The Ledger Donjon security team used a focused laser to disable debug protections on the RP2350 microcontroller by flipping bits in a target register, demonstrating that physical access to hardware enables sophisticated attacks even against secure chips with glitch detection and secure boot features.
Ledger Donjon's security team used a focused laser to flip bits in the RP2350's debug-enable register, bypassing the chip's secure boot and glitch detection by decapsulating it and targeting the die with infrared light, demonstrating that physical access to hardware enables sophisticated attacks even against well-designed security features.
A developer at Nordic Semiconductor discovered unexpected memory values in the nRF54L series' Key Management Unit while using a debugger to manually inspect registers. The issue stems from how the debugger interacts with the SoC's security components, particularly the Secure Information Configuration Region (SICR) used for storing cryptographic keys and metadata.
Researchers used photon-emission microscopy and laser fault injection to bypass security features on the Raspberry Pi RP2350 microcontroller, locating and manipulating a register that controls debug access. By exploiting timing during a rescue reset before firmware could apply runtime locks, they recovered secrets from one-time-programmable memory, though the attack requires physical access and expensive laboratory equipment.