The PS2's last sealed security chip is open. What changes?

Researchers dumped the early PS2's SPC970 MechaCon firmware. It matters for preservation and future homebrew, but your console has not gained a new jailbreak.

Can an early PlayStation 2 play burned discs because of this? No, not yet. Will PCSX2 suddenly run faster? No. Does the SPC970 firmware dump matter? Yes, especially for researchers trying to document, emulate and repair the original fat PS2.

That distinction matters because "security chip cracked" headlines make this sound like a finished jailbreak. It is not. A small group of PS2 researchers has finally extracted clean firmware from Sony's SPC970 MechaCon, the controller used in early fat consoles. The dump gives them code they can study. It does not hand ordinary owners a safe new mod.

What is the SPC970 MechaCon?

The MechaCon sits between several jobs that made the PS2 unusually awkward to reproduce. It controls the optical drive, authorizes discs and handles parts of Sony's MagicGate and KELF security. Later fat and slim systems moved to a newer "Dragon" MechaCon whose firmware was dumped in 2021. The older SPC970 remained the stubborn gap.

The newly released SPC970 dumping project supports three revisions: the 256 KiB CXP101064 and CXP102064, plus the 192 KiB CXP103049. Those chips appeared across early machines including the Japanese SCPH-10000 and later 30000 and 39000-series models. The project's public index already documents firmware from several regions and revisions.

Close view of a Sony Computer Entertainment chip associated with the SPC970 MechaCon research.
The firmware dump gives researchers code to inspect, not a one-click unlock. Image: DiscoStarslayer via Bluesky, as reproduced by Engadget.

How researchers got the firmware out

The chip stores its program in mask ROM. That code was fixed when the silicon was made, so researchers could not ask the PS2 to patch or export it through a friendly update mechanism. The route in was the separate 1 KiB EEPROM used for configuration data.

According to the dumper documentation, opening a configuration write with a block count of zero causes an internal counter to underflow. Sending more than the expected seven blocks then reaches RAM used by the EEPROM worker. The tool redirects that worker so it copies a 256-byte piece of ROM into the readable EEPROM area. Repeating the process eventually reconstructs the whole firmware image on USB storage.

It is clever, slow and hard on the machine. A complete 256 KiB dump needs roughly 1,000 of those copy cycles. The current tool backs up the EEPROM, restores it afterward and verifies the result against the MechaCon's own power-on checksums. Those safeguards reduce risk; they do not erase it.

What changes now

Now: researchers can inspect real SPC970 code instead of inferring every behavior from inputs and outputs. That improves documentation of early PS2 revisions and lets preservation projects compare firmware across regions and board versions. It also closes a conspicuous hole in the technical record of a console that Sony says sold more than 160 million units.

Later, perhaps: the code may expose a vulnerability suitable for a MechaPwn-style or TonyHax-style unlock on early machines. It could also help with more faithful low-level emulation, replacement MechaCon work or a future modchip that keeps the drive's existing DSP. These are research goals, not shipping features.

Not from this dump alone: a new optical drive emulator, instant backup-disc support or a PCSX2 speed boost. Contributor uyjulian's technical clarification notes that PS2 game data was not encrypted in the first place. PCSX2 currently reimplements MechaCon commands rather than running this firmware, so dropping the ROM into an emulator folder will not improve your games.

Why PCSX2 still has something to gain

PCSX2 does not need the SPC970 firmware for ordinary high-level emulation. It uses C++ replacements for the commands games expect and stand-in files for the console's NVRAM and version data. That is enough for most software, which is why PS2 emulation did not spend the last two decades waiting for this dump.

Low-level work asks a different question: can the emulator reproduce authenticated paths and hardware identity checks instead of approximating them? DiscoStarslayer's Reliquary fork is exploring that territory. The new firmware is useful there, but accuracy work is measured in implementation and tests, not in possession of a ROM file.

This is the same patient, unglamorous work behind wider game preservation efforts. Access to old software is only one part of preservation. We also need to understand the hardware assumptions that software was written around.

Early fat PS2 owners should wait

The current dumper is an alpha research tool, not a weekend softmod. Its own documentation warns that interrupted writes, unsupported hardware, storage failures or power loss can corrupt console data and leave a machine needing hardware-level repair. EEPROM also has limited write endurance, and this method writes to it repeatedly.

If your PS2 works, the sensible move is to leave it working. There are already established software routes for homebrew and backups on many setups. The new dump is for people developing and validating the next layer of tools, not casual owners chasing a headline.

That restraint is worth keeping in mind whenever old hardware research escapes into the mainstream. A breakthrough can be real without being ready for players. Retro projects built around a Raspberry Pi handheld or modern ports are forgiving; a wear-limited security controller inside an irreplaceable console is not.

What to watch next

The next meaningful update will not be another dramatic adjective. Watch for a stable dumper release, broader verified model support, a public exploit for SPC970 systems, or actual integration into PCSX2 or Reliquary. Repair and optical-drive replacement projects would also be concrete outcomes.

For now, the achievement is narrower and better than the hype: researchers spent four years turning an unreadable chip into code the preservation community can inspect. The PS2 did not become a different console overnight. We simply know more about the machine we already have.