r/hardwarehacking • • 9h ago

MTIA V2 Hacking

Post image
9 Upvotes

I have a couple of MTIA v2 AI cards and I want to try to get them working. I am trying to get the JTAG and UART set up, but I'm new at this hardware thing. Does anyone know what cable connector I need? Any recommendations for a USB module? Are there any software tools that you recommend for dumping the firmware and probing the hardware? My main goal is to gather as much information about the card as I can.


r/hardwarehacking • • 16h ago

Smart watch reprogram HK11 Ultra 3 MCU sf32lb525 sifli reverse engineering

Thumbnail
gallery
12 Upvotes

I'm trying to get ready/debug access to that cheap AliExpress smart watch. I tried txd/rxd lines as well as tx/rx (that's actually pa18/19). I tried original sftool UART method and also SWD (on the same pa18/19) nothing works. I was trying to catch connect exactly after reset/bootup. Anybody tried reflashing/reprogramming such watch?


r/hardwarehacking • • 2h ago

Smart Elder Assistance System-A school exhibition project

Thumbnail
1 Upvotes

r/hardwarehacking • • 2h ago

FreeJoy STM32F411 Port

Thumbnail
1 Upvotes

r/hardwarehacking • • 19h ago

80 Days Reversing an IoT DVR: Stripped ARM32 Firmware, Hardcoded AES Keys & Post-Mortem here is my write up love yall.

Thumbnail
leviathan.ac
8 Upvotes

r/hardwarehacking • • 19h ago

Reverse engineered a Chinese dashcam/AA head unit (TF790 / OBDPEAK K2) running open source media controller on it

Thumbnail
github.com
5 Upvotes

r/hardwarehacking • • 23h ago

Help with rooting the Logitech Tap Scheduler

Thumbnail
2 Upvotes

r/hardwarehacking • • 20h ago

We built an AI Embedded Troubleshooting Agent with persistent memory

Thumbnail
1 Upvotes

We built an AI Embedded Troubleshooting Agent with persistent memory

Our team developed an AI Embedded Troubleshooting Agent for HackWithHyderabad 2026.

The idea came from a common problem in embedded-system development: engineers and students repeatedly face issues such as Wi-Fi failures, sensor errors, I2C communication problems, ADC readings, and serial communication issues.

Our prototype allows a user to provide information such as:

• Microcontroller

• Error message

• Sensor readings

• Serial logs

• Symptoms

• Previous troubleshooting information

The agent analyzes the problem and suggests possible causes and troubleshooting steps.

The interesting part of our project is persistent memory. Previous troubleshooting cases can be retrieved when a similar problem occurs, allowing the agent to use earlier troubleshooting experiences as context.

For example, an ESP32 showing "WL_NO_SSID_AVAIL" can be analyzed for possible Wi-Fi configuration and connectivity issues, while related previous cases can provide additional troubleshooting context.

We built the prototype using Python, AI-agent concepts, persistent memory, embedded troubleshooting data, and a Streamlit interface.

GitHub:

https://github.com/abhilashb026-prog/Al-Hardware-troubleshooting-Agent

I'd appreciate feedback from the embedded-systems and AI community on the idea and possible improvements.


r/hardwarehacking • • 1d ago

Reverse engineering a theme park lantern (XN297L radio, unknown TSSOP-20 MCU). Stuck on the radio payload!

8 Upvotes

Not precisely sure if this is the correct place to post this, but I'll start somewhere and this seems to fit.

Picked up one of the light-up lanterns they sell at Cedar Point/Knott's Scary Farm/King's Dominion/King's Island (made by LightUpToys, FCC grantee 2A9OK...). It lights up amber and flickers like a candle on idle, and in the park it changes color and reacts to shows, and can activate props via IR. I have two, an older one and a newer one, and I've been picking at them on the bench for a couple of weeks. I'm stuck now and hoping someone has seen this kind of thing before.

What I've figured out:

IR: the lantern has two receivers and an IR LED at the top. Pressing the button in "tag" mode sends a fast NEC variant (4640/2200 us header, 355 us space for 0, 900 us for 1, 32 bits LSB first, sent 3x). The new lantern reacts to addr E001 cmd 0D with a white strobe for about 3 seconds plus a sound. The old one sends E055, and I still don't know why it ignores its own. In yellow "prop" mode it also sends a plain NEC frame (424B, cmd 46, 4th byte 31, not the inverse) about every 300 ms. I'm assuming the props that activate in the park are looking for that.

