DiscoStarslayer Cracks the PS2's Last Locked Chip After 26 Years
Hardware / explainer
DiscoStarslayer Cracks the PS2's Last Locked Chip After 26 Years
A four-year decapping project defeated the CXP102064 MechaCon security chip in Sony's original PlayStation 2, the chip the 2021 MechaPwn exploit never reached.

Hardware researcher DiscoStarslayer said on Sept. 14, 2026, that a four-year effort had cracked the CXP102064, the MechaCon security chip Sony built into the original "Fat" PlayStation 2 that launched in 2000, according to a project summary posted to the spc970-dumper-union GitHub organization. The chip belongs to the SPC970 family Sony used on the console's earliest hardware revisions, before Sony moved to a redesigned chip on later consoles.
Four years, one decapped die, one lucky exploit
The technique combined chemical decapping, which strips a chip's plastic housing in acid to expose the bare silicon die under a microscope, with optical dumping of the exposed circuitry to read out its contents. A collaborator identified as Libby then found a software exploit inside the resulting dumps that let the team pull MechaCon firmware without decapping every unit it wanted to study, according to Retroacademy, an Italian retro-hardware outlet that covered the project on Sept. 14. Retroacademy described the result as a lengthy process that ended in a software solution able to extract the firmware, rather than a route that requires decapping every console it touches.
What the SPC970 MechaCon actually gated
The MechaCon is a secondary microcontroller that handles the PS2's optical-drive motor control alongside two authentication jobs: Magic Gate memory-card verification and KELF executable decryption, according to project notes on GitHub. The dumps the team has published cover firmware versions 1.xx through 3.xx across three chip part numbers, CXP101064, CXP102064 and CXP103049, spanning console chassis A through G in the SCPH-10000 to SCPH-39000 range, plus the Namco System 246 and System 256 arcade boards that reused the same silicon. Contributors credited as "dai" and "inui" in the project's published checksums built the archive that made comparing firmware across that many chassis revisions possible in the first place.
The newer Dragon chip fell to software alone, in 2021
The SPC970 was not the PS2's only security microcontroller, and it was not the first one broken. Sony's later Slim consoles and its late-model Fat units, series SCPH-50000 through SCPH-90000, shipped a redesigned ARM-based chip nicknamed Dragon. Developer Triszka Balázs broke that one with a pure software exploit called MechaPwn, released in April 2021, about a month after the Dragon MechaCon's ROM was first dumped, according to RetroRGB. MechaPwn lets a compatible console reset its region lock and boot backup discs without opening the case. The older SPC970 resisted that kind of attack for five more years because, unlike Dragon, nobody had found a software-only hole in it, which is the specific gap DiscoStarslayer's team closed with acid and a microscope instead of code.
| Chip family | Console chassis | Cracked | Method |
|---|---|---|---|
| Dragon MechaCon | SCPH-50000 to SCPH-90000 (late Fat, all Slim) | April 2021 | MechaPwn software exploit, Triszka Balázs |
| SPC970 MechaCon | SCPH-10000 to SCPH-39000, Namco System 246/256 | Sept. 14, 2026 | Chemical decap plus optical dump plus software exploit, DiscoStarslayer and Libby |

What changes for owners, and what already worked without this
The practical stakes are narrower than "broken wide open" suggests. PS2 game discs are not encrypted, apart from titles that use Sony's DNAS online-authentication layer, so the software tools that let PS2 owners run backup discs from a hard drive or an optical-disc emulator existed years before this project, according to the same project notes on GitHub. What the SPC970 dumps add is the ability to compare firmware behavior across chassis and years precisely, which matters for optical-disc-emulator projects trying to replicate MechaCon timing exactly, and for security researchers documenting exploits such as MechaPwn and TonyHax, a separate tool that unlocks PS1-disc playback on SPC970-based consoles. DiscoStarslayer said a full technical write-up covering the exploit chain is still to come. As of Sept. 16, it had not been published, so the specific software vulnerability Libby found inside the optical dumps remains undocumented outside the team that found it.
The same tension between hardware-level security and years-later reverse engineering surfaced this month in a different device: researcher David Buchanan demonstrated a forgery of Google's C2PA photo-authentication scheme on a Pixel 10, a reminder that a chip built to attest to authenticity only holds until someone tries the attack nobody else has. Not every hardware project needs that kind of force: robotics firm Enactic chose to publish its OpenArm robot-arm design files under a copyleft hardware license rather than keep them closed, reaching an open result the SPC970 project had to spend four years reaching by other means.
Sources
- 06MechaPwn
More in Hardware
- 01Waymo Targets Singapore for 2028, Two Rivals Already Carry RidersWeRide and Pony AI have carried invited and paying riders through Singapore's Punggol district since April, roughly two years before Waymo's own timeline puts a rider in one of its cars there.
- 02Royal Enfield Prices Flying Flea at €5,990 Abroad, ₹2.79 Lakh at HomeNew Atlas pegs the electric motorcycle's April price in India at roughly $3,000 by direct conversion, and Royal Enfield has already lived through the same gap once with a gasoline model.
- 03Nvidia Won't Call Its Working Rust GPU Track Production-Readycutile-rs already backs an open-source LLM server and a Hugging Face testbed, but Nvidia's Sept. 8 announcement stops short of endorsing either new track for production.
- 04Arm Reuses the Total Design Name for Robots, Not Yet the SiliconThe original Total Design already has a customer-ready chiplet on TSMC's N2 process; the physical AI version Arm announced Sept. 8 is a set of robot-capability definitions.