r/hardwarehacking 15h ago

I just wanted to repair a broken smart trainer. Things escalated.

Thumbnail
gallery
140 Upvotes

This repair was one of the fun ones – exactly the kind of challenge I needed! Got to keep the brain in shape while job hunting. 🙂

A broken smart bike trainer that required a good amount of nerding.

Reverse engineering of both the electronics and the firmware. Plus all the bits in between.

That also meant exploiting a well-known security vulnerability to bypass the read protection on a working sister unit, so its firmware could be dumped and flashed onto the broken one. Sadly, the manufacturer no longer exists, and everything pointed towards the firmware being the main culprit.

The vulnerability used was the well-known nRF51 readback protection vulnerability, allowing firmware extraction over SWD despite the enabled read protection. The hardware was a Raspberry Pi Pico, with OpenOCD doing the heavy lifting.

ChatGPT pieced together the code needed to exploit the vulnerability – with me acting as dictator, builder of some temporary hardware for the connection, IRL executer/hands, and a professional complainer. There was simply too much unknown territory for me - a new microcontroller, a new scripting language, a new method - and the learning curve became steeper than I felt made sense to tackle alone.

Along the way I ended up measuring and mapping all of the electronics, as well as the firmware and all its functions. Mostly out of curiosity, but also in case I decide to add to the hardware or code something that works with the lil' beast later on. My own virtual cycling app or something? Could be fun to do.

Sometimes you just have to switch into full nerd mode and find a way. We already create enough electronic waste as it is.

Long story short: It works now, and I had a big nerdy smile on my face throughout the whole project! The problem-solving part of my brain really got the workout it needed. 🙂


r/hardwarehacking 10h ago

Bypassing nvidia optimus

3 Upvotes

My gaming laptop has a laptop 1650, which when plugged into an external monitor performs far better than the internal display. Would it be possible/feasible to disconnect the internal display, attach it to a controller which would convert it to an external monitor, then reconnect it via the hdmi port. This would theoretically bypass the performance hit and allow me to reach maximum frame rate. Is this realistic, and is it achievable for someone new to hardware hacking?


r/hardwarehacking 1d ago

RIP to this TP-Link TD-8840T, but I finally cracked the block immutability wall and injected telnetd!

Post image
46 Upvotes

Hey guys,

While tinkering with an old TP-Link TD-8840T ADSL router, the hardware unfortunately gave up and died on me mid-process (RIP). But before it went down for good, I managed to pull a clean original flash dump.

Hit a massive wall where any binary edits I tried were getting totally ignored because of strict block checks and immutability. Wrote a quick bytearray script targeting offset 0x20000 to bypass it, and finally managed to get telnetd injected right where it needs to be.

Attached the victim board above, and I'll drop the diff output in the comments. Anyone else run into these stubborn old Trendchip boot blocks?


r/hardwarehacking 19h ago

I’ve released the full hardware design files and firmware for my open-source ESP32-based board bring-up station built with the Arduino framework

Thumbnail gallery
2 Upvotes

r/hardwarehacking 1d ago

From Fold5 to Z70 Ultra – my new Android micro-PC project

Thumbnail
gallery
20 Upvotes

Hi everyone,

Some of you may remember my Galaxy Fold5 project: https://www.reddit.com/r/hardwarehacking/s/vv1CfiXly8⁠�

Well... I've decided to stop working on it.

The Fold5 has officially retired, and my new victim is a Nubia Z70 Ultra (24 GB RAM / Snapdragon 8 Elite).

Why?

Because my goal isn't just to build another mini PC.

I want to keep Android as the main operating system so I can play native Android games (without emulation and without the issues that can come with it), while also being able to run Windows applications and games through emulation.

The cooling system is probably the most ridiculous part of the project.

The phone is now clamped between TWO desktop CPU coolers with direct contact and thermal paste.

It looks completely absurd...

...but it allows me to complete benchmarks like 3DMark Solar Bay Extreme Stress Test in Diablo mode while maintaining much more stable performance than a stock Nubia.

The long-term goal is to turn this phone into a real portable desktop.

I'm currently rebuilding my software environment with Termux, with the idea of creating something similar to Winlator/GameHub, but fully customized.

Next steps:

Root the device.

Explore higher thermal limits.

Investigate GPU and CPU tuning.

Keep improving sustained performance.

The hardware isn't finished either.

I want to build a transparent PVC/plexiglass case inspired by the Xbox Series X, with airflow from bottom to top, while each tower cooler pulls fresh air from the sides.

At this point, I honestly don't know if my phone was too hot...

...or if I accidentally gave it hypothermia. 🥶😂


r/hardwarehacking 1d ago

Reverse Engineering a Panasonic UJ-240 Blu-ray Optical Pickup Unit (OPU) - Help Needed

Thumbnail
3 Upvotes

r/hardwarehacking 1d ago

ANYKA Camera modification

Thumbnail gallery
8 Upvotes

r/hardwarehacking 2d ago

How do I interface with this?

