Original PlayStation 2 Security Chip Reverse-Engineered, Firmware Published
Developer DiscoStarslayer has extracted firmware from the SPC970 MechaCon chip in early fat PlayStation 2 consoles, publishing 22 images and an exploit that may open the path to chip-level unlocks.
The exploit is described in the dump tool's documentation. It told the chip that an incoming batch of settings data would be empty, then sent more data than it had room for. Before this, roughly four years of work had relied on a slower method of stripping the chip's packaging and reading its contents, producing only rough dumps.
The firmware and tooling have been pushed to GitHub alongside 22 firmware images. They cover fat PS2s from the Japan-only SCPH-15000 of 2000 to 39000-series models of 2002. They also cover the Namco System 246 and 256 arcade boards, which used the same chip. Those early machines were among the final unread parts of the PS2 after the 2003 "Dragon" MechaCon was dumped in 2021.
The SPC970 keeps its code in mask ROM, which cannot be written or patched, and stores only calibration and configuration data in a separate 1KB EEPROM. To get around that, the "spc970-dumper-union" enthusiast group abused how the chip writes to the EEPROM.
The group found that opening a config write session with a block count of zero caused the chip's internal counter to underflow. Pushing more data than the seven-block buffer can hold overflows into RAM that holds the EEPROM write task. Overwriting that task's source address points it at the chip's ROM, so the MechaCon copies 256 bytes of its firmware into the EEPROM. The PS2 can then read it back with a standard command. Repeated around 1,000 times, the full 256KB image sits on a USB stick.
Each pass rewrites the EEPROM, and every dump shortens its life because it has no wear leveling and a smaller write budget than flash memory. The tool backs up the EEPROM before it starts, restores it word by word afterward, and checks the result against the chip's power-on checksum routine. Libby's original dumper still warns that it can leave a PS2 "unable to operate normally, or require hardware-level repair. Use it entirely at your own risk."
Dragon MechaCon firmware images were released in 2021. MechaPwn, the exploit that makes later PS2s region-free and lets them read backup discs, was released a month later. Its README says older consoles do not use a Dragon-based MechaCon and therefore are not supported, with no support planned. That affects roughly 20 model numbers from the PS2's first three years between 2000 and 2003. Those machines can still run backups through memory card and hard drive exploits, but they could not be unlocked at the chip level until now because nobody could see its code. The dumps make that search possible for the first time.
The images alone do not hold enough information to build an optical drive emulator, but they could support a modchip that replaces the MechaCon while keeping the drive's DSP to read discs. Since PS2 games were not encrypted, nothing new is unlocked in that sense. The firmware does expose the code behind Sony's "MagicGate" encryption for memory cards and KELF executables that the console boots from disc and memory cards. Contributor uyjulian says that will eventually feed "full-system low-level emulation."
PCSX2 and other emulators, which can also emulate the weaker GameCube, do not run the chip's code at all. PCSX2 reimplements MechaCon's commands in C++ and reads a 1KB NVRAM file and a four-byte version number from disk to stand in for the real part. DiscoStarslayer maintains a PCSX2 fork called Reliquary, aimed at the PS2's authed paths. They acknowledge in its README that generated stand-in data is not a substitute for hardware values when a security check inspects console identity.
As for the SPC970, the first job of its dump is to find a bug that opens up the early consoles. With MechaPwn, people could read the Dragon chip's code and find a weakness in how Sony let that chip update itself. uyjulian says a MechaPwn or TonyHax-style unlock for the SPC970 is one of the goals, but it will not come as fast. It took researchers only a month to crack Dragon because Sony built that chip to accept patches, giving researchers something to break. The SPC970 cannot be updated at all; its code was baked into the chip in 2000 and has never changed.