Xbox One "Bliss Hack" Open-Source Modchip in Development by GFL_Tech

  • Thread starter Thread starter RainReach
  • Start date Start date
  • Views Views 1,391
  • Replies Replies 14
  • Likes Likes 8

RainReach

Well-Known Member
Newcomer
Joined
Apr 21, 2021
Messages
50
Reaction score
23
Trophies
0
Age
27
XP
356
Country
United States
Hey everyone,


As many of you saw at the RE//verse conference, researcher Markus "doom" Gaasedelen blew the Xbox One’s security wide open with the "Bliss" exploit—a hardware-level Voltage Glitch Hack (VGH) targeting the secure boot ROM. Because this attack exploits physical silicon behavior during early boot, it is completely unpatchable.


While Mark proved the concept, we haven't had a consumer-ready "modchip" to automate this process for regular users. However, hardware developer GFL_Tech has officially stepped up to change that. They have launched an open-source hardware project to design, build, and code a functional physical modchip for the Bliss Hack.


I wanted to put together a tracking thread here on GBATemp to log their engineering progress, layout the roadmap, and get more eyes from the HW hacking scene on this project.


The Hardware and How It Works


Unlike the original Xbox ModXO project, which uses a cheap Raspberry Pi RP2040 to mimic a flash chip, glitching the Xbox One requires insane, sub-nanosecond timing precision.


The GFL_Tech modchip is currently leveraging a hybrid approach to tackle the security processor:


Signal Processing: Utilizing a TLV3201 high-speed comparator circuit to clean up and track the motherboard's hardware states.


Sidechannel Isolation: Designing a custom Quick Solder Board (QSB) to hook directly into the EFUSE lines, tuning resistor values to kill signal noise.


The Glitch Trigger: The end goal is using a microcontroller/CPLD setup to automatically sweep timing profiles against the EMMC DAT0 lines to intercept execution flow and drop the voltage rail at the exact microsecond required.


The Project Roadmap and Current Status


GFL_Tech is treating this as a transparent, step-by-step engineering journey. Here is where the project currently sits:


Phase 1: Sourcing and teardown of a 2013 "Day One" Xbox One retail testbed. (Completed)


Phase 2: Successful testing of the TLV3201 comparator circuit. (Completed)


Phase 3: Finalizing the EFUSE QSB layout and stabilizing pull-up/pull-down noise. (In Progress)


Phase 4: Coding the automated glitch-sweep logic for the MCU. (Planned)


Phase 5: Real-time timing sweeps against the EMMC lines to hijack execution flow. (Planned)


Phase 6: Public V1 Release featuring open-source PCB schematics, code, and installation guides for the community to test and refine. (Planned)


Where to Follow and Contribute


If you want to look at the hardware schematics, trace their engineering steps, or contribute to the codebase, everything is being kept open:


GitHub Source: https://github.com/GFLTech/Xbox-One-Bliss-Hack-GFL_Tech-Modchip- to check out the wiki and hardware roadmaps.


Video Devlogs: They are documenting the actual hardware breakdowns, scope readouts, and circuit testing on YouTube under the handle @GFL_Tech.

Videos
 
Well I usuall
Post automatically merged:

will keep an eye on this project
Well I usually keep an eye out on all these videos talking about most this stuff most people don’t actually look they just relay what big YouTubers say
 
Definitely will be keep track of this. I have a Series X and Xbox One X right now. I guess I will have to get a launch Xbox One soon, but not only will I have to wait for a modchip but also for people to be able to install it cause I suck at soldering.
 
Definitely will be keep track of this. I have a Series X and Xbox One X right now. I guess I will have to get a launch Xbox One soon, but not only will I have to wait for a modchip but also for people to be able to install it cause I suck at soldering.
There will be no issues. We have made Sharkey customs aware of this and he does Jtags and RGHs for a living so there will be no need for you to do it I am sure he will do it for like 100-150
 
Massive respect for GFL_Tech taking this on openly. The sub-nanosecond timing requirement for VGH is genuinely the hard part here. The TLV3201 comparator approach for state-tracking makes sense as a foundation though.


What I keep coming back to is the preservation angle, and I think it's underdiscussed relative to the piracy conversation people keep defaulting to. The Xbox One is arguably the most at-risk 7th/8th gen console for preservation specifically because it was the first system that went all-in on DRM and online dependency by design. There are titles, patches, and DLC that exist nowhere physical and that Microsoft can sunset whenever it stops being profitable to maintain the servers. The 360 scene eventually solved that problem — the XB1 scene had nothing until Doom's work at RE//verse.

Also to Mayo1990's point — Quake 3 native on XB1 without dev mode would be exactly the kind of homebrew payload this enables. Not emulation, the real thing. That's a good example of what this actually unlocks beyond game backups.

The JTAG/RGH parallel is apt too. Those mods started as extremely fiddly hardware operations and within a couple of years became something shops would do for $80. If GFL_Tech ships a clean open-source PCB design, the install complexity will come down fast.
 
Not emulation, actually native!
I do not care about quake quest three this topic is not about quake quest three it’s about a mod chip. Please stop going off topic or you will be reported for thread hijacking. If you’d like to talk about it go talk about it on your topic,
 
Last edited by RainReach,
@RainReach : nobody asked whether you personally care about Quake. Mayo's post was an example of what this kind of payload could enable — native homebrew execution outside dev mode. That's directly relevant to what a working modchip unlocks. Emulation was never mentioned by anyone in that exchange either, so that correction came out of nowhere.
Worth reflecting on before moderating other people's contributions to your thread.

One more observation: the opening post reads like AI-generated content — clean structure, correctly used technical terminology without apparent understanding behind it, and at least one factual error that suggests the source material was summarized rather than understood. "Microsecond" precision is off by roughly three orders of magnitude for a VGH attack. Doom demonstrated sub-nanosecond timing at RE//verse, so either the OP is significantly underselling the complexity, or the person writing it didn't fully process what they were summarizing.


To be clear: the Bliss exploit is real, GFL_Tech's early work appears genuine, and the project is worth watching.

Not sure who ever you are or what you are up to .. the only thing i can tell that you are not working on any development.
 
Last edited by Svond,
  • Like
Reactions: RainReach
@RainReach : nobody asked whether you personally care about Quake. Mayo's post was an example of what this kind of payload could enable — native homebrew execution outside dev mode. That's directly relevant to what a working modchip unlocks. Emulation was never mentioned by anyone in that exchange either, so that correction came out of nowhere.
Worth reflecting on before moderating other people's contributions to your thread.

One more observation: the opening post reads like AI-generated content — clean structure, correctly used technical terminology without apparent understanding behind it, and at least one factual error that suggests the source material was summarized rather than understood. "Microsecond" precision is off by roughly three orders of magnitude for a VGH attack. Doom demonstrated sub-nanosecond timing at RE//verse, so either the OP is significantly underselling the complexity, or the person writing it didn't fully process what they were summarizing.


To be clear: the Bliss exploit is real, GFL_Tech's early work appears genuine, and the project is worth watching.

Not sure who ever you are or what you are up to .. the only thing i can tell that you are not working on any development.
I am a highly skilled. vulnerability reverse engineer you should look up the name on unknowncheats.
-Thank you
Thanks again for the constructive criticism. it will be noted and appreciated

And I hold a lot of great Xbox one SDK’s so what I release will be the most important thing everyone will need. I technically have Xbox neighborhood for Xbox one
 

Site & Scene News

Popular threads in this forum