← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Original PlayStation 2 Security Chip SPC970 MechaCon Reverse Engineered

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • SPC970 MechaCon chip firmware extracted from original PlayStation 2.
  • Exploit involved overflowing a buffer during EEPROM write operations.
  • Firmware images for fat PS2 models and Namco arcade boards released.
  • This completes the reverse engineering of the fat PS2's unmapped parts.

Firmware Extraction Achieved

Developer DiscoStarslayer, aided by collaborator Libby, has successfully reverse engineered the SPC970 MechaCon chip found in the original PlayStation 2. This chip manages disc authorization and console security. The effort involved extracting the firmware, which had previously been a challenging task for over four years.

Exploit Details

The breakthrough came from an exploit that manipulated the chip's EEPROM write process. By initiating a configuration write session with a zero block count, the chip's internal counter underflowed. Sending more data than the buffer could hold caused an overflow into RAM, redirecting the EEPROM write task to the chip's mask ROM. This allowed 256 bytes of firmware to be copied into the EEPROM, which could then be read by the PS2 using standard commands. The full 256KB image was assembled after approximately 1,000 such passes.

Released Data and Scope

The extracted firmware and associated tools have been published on GitHub. The release includes 22 firmware images covering fat PS2 models, from the Japan-only SCPH-15000 (2000) to the 39000-series models (2002). The data also covers Namco System 246 and 256 arcade boards, which utilized the same chip. This achievement marks the dumping of the final unread parts of the fat PS2, following the 2021 dumping of the 2003 "Dragon" MechaCon.

Risks and Safeguards

Each pass of the dumping process rewrites the EEPROM, which has a limited write budget and no wear leveling, potentially shortening its lifespan. To mitigate this, the dumper tool backs up the EEPROM before starting and restores it word by word afterward, verifying the result with the chip's power-on checksum routine. Despite these precautions, a risk of rendering the PS2 inoperable or requiring hardware repair remains, as noted in Libby's original dumper.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~23 min · 20 stories · Oct 03

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

A developer named DiscoStarslayer, with collaborator Libby, successfully extracted firmware from the SPC970 MechaCon chip in the original PlayStation 2, a component responsible for disc authorization and security. This reverse engineering effort, which took four years, completes the dumping of the last unmapped part of the fat PS2, providing insights into its security mechanisms.