Reverse engineering efforts have finally cracked the firmware of the original security chip found in early PlayStation 2 consoles. While later models were successfully exploited through the Dragon MechaCon chip, the first three years of production—spanning roughly 20 model numbers between 2000 and 2003—remained inaccessible at the hardware level until now.
The breakthrough follows earlier achievements in the community. Firmware images for the Dragon MechaCon were published in 2021, leading to the release of the MechaPwn exploit a month later. That tool enabled region-free play and backup disc support on compatible hardware. However, its documentation explicitly noted that older consoles utilizing the SPC970 chip were unsupported and would remain so due to the inability to inspect its internal code.
Although these consoles could still execute backups via memory card or hard drive vulnerabilities, the newly dumped images provide the first clear view of the chip’s logic. According to contributor uyjulian, the dumps alone are insufficient for creating an optical drive emulator. However, they do pave the way for a modchip that replaces the MechaCon while retaining the drive’s digital signal processor for disc reading. Because PS2 game data was not encrypted, no new media piracy capabilities are introduced by this discovery.
The significance lies elsewhere. The firmware exposes the code behind Sony’s “MagicGate” encryption system used for memory cards and KELF executables. This transparency is expected to advance “full-system low-level emulation.” Current emulators like PCSX2 simulate the MechaCon using C++ replacements and static files rather than emulating the actual chip. Reliquary, a PCSX2 fork maintained by DiscoStarslayer, specifically targets authenticated paths but acknowledges that synthetic data cannot replicate hardware values when security checks verify console identity.
Looking ahead, the primary objective for researchers is identifying a vulnerability in the SPC970 similar to those found in the Dragon chip. However, this process is anticipated to be significantly slower. The Dragon chip was designed to accept firmware patches, giving attackers an update mechanism to exploit. In contrast, the SPC970 code was permanently baked into the hardware in 2000 and has never supported updates, making it a more stubborn target for hackers.
So no new piracy vector since discs weren’t encrypted? Glad to hear. It’s all about preservation and accuracy now.
Good for emulation, but I’m skeptical we’ll see full hardware-level bypasses soon. Locked firmware without updates is tough.
Does this mean PCSX2 can finally emulate the authentic MagicGate checks properly? That would be a game changer.
Finally! I’ve been waiting years for early SCP970 support. This is huge for preserving the original boot experience.