Hackaday · Creativity & design
Laser Attack Bypasses RP2350 Security Features
A security team has successfully used a laser to bypass the debug security of the RP2350 microcontroller, a chip designed with features like secure boot and TrustZone.

The Ledger Donjon security team employed a sophisticated setup, including a focused laser, to target a specific register that enables the RP2350's debug features. This register was identified by decapsulating the chip and examining its die using photon-emission electron microscopy.
The laser fault injection attack was performed on a back-decapped chip, with infrared light shone through the silicon wafer. This method allowed the team to precisely target and flip bits in the register, thereby restoring access to the secure execution zone.
Following the successful bypass, the team reset the chip and retrieved a 128-bit secret hidden in memory as part of a hacking challenge set by the Pi Foundation.
This exploit highlights the ongoing challenge of hardware security, as determined attackers can often find ways to compromise even well-protected microcontrollers.
The effort required for this specific attack on the RP2350 is noted as impressive, especially considering the chip's built-in defenses like glitch detection, which are designed to thwart traditional methods such as power glitching.
AI-samenvatting op basis van de bron.
Hackaday