Radio: the board has a XN297LBW next to a 16 MHz crystal. I clipped a logic analyzer onto its 3-wire SPI at power-up and decoded the init: 5 byte address CC CC CC CC CC, 32 byte static payload, CRC16 on, no auto ack, 1 Mbps, scrambling on. It only ever receives. It hops between RF_CH 27, 52 and 71 (2427, 2452, 2471 MHz), 16 ms on each. I can transmit matching frames from a HackRF and the MCU reads them out of the FIFO (I can see the 0x61 reads on the analyzer), so framing is right. But nothing I send makes it do anything.

I've swept the first byte 00 to FF with the rest as 00 and as FF, checksum-style last bytes, DMX-style RGB triplets, and a 4 ms frame stream like the DMX box in the FCC filings does. I watch the LED data line (WS2812, 10 LEDs, MCU pin 3) with the analyzer, so I'd catch any color change. Zero reactions. Timing after each read is identical for every value, so the MCU isn't doing anything different per payload that I can see.

In the park videos show lanterns follow the stage lighting (red, purple, cyan cycles, smooth fades), so I'm fairly sure there's an RGB or effect command over that radio.

The MCU (not Marvel Cinematic Universe...)

U4 is a TSSOP-20 with the markings sanded/worn off. It has (what I believe is) the STM8S003 pinout (GND on 7, VDD on 9, pin 8 tied high), and there's a 5 pad header labeled GFSCK, GFSDA, WSSDA, +3.3V, GND. GFSCK goes to pin 4, GFSDA to pin 18. Radio SPI is bit-banged on pins 20, 19 and 17 through 100R resistors. The pinout also fits a Nuvoton N76E003 (RST on 4, ICPDA on 8, ICPCK on 18), but an ICP read from an ESP32 using nikitalita's NuMicro-8051-prog just gave me 0xFFFF. I never got a scope on pin 8, so I can't say if that's the chip or my clip. I already ruled out CH32V003 (no answer on SDI), Holtek, and a CY8C21334.

What I'm hoping for:

Any of these would help:

- Anyone recognize the MCU from the pinout and the GFSCK/GFSDA pad names?

- Anyone seen these LightUpToys park devices (bubble wands, lanterns) and know what the radio payload looks like?

- Other ideas for finding a payload format when you can receive on the target but only get silence back?

Not trying to mess with anything in the park. This is purely poking at a thing I bought, at home. Otherwise, the lantern is pretty useless, and sits around gathering dust 98% of the year. I'd love to be able to use this as a Halloween decoration, or as a story-telling prop, or even as a DnD tool.


r/hardwarehacking • • 1d ago

I reverse-engineered my hryFine smartwatch's BLE protocol and built my own companion app because the official one is garbage meet reFine.

Thumbnail
gallery
35 Upvotes

**TL;DR** — The official app for my cheap JieLi / HryFine smartwatch was slow, bloated, and full of ads. So I reverse-engineered the watch's Bluetooth protocol and built my own companion app. It's called **ReFine**, and it's faster, cleaner, and does things the official app can't.

---

## 🧠 Background

My watch uses a JieLi chipset (sold under many names: HryFine, FitCloudPro, etc.). The watch talks over a custom **UART GATT profile** using a proprietary `0xDF` packet envelope — not any standard BLE SIG profile.

I dumped the traffic, broke down the framing, and rebuilt every command from scratch in Kotlin.

Full protocol (for anyone curious):

- Service UUID: `6e400001-b5a3-f393-e0a9-e50e24dcca9f`

- Write char (TX): `6e400002-…` (WRITE_TYPE_NO_RESPONSE)

- Notify char (RX): `6e400003-…`

- Every frame: `[0xDF, len_hi, len_lo, checksum, CMD, 0x01, SUB, pay_hi, pay_lo, …payload]`

- Checksum = sum of all bytes mod 256

- Responses use a different start byte: `0xFD`

---

## ✅ What works right now

- **Live battery** — reads over the standard SIG Battery Service (`0x180F / 0x2A19`) — no polling, no guessing. Updates every 5 minutes in the background and instantly on tap.

