PS2 early-model MechaCon firmware dumped after four years of reverse engineering

PS2 early-model MechaCon firmware dumped after four years of reverse engineering

N
News Editor
2026-09-18 10:20:44
Canadian reverse-engineering hobbyist DiscoStarslayer said he has finally extracted firmware from the PlayStation 2's early-model MechaCon security chip after four years of work. The chip handles disc authentication, MagicGate memory card checks, and decryption for KELF encrypted executables. According to the report, no one had fully dumped the firmware from these early PS2 units in the 26 years since the console launched. DiscoStarslayer said the process involved decapping the chip, producing optical dumps, and eventually finding a software-based method to read the firmware. He credited developer Libby with identifying the exploit from incomplete optical data. A GitHub list created on Sept. 14 and updated through Sept. 16 shows 22 firmware entries with SHA-256 hashes and build dates, covering most early fat PS2 models from the SCPH-15000 to SCPH-39000 series, as well as Namco's System 246 and 256 arcade boards. The firmware files themselves were not released. The earliest v1 firmware, including the launch-era Japanese SCPH-10000, remains unread. Participants said the dump does not newly unlock game content and is likely to be more useful for emulator development, hardware research, and repair-related work than for piracy.

Canadian reverse-engineering hobbyist DiscoStarslayer says he has dumped firmware from the PlayStation 2's early-model MechaCon security chip after four years of work, exposing code that had never been fully read since the console first launched.

In a Sept. 13 post on X, he wrote, "One of the last secrets of the PS2 has been blown wide open." He said the job took decapping, optical dumping, and then, at last, a software-based solution. He also thanked Libby for spotting the exploit in what he called dirty optical dumps. By the afternoon of Sept. 18, the post had reached 350,000 views.

What MechaCon does inside the PS2

MechaCon, short for Mechanics Controller, runs the disc drive motor and the read head. But that is only part of it. It also sits inside Sony's anti-piracy setup, checking whether a disc is genuine, validating MagicGate-encrypted memory cards, and decrypting KELF-format encrypted executables.

The PS2 launched in Japan in March 2000 and went on to sell 160 million units worldwide, still the best-selling game console ever made. According to the report, the firmware inside MechaCon on early systems had not been fully extracted for 26 years.

From chip decapping to a software readout

DiscoStarslayer started by stripping away the chip's outer package with chemicals to expose the silicon die, a step called decapping. Then he photographed the die under a microscope and tried to read the stored data from those images through optical dumping.

It did not go cleanly. The method produced plenty of errors, and DiscoStarslayer called the optical dumps dirty. Libby then found an exploit in that incomplete data, which let the team read the full firmware directly through software instead of rebuilding it bit by bit from microscope photos.

The team put up a public GitHub list on Sept. 14 and named the exploit "Mecha-LIBeration." In a Sept. 16 update, that list showed 22 firmware entries with SHA-256 hashes and compilation dates. The hashes were there for file verification. The firmware files themselves were not uploaded.

Those firmware builds run from July 2000 through June 2003. They cover most early fat PS2 models, from the SCPH-15000 through the SCPH-39000 series, and they also include Namco's PS2-based System 246 and System 256 arcade boards.

Launch-era firmware is still missing

The list also flags versions that still have not been dumped. The earliest v1 firmware remains unread, including the launch-era Japanese SCPH-10000 and early development units. TechSpot reported that DiscoStarslayer and Libby are trying to extend support to more chip versions.

Later Dragon chips had already been targeted

Starting with the SCPH-50000 series, Sony swapped out MechaCon for a redesigned chip codenamed Dragon. That chip appeared in later fat models and in every slim PS2 system. Back in April 2021, the MechaResearch team released the MechaPwn tool on GitHub. It used the Dragon chip's built-in update function to rewrite settings, enabling region-free operation and backup disc loading.

MechaPwn documentation says earlier systems do not use the Dragon chip, fall outside its support scope, and are not planned for future support. So this firmware dump covers the older chips MechaPwn could not touch.

Limited piracy impact, broader value for emulation and research

Developer uyjulian, who said he took part in the reverse-engineering effort, wrote in the comments on Tom's Hardware's coverage that the firmware does not do much for piracy. He said backup games can already be launched through software-only methods, including exploits involving memory cards, hard drives, or the DVD player. He also said PS2 game discs are not encrypted, aside from titles that use DNAS for online authentication, so the dumped firmware does not newly unlock disc content.

uyjulian said the firmware matters more for emulators and research. MagicGate and KELF verification both go through MechaCon, and access to the firmware could let emulators reproduce those security mechanisms at a lower level while also giving researchers more material to examine for extra exploits.

TechSpot, citing PCSX2 compatibility data, said more than 98% of PS2 games are already listed as playable on the PC emulator. HotHardware said emulators had previously handled communication between MechaCon and other hardware through approximation rather than full low-level behavior.

uyjulian also said the firmware by itself is still not enough to build an optical drive emulator, or ODE, that replaces the physical disc drive with a hard drive or memory card. But he added that it could be used to create a modchip that replaces MechaCon. The source text says HotHardware believes this could help...

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
3000

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.