firmware.bin is the raw dump. Flash firmware.uf2, do aTry on fw.bin
picotool save --all
We don't need to decompile it if we can make it run. At that point someone could just reverse engineer it, as long as it's functioning (or use it as-is). Otherwise, you're just trying to reimplement the FPGA's functionality from scratch, and we don't have the bitstream or its source. If someone with one of these chips shares their dump AND their serial (also called unique ID) then we can move forward with this. Otherwise, there's nothing to be done, someone would have to determine exactly how the HWFLY FPGA works and write an RP2040 sketch that does the same thing.you aren't going to have any luck decompiling the uf2 file. I tried to decrypt the binary file and while it worked, it seems they've done their homework and removed any useful information from that file. It would genuinely be easier to write your own.
From what I understand they're using the PIO on the rp2040 to perform the glitch instead of the fgpa on the hwfly boards

A level shifter is not needed, the eMMC is 3.3v tolerant.that's exactly what i was asking myself. how the fuck did he do that? how does he communicate with the emmc (no level shifter)
you can take the starlink hack as an example but I can't really make sense of it.
https://github.com/KULeuven-COSIC/Starlink-FI
We don't need to decompile it to make it run if there's a way to spoof the unique ID at the bootloader level.well we do kinda need to decompile it, considering the code is encrypted, we'd need to at least get past that


Won't work, it's not a check, it's decrypting the binary.You guys should try using fault injection on the RP2040 to make the unique ID check pass
it's impossible, we 100% need Mansi's IDindeed, but have fun brute forcing that![]()
No, it doesn't. "Pikofly" includes the functionality of the FPGA bitstream, this is just the MCU firmware.pikofly it looks like this https://github.com/Spacecraft-NX/firmware
do you think the control is in uf2?A level shifter is not needed, the eMMC is 3.3v tolerant.
We don't need to decompile it to make it run if there's a way to spoof the unique ID at the bootloader level.
control?the fw is similar, obviously the fpga part for the glich is missing
Post automatically merged:
do you think the control is in uf2?

I was joking. I mean what you gonna do? Have an RP2040 to glitch an RP2040 just to glitch your Switch?Won't work, it's not a check, it's decrypting the binary.
OHHH I SEEWell, let's see, considering I already paid $9 (including shipping) for two of them, yah!
I was joking. I mean what you gonna do? Have an RP2040 to glitch an RP2040 just to glitch your Switch?
OHHH I SEE
![]()
Ohhhh. You mean we could use another RP2040 to glitch the original RP2040!You guys should try using fault injection on the RP2040 to make the unique ID check pass
By god it's Glitch-ception!!!!but then what glitches the Pi that glitches the Pi?![]()

A couple chunks of Uranium should do itbut then what glitches the Pi that glitches the Pi?![]()
You win the threadYou guys should try using fault injection on the RP2040 to make the unique ID check pass
If nobody else can help I will open mine up and measure later today.Can anyone measure the thickness of a hwfly pcb board without the components?
0.45mm on my oled oneCan anyone measure the thickness of a hwfly pcb board without the components?