Back
PlayStation 2 SPC970 firmware dumped after reverse engineering
SiTech AI Team3 min read

PlayStation 2 SPC970 firmware dumped after reverse engineering

Developer DiscoStarslayer has extracted SPC970 MechaCon firmware from early PlayStation 2 consoles, filling a major gap in hardware research and opening a path toward new chip-level unlock and emulation work.

Early PS2 chip firmware dumped

More than 25 years after the original PlayStation 2 launched, developer DiscoStarslayer has extracted firmware from the SPC970 MechaCon, the chip used in early consoles to authorize discs and handle most security functions. DiscoStarslayer credited Libby, who found the exploit that made the extraction possible.

The project published 22 firmware images on GitHub. They cover the Japan-only SCPH-15000 from 2000 through the 39000-series models from 2002, along with the Namco System 246 and 256 arcade boards that used the same chip. These machines were among the final unread parts of the PS2 after the Dragon MechaCon was dumped in 2021.

How the SPC970 was read

The SPC970 stores its code in mask ROM, which cannot be written or patched, while calibration and configuration data are kept in a separate 1KB EEPROM. The spc970-dumper-union group exploited the chip's EEPROM write process. Opening a configuration write session with a block count of zero caused an internal counter to underflow.

Sending more data than the seven-block buffer could hold overflowed into RAM containing the EEPROM write task. Changing that task's source address pointed it toward the chip's ROM, causing the MechaCon to copy 256 bytes of firmware into the EEPROM. After around 1,000 repetitions, the complete 256KB image could be read from a USB stick.

The tool backs up the EEPROM before extraction, restores it word by word afterward and checks the result against the chip's power-on checksum routine. However, the EEPROM has no wear leveling and has a smaller write budget than flash memory, so every dump shortens its lifespan. The original dumper warns that the process can leave a console unable to operate normally or requiring hardware-level repair.

Possible hardware and emulation work

Dragon MechaCon firmware was released in 2021, followed one month later by MechaPwn, an exploit that makes later PS2s region-free and able to read backup discs. Its documentation says it does not support older consoles because they do not use the Dragon chip. That leaves roughly 20 model numbers from the PS2's first three years without chip-level unlocking, although memory card and hard drive exploits can still be used to run backups.

The new images are not enough to build an optical drive emulator, but they could support a modchip that replaces the MechaCon while retaining the drive's DSP to read discs. Since PS2 games were not encrypted, the dumps do not unlock new games. They do expose code behind Sony's MagicGate encryption for memory cards and KELF executables.

A new target for unlock research

Contributor uyjulian says the firmware will eventually support full-system low-level emulation. PCSX2 does not execute the chip's code, instead reimplementing MechaCon commands in C++ and using a 1KB NVRAM file plus a four-byte version number as stand-ins. DiscoStarslayer maintains the Reliquary PCSX2 fork for authenticated console paths, but its documentation says generated data cannot replace hardware values when a security check examines console identity.

The immediate goal is to locate a bug that could unlock early SPC970-based consoles. A MechaPwn or TonyHax-style unlock is a longer-term aim. Dragon could be cracked within a month because Sony designed it to accept patches, while the SPC970's code was fixed in mask ROM in 2000 and cannot be updated.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.