Researchers Extract Firmware From Early PlayStation 2 Security Silicon
A software exploit targeting an EEPROM write buffer bypasses physical decapping to dump mask ROM from Sony's early SPC970 MechaCon chip.

More than two decades after the original PlayStation 2 debuted, hardware security researchers have successfully extracted the firmware from Sony's SPC970 MechaCon security chip. As reported by Engadget (https://www.engadget.com/2273354/playstation-2-security-chip-reverse-engineered/), the extraction resolves one of the final unread components of early PlayStation 2 hardware, which handles optical disc authorization and baseline system security.
Developer DiscoStarslayer published the extraction tool and 22 firmware images to GitHub, crediting collaborator Libby with discovering the memory overflow exploit that enabled the extraction. The software-based technique supersedes a four-year effort to extract code by chemically stripping the chip's physical packaging and reading the silicon directly, which had previously yielded only rough, incomplete dumps.
The SPC970 chip stores its core code in non-rewritable mask ROM and keeps calibration and configuration settings in a separate 1-kilobyte EEPROM. Members of the spc970-dumper-union research group found that sending a configuration write command with a block count of zero caused an integer underflow in the chip's internal counter. Sending data beyond the chip's seven-block buffer then overflowed memory into RAM managing the EEPROM write task. By overwriting the write task's source address to point to mask ROM instead, the chip was tricked into copying 256-byte blocks of its own firmware into EEPROM, where the console could read the data back using normal commands across roughly 1,000 sequential passes to assemble the complete 256-kilobyte ROM onto a USB drive.
Because the legacy EEPROM lacks wear-leveling and has limited write endurance compared to modern flash memory, repeatedly rewriting the chip poses hardware risks. The extraction tool mitigates this by backing up the EEPROM before running, restoring it word-by-word afterward, and validating the restore against the chip's boot-up checksum routine. However, tool documentation still cautions that running the dumper carries a risk of hardware failure or requiring board-level repair.
The 22 dumped firmware images cover early Japanese models, starting with the Japan-only SCPH-15000 from 2000 through the 39000-series revisions from 2002, alongside Namco System 246 and 256 arcade boards using the same MechaCon silicon. These early revisions remained undocumented after researchers dumped the later 2003 'Dragon' MechaCon revision in 2021. The subsequent MechaPwn exploit, which unlocked later PS2 models for region-free playback, omitted roughly 20 early model numbers manufactured between 2000 and 2003 because they relied on the SPC970.
While the dumps do not contain enough data to construct a standalone optical drive emulator, they expose Sony's proprietary MagicGate encryption routines for memory cards and KELF boot executables. According to technical contributor uyjulian, the code will assist ongoing development of low-level hardware emulation. Existing emulators such as PCSX2 do not execute native MechaCon code, instead reimplementing commands in C++ and reading a placeholder NVRAM file.
Researchers are now analyzing the firmware images to search for software vulnerabilities that could enable chip-level unlocking on early consoles. Unlike the 2003 Dragon chip, which was designed to accept software patches and was cracked within a month of dumping, the SPC970 cannot be updated, meaning researchers must find exploitable logic flaws in static code manufactured in 2000.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