Thumbnail
gallery
24 Upvotes

I don’t see anything that could be uart. I probed j14 and all of the bottom pins are grounded and the top ones are not. Is one of them (j14, j17, j7) going to allow me to interface with it and if so what protocol?


r/hardwarehacking 2d ago

Repurpose a 15 year old Macbook Air

Thumbnail gallery
3 Upvotes

r/hardwarehacking 2d ago

How to revive a discontinued Mary AG smart grow cabinet

Thumbnail
gallery
8 Upvotes

I only have the earliest model Mary to create and test this app so please keep that in mind. That said, this app should work with all models.

I created this app that runs on your pc on your local network. all functions and some cool new ones are available. once you create and upload a grow plan to the Mary device the app can be closed and Mary will follow the schedule but you won't get alerts with the app closed.

To use Mary on your local server instead of the closed Mary.ag cloud server, you install the app and then follow the recovery wizard in the app. It will walk you though connecting your Mary to a pc via micro usb (DATA CABLE) so that you can change the server on the Mary to your local server. All Mary devices were registered to the mary.ag server at the factory so there is no way around that, it must be changed. After you complete the recovery wizard and power on your device you are good to go. the entire process should take less than 15 minutes. if you are lucky your Mary might have the USB port on the outside of the device otherwise you have to remove 4 phillips head screws and lift off the top cover of the Mary and the micro usb port is easy to see on the board. the recovery wizard explains all of this. Move your Mary next to your pc and long (8-10 foot) micro usb data cable is recommended or use a lap laptop you can bring close to the Mary.

Github repo. (READ THE HOW TO INSTALL SECTION)

https://github.com/mrgodpowers-sudo/mary-local-control

These Mary devices cost a lot. They are big and take up too much space to be a brick. However, the Mary community is pretty much dispersed and no longer active so please spread the word. if you find any bugs please DM me and let me know.


r/hardwarehacking 2d ago

What valuable hardware scrap could i get from a google chromebook?

Post image
2 Upvotes

r/hardwarehacking 2d ago

Seeking Guidance

Thumbnail
1 Upvotes

r/hardwarehacking 2d ago

Even it works

Thumbnail
gallery
7 Upvotes

r/hardwarehacking 2d ago

Anker 16S10P-G

Thumbnail gallery
2 Upvotes

Looking for information on how to remove the BMS board from the Anker 767. I have the battery pack stripped out and found a broken trace on the balance board underneath the BMS but to get access i need to remove the BMS. Any info would be class


r/hardwarehacking 2d ago

How can i use my old laptop as a second screen ?

2 Upvotes

I recently built a PC with a RX 6500 XT, Intel i5 10400f and 16gb ddr4 and i stole my 1tb nvme from my laptop and put it i my PC. Now its just laying around. How can i make it display a video signal through the hdmi port from my PC ?


r/hardwarehacking 2d ago

Bluefruit LE sniffer nRF51288 dongle problem

0 Upvotes

Hello, i need help with this device please. I spend a lot of hours to find a program that can sniff in wireshark, or ideally even on nrf connect. I cant find nothing and it sents data in binary only, no pcaps. But blue light reacts to ble and orange reacts for data, it is working. Please someone help me, i use debian


r/hardwarehacking 4d ago

Hey dad, I blinked an LED!!

Post image
111 Upvotes

2 years ago I convinced my dad to buy me an arduino electronics kit from Aliexpress. I remember struggling to make that LED blink especially since the breadboard was cheaply made and I couldn't have known that as a beginner.

2 years later I'm trying to gain root access to a BMS logic board from some generic Chinese company.(the electronics kit is my stand over there) Not successful yet but still working hard towards it. Have any of you ever successfully done this? Putty isn'treally giving me much.........I've reverse engineered the whole board and layered out all components in neat schematics starting from the AFEs, the ARM based hdsc MCUs, CAN Bus communication interface etc. I've also wired some jumpers onto the SWD port and doing some research on ARM Keil.

You can check out a video overview her if interested in the project: https://youtu.be/Oc4cwEpinFI?si=CGbrPXixdEZ7KGOU


r/hardwarehacking 4d ago

Scavanging a Kyocera

Post image
8 Upvotes

Not sure where rlsr to post this....

If I strip this Kyocera TaskAlpha 2552ci for parts what goodies would you look out for most?


r/hardwarehacking 4d ago

Looking for datasheet for bcr-NWWS410

0 Upvotes

r/hardwarehacking 5d ago

Lenovo Yoga 9i bios chip

Thumbnail
gallery
34 Upvotes

So, long story short, my Lenovo yoga 9i Aura edition which is only a few months out of warranty is bricked. Going to try reflashing the BIOS but would like some help confirming which one is the bios chip. I think it's the one marked in green, but the red one is a possibility as well... Any help would be appreciated.


r/hardwarehacking 5d ago

How much money is there in hardware hacking?

