Hardware Hacking Fake RCMloader dongles in the wild

Hayato213

Newcomer
Member
Joined
Dec 26, 2015
Messages
19,896
Trophies
1
XP
20,848
Country
United States
none of mine was overpriced, one cost 5 USD (fake "V5") and a original what I buy on 7 USD.

For me, my wife and my niece is a lot convenient have a little gadget what fits on the switch case and don't get lost and no need to carry extra cables. and my niece isn't allowed to have a phone with her, so.

I just installed a internal gema chip to replace the dongle and never again use a external injection method.

All is about preferences.

Last Week see a Fake V5 on a local game shop and was hilarious don't even have a reset switch on the bottom, we opened and instead a 90° switch have a normal one so if you need to reset it you have to open the case :rofl2:
:rofl2:

Good choice of a internal modchip, much more convenient than having a dongle, I had NS Atmosphere and RCM Loader One dongle before I sold them, never used them, crazy thing that my dragon injector is collecting dust.
 

Maxeatedcheese

Active Member
Newcomer
Joined
Aug 8, 2019
Messages
29
Trophies
0
Age
22
XP
77
Country
United States
Good choice of a internal modchip, much more convenient than having a dongle, I had NS Atmosphere and RCM Loader One dongle before I sold them, never used them, crazy thing that my dragon injector is collecting dust.
just sayin if you want to sell that to me I will pay whatever (reasonable price) for it DI's are so rare now
 
  • Like
Reactions: binkinator

Hayato213

Newcomer
Member
Joined
Dec 26, 2015
Messages
19,896
Trophies
1
XP
20,848
Country
United States

Maxeatedcheese

Active Member
Newcomer
Joined
Aug 8, 2019
Messages
29
Trophies
0
Age
22
XP
77
Country
United States
Sounds more like a rip off.
Thanks, I will just keep mine as a collector item.
yeah I don't get paid much, I don't really want to spend almost all of my money on one anyways just thought it was worth a shot lol! :)

im actually a little upset they don't have the files for them online anymore because my boyfriend's dad has a 3d printer and I was thinking of making one myself
 
  • Like
Reactions: SylverReZ

SylverReZ

Dat one with the Rez
Member
GBAtemp Patron
Joined
Sep 13, 2022
Messages
7,106
Trophies
3
Location
The Wired
Website
m4x1mumrez87.neocities.org
XP
21,779
Country
United Kingdom

Maxeatedcheese

Active Member
Newcomer
Joined
Aug 8, 2019
Messages
29
Trophies
0
Age
22
XP
77
Country
United States
  • Like
Reactions: SylverReZ

SylverReZ

Dat one with the Rez
Member
GBAtemp Patron
Joined
Sep 13, 2022
Messages
7,106
Trophies
3
Location
The Wired
Website
m4x1mumrez87.neocities.org
XP
21,779
Country
United Kingdom
Here are some teardown photos of my RCM Loader One B for reference if anybody is interested. My RCM Loader is using a 'GDF350G8' GD32-series ARM Cortex-M4 microcontroller running at 108MHz, followed by a 16MBit SPI flash chip labelled '25VQ16ATIG'. After I dumped the flash chip, and opened up the dump with a hex editor, my speculation is that it stores some sort of configuration for the device.

Datasheets:
GDF350G8: Manual: https://gd32mcu.com/data/documents/userManual/GD32F3x0_User_Manual_Rev2.6.pdf / Datasheet: https://www.gd32mcu.com/data/documents/datasheet/GD32F350xx_Datasheet_Rev2.1.pdf
25VQ16ATIG (not the same but similar): https://pdf1.alldatasheet.com/datasheet-pdf/download/1151995/GIGADEVICE/GD25VQ16C.html

DSCF6537.JPG


DSCF6500.JPG
 
Last edited by SylverReZ,

Maxeatedcheese

Active Member
Newcomer
Joined
Aug 8, 2019
Messages
29
Trophies
0
Age
22
XP
77
Country
United States
Here are some teardown photos of my RCM Loader One B for reference if anybody is interested. My RCM Loader is using a 'GDF350G8' GD32-series ARM Cortex-M4 microcontroller running at 108MHz, followed by a 16MBit SPI flash chip labelled '25VQ16ATIG'. After I dumped the flash chip, and opened up the dump with a hex editor, my speculation is that it stores some sort of configuration for the device.

View attachment 335644View attachment 335645
okay so! I saw your teardown and got curious, luckily I had the tools to open my clone chip up (it wasn't difficult it was just 4 plastic clips) and I have spotted a lot of differences.

