PlayStation 2 Security Chip Has Been Reverse Engineered

Researchers successfully extracted firmware from the console’s SPC970 chip to enable new system-level exploits.

Updated on Oct. 3, 2026 in Semiconductors

Graphic illustration of a silver integrated circuit on a dark background, evoking a retro-tech technical aesthetic.
Security researchers have reverse engineered the SPC970 chip found in early PlayStation 2 consoles, potentially enabling permanent hardware-level modifications for the system. AI Illustration. Upload story photo >

Live Poll

Do you believe owners should be allowed to modify the security firmware of their retro consoles?

Security researchers have successfully reverse engineered the SPC970 chip found in early PlayStation 2 consoles. The discovery provides firmware data that could enable custom unlocks similar to existing exploits for later hardware.

Why it matters

Gaining access to the chip-level code allows developers to move beyond current emulation methods, potentially leading to permanent system-wide hardware modifications. This milestone brings early PlayStation 2 models closer to the unlocking capabilities already available for subsequent versions.

The extraction process requires rewriting the EEPROM 1,000 times to pull the firmware code. Approximately 20 different PlayStation 2 model numbers produced between 2000 and 2003 contain the targeted SPC970 security chip.

The players

PlayStation 2

This home video game console was released by Sony in 2000 and remains the best-selling video game console of all time.

PCSX2

This is an open-source PlayStation 2 emulator that allows the console's software to run on modern computing hardware.

The details

By dumping the EEPROM data, researchers have exposed the underlying MagicGate encryption protocols used for memory cards and KELF executables. While PCSX2 emulators currently approximate these functions in C++, this new data allows for low-level integration that better mirrors original console behavior.

Timeline

  1. The SPC970 security chip was first integrated into PlayStation 2 hardware in 2000.

  2. Affected console models were released between 2000 and 2003.

  3. Firmware images for the newer Dragon MechaCon chips were released in 2021.

The Tech Race

This development bridges a significant gap in console security by extending the capabilities established by the MechaPwn exploit for Dragon-based MechaCon chips. It marks a shift from relying on emulated C++ command approximations to using raw, authentic hardware firmware data.

Users can expect future updates to emulation software that provide more accurate, low-level console behavior as developers integrate the new firmware. These findings may eventually lead to hardware-based unlocking tools that expand the functionality of early-model consoles.

The takeaway

Reverse engineering legacy security chips allows for a deeper understanding of proprietary hardware that can no longer be updated via software patches. Enthusiasts should monitor developer forums for future releases of low-level tools that take advantage of this extracted firmware.

Further reading

Learn more about the latest developments in Semiconductors.

Source note: This article includes information reported by Engadget.

Live Poll

Do you believe owners should be allowed to modify the security firmware of their retro consoles?