Latest
Gaming

The Original PlayStation 2 Security Chip Has Been Reverse Engineered

Dragon MechaCon firmware images were released back in 2021. MechaPwn, the exploit that makes later PS2s region-free and lets them read backup discs, was released a month later. That exploit's README says that older consoles don't use a Dragon-based MechaCon…

TechChallenger Staff3 October 2026 at 18:00 UTC2 min read
The Original PlayStation 2 Security Chip Has Been Reverse Engineered

Dragon MechaCon firmware images were released back in 2021. MechaPwn, the exploit that makes later PS2s region-free and lets them read backup discs, was released a month later. That exploit's README says that older consoles don't use a Dragon-based MechaCon and therefore aren't supported, and that no support is planned. That affects roughly 20 model numbers from the PS2's first three years between 2000 and 2003. Those machines can still run backups through memory card and hard drive exploits, but couldn't be unlocked at the chip level until now because nobody could see its code. These dumps make that search possible for the first time.

The images alone don't hold enough information to build an optical drive emulator, but they could support a modchip that replaces the MechaCon, while keeping the drive's DSP to read discs. Since PS2 games weren't encrypted, nothing new is unlocked here. But the firmware does expose the code behind Sony's "MagicGate" encryption for memory cards and KELF executables the console boots from disc and memory cards. That'll eventually feed "full-system low-level emulation," says contributor uyjulian. PCSX2 and other emulators, which can also emulate the weaker GameCube, don't run the chip's code at all: PCSX2 reimplements MechaCon's commands in C++ and reads a 1KB NVRAM file and a four-byte version number from disk to stand in for the real part. DiscoStarslayer maintains a PCSX2 fork called Reliquary, aimed at the PS2's authed paths. They acknowledge in its README that generated stand-in data isn't a substitute for hardware values when a security check inspects console identity.

As for the SPC970, the first job of its dump is to find a bug that opens up the early consoles. With MechaPwn, people could read the Dragon chip's code and find a weakness in how Sony let that chip update itself. uyjulian says a MechaPwn or TonyHax-style unlock for the SPC970 is one of the goals here, but it won't come as fast. It took researchers only a month to crack Dragon because Sony built that chip to accept patches. That gave researchers something to break. The SPC970 can't be updated at all; its code was baked into the chip in 2000 and has never changed.

More in Gaming

All Gaming »