Laser pulses crack Raspberry Pi RP2350's permanent debug lock, exposing Secure world

Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure Debug

Laser pulses crack Raspberry Pi RP2350's permanent debug lock, exposing Secure world

Ledger Donjon used photon-emission microscopy to pinpoint the register that re-enables debug on Raspberry Pi's RP2350, then fired laser pulses at two nearby spots to set the bits, restoring Secure debug access despite a permanent disable flag. After a rescue reset halted firmware before its runtime lock, they read a secret from one-time-programmable memory. The attack needs physical access, destructive chip preparation, and about $250,000 in lab gear.

Once both bits were set, they remained set without further pulses or software writes.
  1. BitBangingBytes

    I appreciate all the details they provide in the post. The $250k in lab gear is useful when initially discovering, exploiting and documenting attacks like this.

    Definitely doable in a home lab for under $25k in equipment, likely under $10k.

    Same as my replicating Colin O’Flynn’s BAM BAM attack on a MPC5566 chip, he used a ChipShouter ($5,000) and I used a PicoEMP ($50).

    https://youtu.be/URmI1VVilek

  2. byb

    The RP2350's secure enclave made it particularly attractive for use as a Yubikey alternative.

    There will always be an arms race between safe-crackers and safe-builders. Presumably the lessons learned will help make the next generation tougher to break into.

  3. jacquesm

    That's reminiscent of when we first found out that if you opened up dram chips you could use them for imaging. Of course the scale at which this is done is extremely impressive.

  4. stackghost

    > The attack requires physical access, destructive preparation, and approximately $250,000 of laboratory equipment.

    Not super practical, but neat attack

  5. Fred27

    There's always an XKCD...

    https://xkcd.com/538/

More from this day

2026-09-18