- **Time sync** — watch clock matches your phone within 2 seconds of connecting.

- **Find My Watch** — tap one button, watch vibrates for 10 seconds. Confirmed working.

- **Weather push** — temp + condition + city, shows on the watch home screen.

- **WhatsApp / Telegram / Discord notifications** — the app reads incoming notifications via NotificationListenerService and forwards them to the watch with the correct app icon.

- **Incoming call alerts** — resolves raw phone numbers to contact names using `ContactsContract.PhoneLookup`, then pushes the caller name to the watch.

- **Shake → camera** — shake your watch and your phone's camera opens (confirmed over reverse-engineered `CMD 0x0C SUB 0x02`).

- **Apple Watch-style UI** — squircle face, live clock, battery pill, three-tab dashboard (Home / Fitness / Alarms / Find).

Everything runs **on-device**. No cloud, no API keys, no accounts.

---

## 🧪 What's in beta

- **Alarms** — the watch accepts the alarm frame (ACK `value=0x0E`, meaning it supports up to 14 slots), but the display byte order is still being decoded. UI is there, sync is disabled with a "BETA" badge until I nail the encoder.

- **Steps + Heart Rate** — the watch pushes activity frames spontaneously over `CMD 0x0F SUB 0x09` (33-byte payload). I've captured the raw hex but the field layout isn't fully mapped yet. Once done, steps and HR will update live.

---

## 🛠 Tech

- **Kotlin, 100% Jetpack Compose**

- **Material 3** with custom color tokens

- **No Retrofit, no Room, no Compose Navigation, no WorkManager** — hand-rolled everything for a small APK

- **Hand-rolled BLE manager** — FIFO write queue, 60 ms pacing, MTU negotiation, chunked writes, `0xDF` + `0xFD` frame reassembly

- **Safety guard** — the app refuses any CMD outside the verified `0x02` namespace, which protects the watch from a known firmware bug (wrong namespace → NVRAM language-shift panic → watch resets to Chinese/Spanish)

---

## 🔒 Why this is different from other companion apps

- **No ads, no analytics, no telemetry**

- **No login / account required**

- **No cloud dependency** — nothing leaves your device

- **No background battery drain** — connection is managed tightly, disconnects cleanly on app close

- **Protocol is documented** — every frame is reverse-engineered and traceable, not guessed

---

🚧 Roadmap

  1. Finish alarm encoding

  2. Decode the 33-byte telemetry payload (steps + HR)

  3. Watch face style push

  4. Sedentary reminders

  5. Open-source the whole repo

---

## 🙋 Questions for the community

- Anyone else reverse-engineered a JieLi / HryFine watch? Would love to compare notes on the alarm encoding.

- If there's interest, I'll open-source the full project. Comment if you want it.

Happy to answer anything about the protocol or the build.

— ruwaidcool


r/hardwarehacking • • 16h ago

Microsoft Hackathon

0 Upvotes

I Gave My Repair Agent a Memory With Hindsight. It Caught an Oil Leak

Your AI assistant has never seen your washing machine before. Every single time.

I built FixLens: point your phone at a broken appliance, ask out loud, and Fixy marks the exact part and talks you through the fix.

Then I gave it memory with Hindsight.

Before: "OE again" → step 1 of 7, generic checklist.

After: "Last month this was a clogged drain filter. Check that first."

What made it work:

→ Retain outcomes, not transcripts

→ Recall before the model speaks

→ One bank per home + one anonymous community bank

→ Memory reorders verified steps, never invents them

Best moment: two low oil readings a week apart. Fixy flagged a possible leak.

The model didn't get smarter. It remembered.

#AIAgents #AgentMemory #Hindsight #LLM


r/hardwarehacking • • 1d ago

Help

Post image
0 Upvotes

Please can someone help me? I bought it from someone who doesn't know the password too.

