Laser Fault on RP2350
Ledger Donjon published research showing that permanent debug disable on the Raspberry Pi RP2350 microcontroller can be bypassed with laser fault injection. They recovered a secret from one-time-programmable (OTP) memory on a chip with secure boot enabled, debug permanently disabled, and glitch detectors at maximum sensitivity.
The attack chain is elegant. Here is how it works.
The target
The RP2350 is Raspberry Pi's dual-core microcontroller, featuring Armv8-M TrustZone, secure boot, and permanent debug-disable settings stored in OTP memory. The RP2350 Hacking Challenge asked participants to extract a 128-bit secret from OTP on a fully locked-down chip. Ledger Donjon tested the A4 revision, which incorporates fixes from the first round of the challenge.
Photon emission finds the register
The first problem is targeting. Setting a single bit in a memory-mapped register requires knowing where that bit lives on the silicon. A blind laser scan is impractical at that scale.
Their solution: photon-emission microscopy (PEM). Switching transistors emit faint near-infrared photons. By toggling specific DEBUGEN register bits in loops and subtracting the averaged emission maps, they isolated the physical locations associated with each bit. This reduced the search area to a few micrometres.
Laser pulses set the bits
With the target locations known, they used a 980 nm pulsed laser at roughly 1.2 W with a 100 ns pulse width through a 50x objective. Two positions a few micrometres apart corresponded to the PROC1 and PROC1_SECURE bits. Setting both required an iterative sequence: pulse one position until bus access appeared, then pulse the other until Secure attribution was confirmed, switching back if the first bit cleared.
Once set, the bits stayed set without further pulses. The laser effectively overrode the permanent DEBUG_DISABLE flag stored in OTP. DEBUGEN_LOCK, which blocks software writes, did not prevent laser-induced changes.
Rescue reset prevents the runtime lock
The challenge's secret lives in OTP page 48, which has a persistent lock allowing Secure reads but a runtime lock applied by firmware that blocks all access. Reading the secret requires the page to be in its pre-firmware state.
The RP-AP, an always-accessible debug port, exposes a rescue reset that halts the chip in the boot ROM before any user firmware runs. After rescue reset, the runtime lock resets to the persistent value (Secure read-write), but firmware never executes to tighten it. With Secure debug enabled via the laser fault, the debugger reads the secret directly from OTP.
What this means
The system-level lesson is about enforcement paths. The RP2350 has redundant voting for OTP security fields, permanent debug disable, glitch detectors, and TrustZone separation. But the DEBUGEN register that overrides debug disable has no documented redundancy, parity, or majority vote. The enforcement chain is only as strong as its weakest link, and DEBUGEN was that link.
The attack requires physical access, destructive sample preparation (backside decapsulation), and approximately $250'000 in laboratory equipment. This is not a remote exploit. But for hardware security researchers and anyone designing with the RP2350 for sensitive applications, it is a real result: permanent debug disable is not permanent against a determined adversary with a laser.
Raspberry Pi was disclosed on July 28, 2026 and engaged constructively with the findings. The RP2350 remains a capable microcontroller. The lesson is that "permanent" in hardware security means "permanent within the threat model," and the threat model should include laser fault injection for high-value targets.
Sources
[1] Ledger Donjon: Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure Debug: donjon.ledger.com
[2] RP2350 datasheet: pip.raspberrypi.com
[3] RP2350 Hacking Challenge: github.com