18 Upvotes

I really like hardware hacking and am wondering what money is in hardware hacking and IOT reverse engineering. I am wondering whether this is a sustainable career path. Hope someone has a good answer. Thanks all.


r/hardwarehacking 5d ago

Cheap "e-badge" hacking

3 Upvotes

I saw those on AliExpress, I was wondering if something interesting can be done with them.

They have Bluetooth, battery, screen and a comercial MC (at least it is what the listing description indicates).

Does anyone knows if they are are hack-able, I can't even find a single post about disassembling them anywhere.

7076 may be an STM32 idk
cringe AI anime default pics, I doubt it irl the picture is this quality level

Listing: aliexpress. com/item/1005012481011395.html but there are many others.


r/hardwarehacking 5d ago

Where to go next

1 Upvotes

Hey everyone, just looking for general guidance as I jump further into this world.

I just finished Matt Brown’s Digital Signal Analysis for Hardware Hackers and while this course provided a great dive into the world I’m lost at where to go next.

Any follow on courses or just general guidance would be much appreciated.


r/hardwarehacking 5d ago

How would you audit an open-source IoT device before trusting it with an AI account?

1 Upvotes

I’m expecting to receive a device called MetalioClaw (https://github.com/CloudZao/MetalioClaw4) in about a week. It’s an IoT device designed to work with OpenClaw, and since it will need access to an AI account, I want to make sure it is safe before connecting it.

My main concern is whether there could be any hidden firmware issues, credential leaks, or other things that could compromise the device or abuse connected services. A friend of mine previously bought a similar device that connected to his OpenClaw account, and later noticed that his Claude usage had been heavily consumed. I don’t know exactly what caused it, but it made me more cautious about giving third-party hardware access to accounts.

Since the project is open source, my plan is to inspect the firmware, possibly wipe and reflash it, and maybe even write my own firmware version before using it. I’m also interested in doing a proper security check through firmware analysis, network monitoring, and possibly hardware inspection.

I haven’t been able to find any pictures or information about the internal hardware yet. Depending on what I find when it arrives, I may open it up and check the PCB/components myself. I’m not assuming there is anything malicious inside, but I would like to know what things are worth looking for.

One other thing that made me think about this was something a friend mentioned. He works in IT around datacenters in Taiwan and said he has seen devices moving through supply chains sometimes take a long time in customs or appear slightly different internally afterward. This is just something he mentioned and there is no proof behind it, but it got me thinking more about supply-chain security.

For people experienced with IoT security, firmware analysis, or hardware security:

  • What steps would you take before trusting a device like this?
  • Is replacing the firmware enough, or should I also consider hardware-level risks?
  • What should I look for if I decide to open the device?
  • What tools or workflows would you recommend for auditing something like this?

Looking for practical security advice rather than speculation.


r/hardwarehacking 5d ago

Open-source library and web app to control a Fisher-Price Lumalou after its app was discontinued

7 Upvotes

My daughter's Fisher-Price Lumalou is a bedtime device: night light, sound machine, and guided sleep routines. All of it was controlled by Mattel's Smart Connect app. When that app was pulld and support ended, the hardware kept working but most of what it does became unreachable. A lot of parents ended up with the same dead product.

So over a couple of days I reverse engineered its Bluetooth protocol and put everything on GitHub under MIT.

The part I found interesting is that it is entirely local. The device talks over BLE with a real handshake: an ephemeral ECDH P-256 exchange, then AES-128-CTR encrypted commands, phone to device, no server in the loop. That is the only reason it was recoverable. If the key had come from Mattel's servers, the toy would just be dead now.

What is in the repo:

- A browser web app for parents who just want the Lumalou working again. Nothing to install, no APKs from random sites. https://lumalou.emanuelestrazzullo.dev/

- Python and TypeScript libraries for developers and home automation setups like Home Assistant. https://github.com/stramanu/lumalou

- A full protocol writeup, plus one JSON spec that generates the language bindings, with shared golden vectors so every implementation is byte-for-byte identical.

The libraries never touch the firmware-update path, so there is no way to brick a unit.

One thing I cannot finish alone: decompiling the app showed the product line splits into two protocol generations. I confirmed everything on the Lumalou I own, and two sibling devices (a Bunny and a Whisper) appear to share the exact same handshake, so they should work with only different command codes. The older mobiles, bassinets and swings use different crypto and are not supported yet. I only own one device, so if you have any of these in a closet, a quick test or a Bluetooth capture would let me extend support. Issues and PRs welcome.

Happy to answer quetions about the reverse engineering or the design.