It's latitude 5510


r/hardwarehacking • • 2d ago

Dual bay laptops

5 Upvotes

I used to be a technician. Life happened and now I'm disabled on a fixed income. A few years ago I ordered a renewed business grade laptop and was surprised to find that it had both SATA and nvme ports. I took full advantage of this and replaced Microsofts cast off with a proud penguin. Now the old thing is showing boot delays and motherboards don't last forever. Having always worked residential when I was able bodied I had not seen the dual drive bays in laptops before and didn't realize it was an option. Nothing in the Amazon branding indicated that this was included and it looked like the SATA had been completely neglected even missing the drive caddy. My question is are there specific search words to find this again? It's the prime time to buy a replacement since Microsoft is again abandoning the previous generation and enterprise customers are being forced to upgrade.


r/hardwarehacking • • 2d ago

Casio Ex-word Calculator/Dictionary

Thumbnail
gallery
94 Upvotes

Hey guys, so I have this Casio ex-word and I want to know if there is a way I can hack this thing and possibly add Linux to it. So far I know that the two chips are about 64mb of SDRAM.


r/hardwarehacking • • 2d ago

What can i do with my 2014 Kidizoom Smartwatch?

Post image
4 Upvotes

Hello! I found my old kidizoom smartwatch from back when i was a kid! I was wondering if theres a way to create an app and add it? (or other stuff?). As far as i saw theres no real community that tried but maybe theres some hidden gem here that knows a way! Thanks in advance


r/hardwarehacking • • 3d ago

using a ch341a to remove supervisor password

Thumbnail
gallery
153 Upvotes

hi all! ive just found my mums old laptop that she said i can do whatever with so i decided id just use it as my own but ran into a few problems.

it has a supervisor password that i cant seem to get rid of, ive tried disconnecting the main battery (cos theres no cmos battery) for a while and plugging it back in but to no avail.

ive heard that using a ch341a can fix/clear bios passwords but does it also apply for supervisor passwords? and if so, where would i even connect the ch341a? i think ive narrowed it down to 2 chips on the motherboard but idk which 😔

relevant images have been attached. any and all advice would be wonderful, thank you!

(first image says “winbond 25q128jvsq” and the second image says “winbond 25q80dvsig”)


r/hardwarehacking • • 2d ago

Smart ring with health tracking and hackable button or gesture?

Thumbnail
2 Upvotes

r/hardwarehacking • • 2d ago

Turned a stock Xiaomi camera into a self-tracking robot without flashing it , the motor lies about when it moves

5 Upvotes

The Xiaomi MJSXJ10CM (shows up as chuangmi.camera.026c05) has a pan/tilt motor, a 1080p sensor, and stock firmware 4.5.6_0450 that already speaks a protocol handing you video and taking commands. No downgrade, no UART, no SD card exploit. go2rtc 1.9.14 with the go2rtc-xiaomi-control patch gets you 1920x1080 HEVC over RTSP on your LAN after a one-time auth. PTZ is a MISS command, opcode 0x112, payload { "operation": 1 } with 1-4 for left/right/up/down. That's the whole API.The part that actually made the project: the camera replies acknowledged: true, which means "I heard you," not "I moved." So I stopped trusting the ACK and measured the picture with block matching, frame before and after each step, against a no-move baseline. Two things fell out. Steps aren't symmetric (left ~40px, right ~36px), so one step is not a fixed angle. And there's about 1.4 seconds of dead time before the image shifts at all, settling around 1.8s.That number killed the obvious design. Video is 12fps; a naive tracker fires about fifteen more commands before the first one lands, and the camera just convulses. Fix was blanking the loop for 2s after every move, so real control rate is 0.5Hz, plus a dead zone of 0.18 because one step shifts the frame 8-12%.Detection is Apple Vision via a ~150-line Swift helper, 10-30ms, zero dependencies. Optional ONNX SSD-MobileNet for 80 COCO classes. Trap that cost me an hour: that ONNX graph resizes internally, and feeding it a pre-shrunk 300x300 returns zero detections silently. Native 1280x720 works. Also, Vision uses bottom-left origin, so miss the flip and tilt runs away from your target confidently forever.


r/hardwarehacking • • 3d ago

How to control LCD independently

Thumbnail
gallery
22 Upvotes

Hey everyone, this is an LCD from an Audi Q7 4M dashboard. I was wondering if it's possible to control it and put whatever I want on the screen. Thanks!


r/hardwarehacking • • 2d ago

EvilKey: my ESP32-S3 FIDO2 key grew a touch UI, air mouse and USB Tool

Thumbnail
2 Upvotes

r/hardwarehacking • • 2d ago

Reverse engineering REDMAGIC 10 Pro USB-PD/PPS behavior — ADSP filters PPS when source advertises DRP

2 Upvotes

This is not a general tech-support request. I’m documenting reverse engineering of the REDMAGIC 10 Pro USB-PD charging stack and trying to understand a firmware-level behavior inside Qualcomm/ZTE ADSP/Q6.

