stepstube

Hacking the Xbox One Boot ROM: The Bliss Hack

Advancedelectronics

Safety first

  • This hack involves direct physical modification and voltage glitching of sensitive console hardware (SOC, APU, eMMC). Attempting this without advanced electronics and reverse engineering expertise can permanently damage your console and potentially pose electrical hazards.
  • Removing SMD capacitors and soldering directly to the APU requires extreme precision and specialized equipment.
  • Repeated glitching campaigns can burn out eMMC chips; industrial-grade replacements may be necessary for extensive research.

Tools

  • Oscilloscope
  • Logic Analyzer
  • Teensy
  • MOSFET
  • Shunt resistor
  • IDA Pro
  • NAND flash programmer
  • Voltage shifter
  • Soldering iron
  • Wires

Parts & materials

  • Xbox One console (Fat model (2013))
  • eMMC chip (Industrial grade (for replacement, if original burns out))

Steps

  1. Step 1 · 04:23 in the video

    Tear down the Xbox One console to access the motherboard and System-on-Chip (SOC).

    Tools: Screwdriver set, Pry tools

    Parts: 1 Xbox One console (fat model from 2013)

  2. Step 2 · 09:47 in the video

    Enumerate all SOC power rails and attempt to collect power traces, starting with the 1.8 volt rail.

    Tools: Oscilloscope, Shunt resistor

    Parts: 1 Xbox One SOC

  3. Step 3 · 12:40 in the video

    Tap into the I2C bus to analyze on-boot diagnostics data and look for fatal error codes.

    Tools: Logic analyzer, Wires

    Parts: 1 Xbox One motherboard

  4. Step 4 · 13:42 in the video

    Perform crowbar voltage glitching on the initially chosen power rail (1.8V) to destabilize the core and observe changes in I2C data.

    Tools: MOSFET, Wires, Teensy, Oscilloscope

    ⚠ Crowbar voltage glitching is a fault injection technique that can destabilize the core and cause instructions to get corrupted. This can damage the console.

  5. Step 5 · 15:14 in the video

    Re-target voltage glitching to the Northbridge core rail. Remove SMD capacitors from the rail, install a shunt resistor for power side channel analysis, and inject low-noise power.

    Tools: Soldering iron, Desoldering tools, Shunt resistor, Wires, Low-noise power supply, Oscilloscope

    Parts: multiple SMD capacitors (removed from Northbridge core rail)

  6. Step 6 · 16:31 in the video

    Analyze power traces on the Northbridge core rail to identify the entropy collection from ring oscillators and the initialization of the crypto co-processor and hardware RNG. This serves as a timing landmark.

    Tools: Oscilloscope

  7. Step 7 · 18:32 in the video

    Connect to the unmarked GPIO pads on the motherboard, which are intended for post codes if enabled.

    Tools: Wires, Soldering iron, Logic analyzer

  8. Step 8 · 19:45 in the video

    Solder a MOSFET for glitching and perform voltage glitches around the GPIO initialization logic to enable post codes. Observe post codes wiggling out on the GPIO lines.

    Tools: MOSFET, Soldering iron, Oscilloscope, Teensy, Logic analyzer

    ⚠ This process involves hardware modification and fault injection, which can damage the console.

  9. Step 9 · 26:09 in the video

    Flash attacker-controlled pattern data (recognizable bytes) into the eMMC (NAND chip) to prepare for memory copy attacks.

    Tools: NAND flasher, eMMC programmer

    Parts: 1 eMMC (NAND chip)

  10. Step 10 · 25:21 in the video

    Perform voltage glitches during the SP1 header memory copy operation (specifically targeting PCI transfers) to corrupt instruction decode within mem copy and achieve program counter (PC) hijack. Look for fatal error codes containing pattern bytes.

    Tools: MOSFET, Oscilloscope, Teensy, Logic analyzer

    ⚠ This is a fault injection attack that can lead to system crashes or instability.

  11. Step 11 · 32:50 in the video

    (Optional, for demonstration) Within the constrained user jail, develop a Return-Oriented Programming (ROP) chain to achieve arbitrary control and output a custom post code (e.g., 0x41414141) via the I2C bus.

    Tools: Software development tools, Debugger

  12. Step 12 · 35:55 in the video

    Locate and tap into the power rails used for sensing and burning e-fuses. Cut a trace and insert a shunt resistor to build an analog side channel for inspecting e-fuse reads. Convert these analog dips into strong digital pulses for stable glitch timing.

    Tools: Soldering iron, Desoldering tools, Shunt resistor, Wires, Custom circuit, Teensy, Logic analyzer, Oscilloscope

    Parts: 1 Xbox One motherboard (e-fuse power rails)

  13. Step 13 · 40:35 in the video

    Using the e-fuse read pulses as a stable timing anchor, perform voltage glitches to break out of the MPU configuration loop early, effectively preventing the MPU from being enabled.

    Tools: MOSFET, Oscilloscope, Teensy, Logic analyzer

    ⚠ This is a critical fault injection that can lead to system instability or bricking if not performed correctly.

  14. Step 14 · 44:16 in the video

    Due to changes in system behavior with the MPU disabled, re-sweep for new glitch parameters to reliably achieve the program counter hijack. This may require millions of boots and potentially replacing eMMC chips.

    Tools: MOSFET, Oscilloscope, Teensy, Logic analyzer, eMMC programmer

    Parts: multiple eMMC chips (industrial grade recommended for durability)

    ⚠ This step involves extensive, repetitive fault injection which can cause hardware wear and failure, particularly to eMMC chips.

  15. Step 15 · 46:01 in the video

    Perform a double glitch: first, to skip the MPU enablement, and second, to hijack the program counter as a user. This allows execution of shell code from the partially read SP1 header in secure RAM, and corruption of supervisor saved registers to return to supervisor mode.

    Tools: MOSFET, Oscilloscope, Teensy, Logic analyzer, Custom shell code

    ⚠ This is a highly advanced and potentially destructive hardware hack that grants full, unpatchable control over the console's boot ROM and entire system.

  16. Step 16 · 47:58 in the video

    Demonstrate control over GPIO pins by toggling them. Repurpose the previously tapped post pins into a custom UART (RX, TX, clock) to send payloads and test functionality.

    Tools: Teensy, Wires

Tips from the comments

  • The extreme level of security implemented by Microsoft in the Xbox One (from 2013) is remarkable, especially when compared to consoles like the Nintendo Switch or PlayStation 4, which were exploited through simpler methods.
  • This breakthrough could enable the development of a proper modchip, potentially allowing for the reuse of many original Xbox One consoles currently being sold cheaply or discarded.
  • The potential to optimize the glitch to land in just one second is incredibly fast, especially when compared to RGH 360 hacks which typically take around 5 seconds.
  • The HDMI input port on the Xbox One could offer unique opportunities for homebrew applications, a feature not commonly available on other modded consoles.
  • This work is crucial for fighting e-waste by enabling the reuse of Xbox One hardware, for example, by installing Linux.
  • There is hope that this hack could lead to running alternative operating systems like SteamOS or Linux on the Xbox One.
  • Despite the groundbreaking nature of the hack, some community members fear that its complexity might limit widespread replication and use, potentially keeping it a niche achievement.
  • The presentation is highly praised as an excellent lecture on fault injection techniques, covering finding anchors and precise timing.

Have a repair video of your own?

Make your own guide

Made from this YouTube video.

AI-generated from the video — double-check before you start. See Terms.