Hacking Patched V1 Stuck in RCM & Won't Boot

zach__c

New Member
OP
Newbie
Joined
Feb 25, 2024
Messages
3
Trophies
0
Age
26
XP
31
Country
Canada
I have a bit of an odd situation here. I've successfully modded 7 consoles before this, but none of them were a V1 so far. I normally use the V6S chip which has worked great, but I had no V1 CPU flex cables on hand so I decided to try to modify the V2 flex to work (first mistake?). Here's what I came up with after some research:

V6S CPU Flex on V1.png



I soldered it to the top of the appropriate SP1/SP2 caps (and source points to the shield) and tested multiple times with a multimeter to make sure everything checked out before proceeding. I then did the rest of the mod as usual. After connecting everything, I got an error code flashing from the modchip indicating an issue with the CPU flex, and the console booted into OFW. I touched up the points on the caps a bit, re-seated the CPU flex connection to the chip, and booted again. The modchip LED then pulsed purple like it was trying to glitch but then blinked orange 3-4x quickly and kept doing this in a loop, which didn't match any of the LED codes I could find for the V6S.

After a while of waiting, I interrupted it by holding the power button (mistake #2?), disconnected the battery, disconnected all connections to the modchip and tried to boot to OFW. No sign of life, nothing on the display, etc. I removed the CPU flex completely, same issue. I removed everything else (emmc flex cable & modchip), same issue. Can't find any shorts on the board or anything.

The weird thing is, when I plug it into my computer, it gets recognized and even shows up as "RCM OK" in TegraRcmGUI. And of course if I try to inject a payload, I get the "Smashed the stack with a 0x0000 byte SETUP request!" message indicating it's patched. Every time I unplug the battery or hold power and restart the switch, it seems to get recognized by TegraRcmGUI as in RCM mode on boot. Does this mean the CPU is fine, or not necessarily?

I managed to get a NAND backup by putting the NAND in my V2 and dumping it with Hekate (I'm assuming this means the NAND is at least fine). If it's not possible to get the console working, I at least want to try to extract the game save data from the NAND dump for my friend so I can import them to my V2 switch and give it to him. Unfortunately, I can't decrypt the NAND via HacDiskMount unless I have the correct bis_key_3 which I'm unable to dump from the dead board :(

Lots of lessons learned for me on this one haha. My next move is I ordered some proper V1 CPU flex cables, and I'll use an RP2040 to see if I can at least dump the BIS keys.

Anyone have any other ideas? Any input at all is much appreciated!
 

zach__c

New Member
OP
Newbie
Joined
Feb 25, 2024
Messages
3
Trophies
0
Age
26
XP
31
Country
Canada
look on the picofly, and hwfly modchip threads to installation diagrams so you can learn de differences and the points to solder the Drain and source.
Hey thanks for the reply! I did actually do quite a bit of looking around beforehand and found that for the V1 the points are:

Drain => Top of the SP1/SP2 caps
Source => Ground
Gate => Modchip

I also found this image of the flex cable (along with an exposed version of the flex cable) on those threads which is what lead me to try this out:

v2 cpu flex on v1.png


Do you see any issues with this approach? The only thing I can think of is that the V2 has 2 mosfets instead of 1 like the V1 flex. Would that cause a problem?
 
  • Love
Reactions: impeeza

impeeza

¡Kabito!
Member
Joined
Apr 5, 2011
Messages
6,361
Trophies
3
Age
46
Location
At my chair.
XP
18,716
Country
Colombia
Hey thanks for the reply! I did actually do quite a bit of looking around beforehand and found that for the V1 the points are:

Drain => Top of the SP1/SP2 caps
Source => Ground
Gate => Modchip

I also found this image of the flex cable (along with an exposed version of the flex cable) on those threads which is what lead me to try this out:

View attachment 422308

Do you see any issues with this approach? The only thing I can think of is that the V2 has 2 mosfets instead of 1 like the V1 flex. Would that cause a problem?
You can solder thick wires to connect the caps and the flex.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    K3Nv2 @ K3Nv2: Lol rappers still promoting crypto