More than 25 years after the original PlayStation 2 launched, developer Disco Starslayer has successfully extracted firmware from the SPC970 Mecha Con security chip used in early fat PS2 consoles. The breakthrough was made possible by an exploit discovered by collaborator Libby, who found that sending more data than the chip's buffer could handle caused an underflow that exposed its internal ROM code. The extraction required roughly 1,000 passes to dump the full 256KB image, with each pass rewriting the chip's limited-write EEPROM and gradually wearing it out.
The dumped firmware covers 22 images across PS2 models from the Japan-only SCPH-15000 released in 2000 through the 39000-series models of 2002. It also includes firmware for the Namco System 246 and 256 arcade boards that shared the same chip. These were the final unread components of the PS2 following the 2021 release of the "Dragon" Mecha Con firmware.
While the dumps don't contain enough data to build an optical drive emulator, they could enable modchips that replace the Mecha Con while retaining the drive's DSP for disc reading. The firmware also reveals Sony's "Magic Gate" encryption used for memory cards and KELF executables, which will eventually support full-system low-level emulation in projects like PCSX2.
Source: Engadget · Summarized by HeadlinesBriefing