The security processor at the heart of early PlayStation 2 consoles has been reverse engineered, ending a two-decade stretch in which the chip's code could not be read. A developer known as DiscoStarslayer extracted firmware from the SPC970 MechaCon, the component that authorizes discs and handles most of the console's security. The work covers 22 firmware images pulled from fat PS2 units sold between 2000 and 2002. Everything has been published on GitHub.

DiscoStarslayer credited a collaborator named Libby with finding the exploit that made the extraction possible. Documentation for the dump tool describes how the exploit tells the chip that an incoming batch of settings data will be empty, then sends more data than the chip has room for. Earlier attempts relied on a slower method of stripping the chip's packaging and reading it directly, a roughly four-year effort that yielded only rough dumps.

The SPC970 keeps its code in mask ROM, which cannot be written or patched, and stores calibration and configuration data in a separate 1KB EEPROM. The enthusiast group behind the tool, spc970-dumper-union, abused the way the chip writes to that EEPROM. Opening a configuration write session with a block count of zero underflows the chip's internal counter, and sending more data than the seven-block buffer holds overflows into the RAM that runs the EEPROM write task. Overwriting that task's source address points it at the chip's ROM, so the MechaCon copies 256 bytes of its firmware into the EEPROM, where the PS2 can read it back with a standard command. About 1,000 repetitions produce a full 256KB image on a USB stick.

Each pass rewrites the EEPROM, and every dump shortens its life because it has no wear leveling and a smaller write budget than flash memory. The tool backs up the EEPROM before starting, restores it word by word afterward and checks the result against the chip's power-on checksum routine. Libby's original dumper still warns that the process can leave a PS2 unable to operate normally or in need of hardware-level repair.

The images cover fat PS2s from the Japan-only SCPH-15000 of 2000 to the 39000-series models of 2002, plus the Namco System 246 and 256 arcade boards that used the same chip. These machines were among the last unread parts of the PS2 after the 2003 Dragon MechaCon was dumped in 2021. That exploit's documentation says older consoles do not use a Dragon-based MechaCon and are not supported, with no support planned, affecting roughly 20 model numbers from the console's first three years.

The firmware alone cannot support an optical drive emulator, but it could aid a modchip that replaces the MechaCon while keeping the drive's DSP to read discs. Since PS2 games were not encrypted, nothing new is unlocked, though the code behind Sony's MagicGate encryption for memory cards and KELF executables is now exposed. Contributor uyjulian said that will eventually feed full-system low-level emulation. PCSX2 and similar emulators do not run the chip's code at all, instead reimplementing its commands in C++ and reading a 1KB NVRAM file and a four-byte version number from disk.

Uyjulian said a MechaPwn or TonyHax-style unlock for the SPC970 is a goal, but it will not arrive as quickly. Dragon took researchers a month to crack because Sony designed that chip to accept patches. The SPC970 cannot be updated at all; its code was baked into the chip in 2000 and has never changed.

More hardware news from TechManNews.