1: the main chip has a sandpaper like tape on it that keeps you from seeing its label
2: there are 4 other chips, "1AM; 3AUC; HTU6*; 3AUA*"
2* these have a little swoosh symbol I can't figure out what it is, i have a picture i took of these chips using the flash
3: a small piece of metal that reads "32000 MHZ" i assume its probably not a chip but idk im not very literate about these things
4: Battery is larger
5: Text that reads "RCMloader V2.2DDDZ
6: Small metal leads that don't seem to be connected to anything? The one to the right of the USB-C port has letters A, B, D-, D+ if anyone knows what that could mean im curious because as i said im illiterate about hardware

If anyone could help me with info on how to dump any of the chips i am very interested in doing so!
IMG_1300.png
IMG_1299.png
IMG_1301 (1).png
 

MushGuy

Well-Known Member
Member
Joined
Feb 11, 2010
Messages
1,280
Trophies
1
XP
2,576
Country
United States
Hekate will automatically load an updated version of itself from the SD card if found - off the top of my head, I think it's at bootloader/update.bin - just download the latest Hekate and rename it to update.bin in the bootloader folder. Then when you push whatever version is on this dongle, it will load and start the new version.
I didn't even know this was possible. All this time I was updating my Hekate payload in my NS Atmosphere when I could have simply used update.bin in the bootloader folder. I feel like a dummy now!😲
 
  • Like
Reactions: hippy dave

Maxeatedcheese

Active Member
Newcomer
Joined
Aug 8, 2019
Messages
29
Trophies
0
Age
22
XP
77
Country
United States
Update: I talked to the seller about this and they said it was an issue with the supplier! They are offering to give me a full refund but I think I got lucky tbh.
okay so! I saw your teardown and got curious, luckily I had the tools to open my clone chip up (it wasn't difficult it was just 4 plastic clips) and I have spotted a lot of differences.
....
 

randy_w

Well-Known Member
Member
Joined
Feb 27, 2021
Messages
709
Trophies
0
Age
34
XP
1,371
Country
United States
okay so! I saw your teardown and got curious, luckily I had the tools to open my clone chip up (it wasn't difficult it was just 4 plastic clips) and I have spotted a lot of differences.

1: the main chip has a sandpaper like tape on it that keeps you from seeing its label
2: there are 4 other chips, "1AM; 3AUC; HTU6*; 3AUA*"
2* these have a little swoosh symbol I can't figure out what it is, i have a picture i took of these chips using the flash
3: a small piece of metal that reads "32000 MHZ" i assume its probably not a chip but idk im not very literate about these things
4: Battery is larger
5: Text that reads "RCMloader V2.2DDDZ
6: Small metal leads that don't seem to be connected to anything? The one to the right of the USB-C port has letters A, B, D-, D+ if anyone knows what that could mean im curious because as i said im illiterate about hardware

If anyone could help me with info on how to dump any of the chips i am very interested in doing so!
Seems like the main mcu is the same, they just sanded off the label. Too bad it's not an samd21 chip otherwise you can flash matty's fusee suite. You can port it to gd32/stm32 if you have time.
You can probably dump its flash with openocd or st link, then update the binary payload file inside and flash it back. But as others have said, no need to do that as hekate will load the more recent version on sd card.
I think the A/B/D+/D- pads could be used for internal installation (A and B to pull vol+ and joycon pin 10 to ground, d+ and d- to inject payload through usb port). The 4 pads on the side could be the debug/swd port.
 

Maxeatedcheese

Active Member
Newcomer
Joined
Aug 8, 2019
Messages
29
Trophies
0
Age
22
XP
77
Country
United States
Seems like the main mcu is the same, they just sanded off the label. Too bad it's not an samd21 chip otherwise you can flash matty's fusee suite. You can port it to gd32/stm32 if you have time.
You can probably dump its flash with openocd or st link, then update the binary payload file inside and flash it back. But as others have said, no need to do that as hekate will load the more recent version on sd card.
I think the A/B/D+/D- pads could be used for internal installation (A and B to pull vol+ and joycon pin 10 to ground, d+ and d- to inject payload through usb port). The 4 pads on the side could be the debug/swd port.
Thank you for the info! I might try to dump said flash just so you all can see what is different from official ones (bc i don't have an official 1B) also the idea of someone installing one of these cheap knockoffs as a modchip is comical but I do agree thats probably what the pads are for
 
  • Like
Reactions: SylverReZ

SylverReZ

Dat one with the Rez
Member
GBAtemp Patron
Joined
Sep 13, 2022
Messages
7,106
Trophies
3
Location
The Wired
Website
m4x1mumrez87.neocities.org
XP
21,779
Country
United Kingdom
Thank you for the info! I might try to dump said flash just so you all can see what is different from official ones (bc i don't have an official 1B) also the idea of someone installing one of these cheap knockoffs as a modchip is comical but I do agree thats probably what the pads are for
I was definitely thinking the same thing.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    K3Nv2 @ K3Nv2: https://youtu.be/MddR6PTmGKg?si=mU2EO5hoE7XXSbSr