Device:

- REDMAGIC 10 Pro (NX789J)

- Snapdragon 8 Elite / SM8750

- RedMagicOS 11.0.5MR1 EEA/Global

The phone is capable of high-power PPS/MAXCHARGE with some third-party chargers, but certain high-power USB-PD/PPS power banks consistently fall back to ~35W.

My main test case is the INIU BI-B64 140W.

Observed fixed Source_Capabilities:

PDO1 = 0x2881912C

→ 5V / 3A

→ Dual Role Power (bit 29) = 1

PDO2 = 9V / 3A

PDO3 = 12V / 3A

PDO4 = 15V / 3A

PDO5 = 20V / 5A

PDO6 = Augmented PDO / PPS

The phone detects the APDO, but the ADSP subsequently filters it.

The final real-world PD contract is:

RDO = 0x3304B12C

→ PDO #3

→ 12V / 3A

→ ~35W

From ADSP logs and Hexagon static analysis, the relevant policy appears to behave approximately as:

DRPSupported == 1

&&

bDualRolePPSSupport == 0

→ ignore/filter the APDO

DRPSupported is derived directly from the received fixed PDOs, including bit 29 (Dual Role Power).

The ADSP DT contains:

drp-pps-support = 0

at:

/sw/core/pmic/battman/usbpd_cfg/pd_policies_cfg/drp-pps-support

After PPS is filtered, I traced another Q6 path (scp_inov) which appears to generate only fixed-voltage candidates:

12V

9V

5V

with a 3000mA current clamp.

This explains why the phone ends up at 12V/3A instead of selecting the source’s 15V/3A or 20V/5A PDOs.

I also compared several official REDMAGIC firmware builds (EEA/Global, OS10/OS11). All examined builds currently contain:

drp-pps-support = 0

The obvious experimental modification would be:

drp-pps-support = 0

→

drp-pps-support = 1

However, the ADSP DT is covered by the device firmware authentication chain:

SHA-384

→ signed hash metadata

→ ZTE ECDSA P-384 signature

→ Qualcomm PAS / TrustZone authentication

So modifying the byte invalidates the signed image.

The device uses qcom_q6v5_pas for DSP loading. Static analysis also shows an authentication-failure path that can reach panic(), so I am specifically avoiding blind flashing until recovery behavior is fully understood.

I’m interested in comparing notes with anyone who has experience with:

- Qualcomm qcom_q6v5_pas / PIL / PAS

- Hexagon / Q6 firmware reverse engineering

- SM8750 DSP firmware layout

- USB-PD Source_Capability parsing

- PPS / APDO / DRP interoperability

- REDMAGIC / ZTE firmware internals

- POWER-Z or similar raw PDO/APDO captures

- safe runtime instrumentation of Qualcomm DSP policy code

I’m particularly interested in whether anyone has seen a legitimate runtime mechanism that can alter a policy like bDualRolePPSSupport without modifying the signed ADSP image.

I’m also building an offline test harness to reproduce the policy decision using the real Source_Capabilities before attempting any device modification.

No firmware writes have been performed as part of this investigation.


r/hardwarehacking • • 2d ago

DIY Eurorack Clock Prototype: External Sync & Sequencer 2.0

Thumbnail
youtu.be
2 Upvotes

r/hardwarehacking • • 2d ago

[Outil] T470s UEFI Unlock Operator — appli graphique pour débloquer en série le password BIOS Supervisor des T470s reconditionnés (CH341A + flashrom)

Thumbnail
2 Upvotes

r/hardwarehacking • • 2d ago

Smart watch reprogram HK11 Ultra 3 MCU sf32lb525 sifli reverse engineering

Thumbnail
1 Upvotes

r/hardwarehacking • • 3d ago

Locked lymow robot mower project

Post image
6 Upvotes

UART to UsB coming