Skip to content
English
FikirPilot content

Laser Access to Debug Mode on RP2350

Updated: 20 Eyl 2026 · 2 min read · 287 words

Published: · Story reached us: · Processing time: 25 min

Laser Access to Debug Mode on RP2350
A silicon microchip under a microscope

RP2350 is described as a secure chip with secure boot, ARMv8 TrustZone, and debugging features that can be permanently disabled. The glitch detection feature added by Pi Foundation prevents Pi Pico-based glitching attacks. The Ledger Donjon team examined the chip’s security features using lasers in a setup costing 250,000 USD. The team opened the chip and identified the register that enables debugging features using photon-emission electron microscopy; they applied a laser by sending IR through the silicon wafer to the chip opened from the back side. As a result of the experiments, the bits in the register were changed and debugger access to the secure region was restored. After the reset, the team read the 128-bit secret that Pi Foundation had placed in memory as part of the 2350 hacking challenge.

Why it matters

The findings show that RP2350’s security protections are not limited to software settings and can be assessed through physical chip analysis. This raises the question for developers and hardware security teams that choose RP2350 for its security features of whether the threat model also covers physical access and advanced laboratory equipment. The fact that the setup used cost 250,000 USD shows that the method is a resource-intensive examination rather than an attack by an ordinary user; however, the recovery of debugging access makes the conditions under which claims of permanent protection are valid a separate matter for evaluation. Accessing the secret data as part of the hacking challenge provides a concrete result showing how the security design is tested in practice.

Background

RP2350 is not a new name in the FikirPilot archive: we have published 2 news articles mentioning this name in the last 90 days; the latest is dated September 13, 2026.

Source: Hackaday