Laser Your Way Into Debug Mode On The RP2350

Security researchers from Ledger Donjon successfully bypassed the RP2350 microcontroller's security features using laser fault injection. By decapsulating the chip and targeting specific registers with a laser, they were able to gain unauthorized access to secure memory.
Why it matters
This highlights the ongoing cat-and-mouse game between hardware security designers and researchers, demonstrating that even advanced glitch-detection mechanisms can be defeated by sophisticated physical attacks.
The RP2350 is actually a pretty secure chip, all things considered. It has secure boot, ARMv8’s TrustZone to split secure and non-secure execution, and you can permanently disable debug — the Pi Foundation even included glitch detection, meaning the traditional ‘zap the chip until it obeys’ technique is blocked. That’s why the [Ledger Donjon] security team went full Bond Villain and strapped everyone’s favourite fruit-flavoured microcontroller to a table with a slowly-approaching laser beam.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in