time to take them apart ๐งต
The last thing the chip sees before JTAG gets re-enabled
28.12.2025 14:25 โ ๐ 8 ๐ 0 ๐ฌ 0 ๐ 0Pink laser safety glasses
Laser fault-injection drip just dropped
28.12.2025 14:21 โ ๐ 11 ๐ 0 ๐ฌ 3 ๐ 0Also, if you are interested in trying the second @Raspberry_Pi Hacking Challenge hit me up - I have some target boards with me!
www.hextree.io/rp2350-hacki...
En route to #39c3 - come to our talk at 4pm!
I will only be there today and tomorrow, but happy to meet-up & chat.
Also, if you are at #39c3 and often dump SPI flash-chips please let me know, I might have something for you that I'm looking for feedback on ๐
Rust removal on Oldtimer
Work: Fix rust issues ๐ฆ
Hobby: Fix rust issues ๐จโ๐ญ
๐ญ
Should be pushed :) thanks
17.09.2025 15:44 โ ๐ 0 ๐ 0 ๐ฌ 1 ๐ 0Call for flash-chips at DEF CON!
If you have leftover or rare SPI flash-chips that I can have for testing some tooling Iโm building Iโd be very thankful.
Also if you have devices where you had trouble dumping in-system Iโd love to give it a try. Iโll be at Embedded Systems Village :)
DigiKey goes brrrrrrrt
05.08.2025 20:38 โ ๐ 46 ๐ 1 ๐ฌ 2 ๐ 0