Sign in

stacksmashing

@stacksmashing.bsky.social
3.9K followers 78 following 190 posts

Security researcher with a focus on hardware & firmware. I occasionally publish stuff on YouTube. Co-founder of hextree.io. Contact: contact@stacksmashing.net

PostsRepliesMedia
stacksmashing @stacksmashing.bsky.social · 28/09/2026
> You're right, and I own this: I ran erase/program sequences I had not validated against a scope, on your hardware, and it bricked the chip. That was the wrong call 🥲
1132
stacksmashing @stacksmashing.bsky.social · 19/08/2026
Yeah it all looks a bit messy on AST2500
010
stacksmashing @stacksmashing.bsky.social · 19/08/2026
AST2500😅 AST2600 seems to work very differently (running OpenBMC?)
110
stacksmashing @stacksmashing.bsky.social · 18/08/2026
Found a Supermicro BMC vulnerability yesterday and now getting Supermicro ads all day 🤡
1131
stacksmashing @stacksmashing.bsky.social · 18/08/2026
Impatient? Me? Never!!
0150
stacksmashing @stacksmashing.bsky.social · 16/08/2026
I don't know what to do with this information, so just sharing it here: Apparently Stern Pinball game-code updates are encrypted LUKS containers 😀
2263
stacksmashing @stacksmashing.bsky.social · 15/08/2026
At DEF CON I had the idea to look at a particular subsystem of iOS & macOS. When I came back I started reversing - and found exactly the type of bug I was looking for 😀
0240
stacksmashing @stacksmashing.bsky.social · 14/08/2026
We only clone the bad things - Some product person, probably
090
stacksmashing @stacksmashing.bsky.social · 14/08/2026
Google releases their own AirTag. Also Google: Let's make sure it ALSO does not attach to a key.
2141
stacksmashing @stacksmashing.bsky.social · 05/08/2026
Does someone happen to have one of the vulnerable COLDCARDS and would sell it to me at DEFCON?🙏
162
stacksmashing @stacksmashing.bsky.social · 31/07/2026
If there's one hardware wallet I always told people not to trust it's COLDCARD. Not surprised in the slightest by the recent events. (They messed up their RNG in multiple ways, leading to - so far - user losses above $38 million USD.)
1101
stacksmashing @stacksmashing.bsky.social · 31/07/2026
Hacking random companies is totally okay if I claim my GPU did it?!
0252
stacksmashing @stacksmashing.bsky.social · 28/07/2026
(It works on some browsers but not in others)
030
stacksmashing @stacksmashing.bsky.social · 28/07/2026
Did KiCAD get compromised? Or some over-eager AI-scraping prevention?!
230
stacksmashing @stacksmashing.bsky.social · 22/07/2026
If the sandbox escape was so advanced then publish the details.
0162
stacksmashing @stacksmashing.bsky.social · 11/06/2026
My DEF CON talk "Hacking jetskis - from Sea-Don't to Sea-Doo" got accepted 🥳 We'll be having some good fun - such as bypassing the immobilizer using a custom Flipper Zero app, building a custom diagnostic adapter, and some big plot-twists 🛥️
Flipper showing Jetski diagnostic info
0270
stacksmashing @stacksmashing.bsky.social · 16/05/2026
Opposite of solder-pr0n: Messed up the stencil solder application and was hoping for surface tension to fix it for me 🥲 The expired paste probably didn't help either
2150
stacksmashing @stacksmashing.bsky.social · 08/05/2026
This guy doesn’t even use AI for bug hunting 🙄
1170
stacksmashing @stacksmashing.bsky.social · 06/05/2026
Non-technical teams are now shipping production vulns
2254
stacksmashing @stacksmashing.bsky.social · 04/04/2026
Told someone their "vulnerability report" is bs (result of an automatic scanner that has a false positive...) This was the response 😑
Thanks for the confirmation.

I will follow the steps to reproduce to confirm the status.

Let me know if you need anything else from myside

I hope this type of hard effort deserve something rewards

Paypal or bank transfer

Best Regards
2150
stacksmashing @stacksmashing.bsky.social · 30/03/2026
Sometimes it’s nice to go back to basics: Built firmware that’s just 246 bytes, uses no RAM at all, and runs parasitically from a 1-wire bus at just 0.2 mA. Yet it emulates a full jetski key! You can see voltage rising until the chip starts running based on the BOD threshold.
3291
stacksmashing @stacksmashing.bsky.social · 26/03/2026
I don’t think that’s true
100
stacksmashing @stacksmashing.bsky.social · 25/03/2026
If you ever lose the keys to your older Sea-Doo Jetski you might find these bytes useful when talking to the ECU😇 95 BC 2F 02 04 A4 75 BE
1221
stacksmashing @stacksmashing.bsky.social · 25/03/2026
Option A: Upgrade iPhone to iOS26 and have to use liquid glass Option B: Get pwned by DarkSword malware I don't know which one is worse
5180
Reposted by stacksmashing
Banda Bassotti @orpach.neocities.org · 17/03/2026
Put that thing on a pole and call it the BLE swiffer.
011
stacksmashing @stacksmashing.bsky.social · 17/03/2026
0160
stacksmashing @stacksmashing.bsky.social · 17/03/2026
Sometimes, you simply need Bluetooth HIGH Energy📡
2450
stacksmashing @stacksmashing.bsky.social · 17/03/2026
The issue is the ESR. It's too low, impacting the loop stability of the regulator in this case
211
stacksmashing @stacksmashing.bsky.social · 17/03/2026
If the datasheet says to use tantalum capacitors - then use tantalum capacitors! Blue = Ceramics Yellow = Tantalum
1160
stacksmashing @stacksmashing.bsky.social · 09/03/2026
Not if you try ifconfig first every single time 🤷‍♂️
000
stacksmashing @stacksmashing.bsky.social · 08/03/2026
alias ip='rm -rf /'
120
stacksmashing @stacksmashing.bsky.social · 08/03/2026
Simple age check for Linux: Just have the shell ask the user to check the host IP on first boot. If they type ifconfig they are old enough, if they type ip addr they deserve to be restricted from their computer 😇
6407
stacksmashing @stacksmashing.bsky.social · 06/03/2026
Things I didn’t see coming: apparently I own a Game Boy signed by a Eurovision contestant?! 😆 youtu.be/8XR2RvfZ-68
4412
stacksmashing @stacksmashing.bsky.social · 05/03/2026
No JLC, component placement is not correct 😂
3280
stacksmashing @stacksmashing.bsky.social · 05/03/2026
Awesome!! We wrote a similar tool compatible with a bunch of programmers: flash.hextree.io
flash.hextree.io
Hextree Flash Programmer
130
stacksmashing @stacksmashing.bsky.social · 28/02/2026
Won today’s bet of “Do I really have no oil pressure, or is the gauge just broken?” 😅
0280
stacksmashing @stacksmashing.bsky.social · 27/02/2026
If you find one where some channels don’t move: In 90% of cases it’s just the transistors that are broken. Simple to change and readily available at Digikey & co. Replaced all on mine just to be sure.
050
stacksmashing @stacksmashing.bsky.social · 27/02/2026
Wow, used Yamaha 01V96 are a steal - and 17 motor faders are a lot of fun 😀
2170
stacksmashing @stacksmashing.bsky.social · 20/02/2026
Memory Tagging Extension checking my pointer
media.tenor.com
a shirtless man with blonde hair is sitting in a chair .
ALT: a shirtless man with blonde hair is sitting in a chair .
070
stacksmashing @stacksmashing.bsky.social · 20/02/2026
"The pointer was feeling fabulous today."
000
stacksmashing @stacksmashing.bsky.social · 20/02/2026
Yes VSCode, I obviously want to use the color-picker to edit the address offsets in Arm assembly 😂
5706
stacksmashing @stacksmashing.bsky.social · 05/02/2026
Yep, just a very simple nRF52840 BLE sniffer :)
010
stacksmashing @stacksmashing.bsky.social · 05/02/2026
Fancy, the board-house sent me x-rays of my PCBs!
1230
stacksmashing @stacksmashing.bsky.social · 03/02/2026
We were able to find some minor correlations, but by far not enough to leak the key successfully. If you think you found something - even if it's not a full attack - send an e-mail, it's about making the implementation more secure, not about building the best attack.🛡️
080
stacksmashing @stacksmashing.bsky.social · 03/02/2026
My first post on the RaspberryPi Blog 😍 We've extended the RP2350 side-channel hacking challenge to April 30 - and even better: To make attacks for the challenge easier, we decided to disable the random chaffing and some more mitigations! www.raspberrypi.com/news/rp2350-...
raspberrypi.com
RP2350 Hacking Challenge 2: Less randomisation, more correlation - Raspberry Pi
Our second RP2350 Hacking Challenge has evolved, with prize money still up for grabs.
1201
stacksmashing @stacksmashing.bsky.social · 01/02/2026
The one on the stands is just a random QFP carrier i had on my desk - the one on the bottom is my PCBite plate :)
020
stacksmashing @stacksmashing.bsky.social · 29/01/2026
gist.github.com/nezza/3841f9...
gist.github.com
flashfixer.py
GitHub Gist: instantly share code, notes, and snippets.
021
stacksmashing @stacksmashing.bsky.social · 29/01/2026
Yeah I have a script that takes multiple dumps and then creates one "true" dump with the most likely bytes from multiple dumps. It also logs out outliers which is helpful!
130
stacksmashing @stacksmashing.bsky.social · 28/01/2026
The PCB is suuuper sensitive. I ripped off three pads so far... To get to chip-select I had to solder onto the tiny tiny tiny via barrel😵‍💫
090
stacksmashing @stacksmashing.bsky.social · 28/01/2026
9d3e36fc632d77f24c810cb89892dd1959dfb05b output.bin (Created from multiple dumps, something is messing with the signal)
5192