{"id":21573695,"url":"https://github.com/syss-research/icebreaker-glitcher","last_synced_at":"2025-09-04T13:35:05.916Z","repository":{"id":119356939,"uuid":"237160762","full_name":"SySS-Research/icebreaker-glitcher","owner":"SySS-Research","description":"Simple voltage glitcher implementation for the iCEBreaker FPGA board","archived":false,"fork":false,"pushed_at":"2020-03-02T07:42:42.000Z","size":886,"stargazers_count":17,"open_issues_count":0,"forks_count":5,"subscribers_count":2,"default_branch":"master","last_synced_at":"2025-03-18T06:32:59.069Z","etag":null,"topics":["fpga","glitching","ice40","ice40up5k","icebreaker","it-security","security","security-tools","security-vulnerability","tool"],"latest_commit_sha":null,"homepage":null,"language":"Verilog","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/SySS-Research.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null}},"created_at":"2020-01-30T07:26:10.000Z","updated_at":"2025-01-24T00:22:43.000Z","dependencies_parsed_at":null,"dependency_job_id":"7c44e342-722f-4fe9-b05e-b577d5b22a5b","html_url":"https://github.com/SySS-Research/icebreaker-glitcher","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/SySS-Research/icebreaker-glitcher","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/SySS-Research%2Ficebreaker-glitcher","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/SySS-Research%2Ficebreaker-glitcher/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/SySS-Research%2Ficebreaker-glitcher/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/SySS-Research%2Ficebreaker-glitcher/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/SySS-Research","download_url":"https://codeload.github.com/SySS-Research/icebreaker-glitcher/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/SySS-Research%2Ficebreaker-glitcher/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":271786033,"owners_count":24820590,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-08-24T02:00:11.135Z","response_time":111,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["fpga","glitching","ice40","ice40up5k","icebreaker","it-security","security","security-tools","security-vulnerability","tool"],"created_at":"2024-11-24T12:07:44.780Z","updated_at":"2025-08-24T03:34:38.551Z","avatar_url":"https://github.com/SySS-Research.png","language":"Verilog","funding_links":[],"categories":[],"sub_categories":[],"readme":"# iCEBreaker Glitcher\n\nThe iCEBreaker Glitcher is a simple voltage glitcher for an iCEBreaker FPGA board.\n\nThis glitcher is based on and inspired by glitcher implementations by\nDmitry Nedospasov ([@nedos](https://twitter.com/nedos)) from [Toothless Consulting](https://toothless.co/)\nand Grazfather ([@Grazfather](https://twitter.com/Grazfather)).\n\nThe iCEBreaker Glitcher exemplarily demonstrates how the code read protection (CRP) of\nNXP LPC-family microcontrollers can be bypassed as presented by Chris\nGerlinsky (@akacastor) in his talk [Breaking Code Read Protection on the NXP LPC-family Microcontrollers](https://recon.cx/2017/brussels/resources/slides/RECON-BRX-2017-Breaking_CRP_on_NXP_LPC_Microcontrollers_slides.pdf)\nat REcon Brussles 2017.\n\n## Hardware Requirements\n\n- [iCEBreaker FPGA Board](https://www.crowdsupply.com/1bitsquared/icebreaker-fpga)\n- Analog switch, for instance [MAX4619](https://www.maximintegrated.com/en/products/analog/analog-switches-multiplexers/MAX4619.html)\n- Power supply (2 externally supplied voltages required), for instance [Rigol DP832](https://www.rigolna.com/products/dc-power-loads/dp800/)\n\n## Software Requirements\n\n- [Python 3](https://www.python.org/)\n- [pylibftdi](https://pypi.org/project/pylibftdi/)\n- [sty](https://pypi.org/project/sty/)\n- [yosys](https://github.com/YosysHQ/yosys)\n- [nextpnr-ice40](https://github.com/YosysHQ/nextpnr)\n- [Project IceStorm Tools](https://github.com/cliffordwolf/icestorm)\n\n## Installation\n\nThe iCEBreaker Glitcher can be downloaded and built using the SymbiFlow toolchain in the following way:\n```\ngit clone https://github.com/SySS-Research/icebreaker-glitcher.git\ncd icebreaker-glitcher\nmake\nmake prog\n \nvirtualenv glitching\nsource glitching/bin/activate\npip install -r python/requirements.txt\n```\n\n## Test Setup\n\nThe following two images show a working test setup for the iCEBreaker Glitcher.\n\n![iCEBreaker Glitcher test setup](/images/icebreaker_glitcher_test_setup.jpg)\n\n![MAX4619 wiring using iCEBreaker Glitcher](/images/glitcher_max4619_wiring.jpg)\n\n## Usage\n\nThe iCEBreaker Glitcher is used via the Python command tool **iCE iCE Baby Glitcher**.\n\n```\n$ python ice-glitcher.py --help\n \n ██▓ ▄████▄  ▓█████     ██▓ ▄████▄  ▓█████     ▄▄▄▄    ▄▄▄       ▄▄▄▄ ▓██   ██▓     ▄████  ██▓     ██▓▄▄▄█████▓ ▄████▄   ██░ ██ ▓█████  ██▀███ \n▓██▒▒██▀ ▀█  ▓█   ▀    ▓██▒▒██▀ ▀█  ▓█   ▀    ▓█████▄ ▒████▄    ▓█████▄▒██  ██▒    ██▒ ▀█▒▓██▒    ▓██▒▓  ██▒ ▓▒▒██▀ ▀█  ▓██░ ██▒▓█   ▀ ▓██ ▒ ██▒\n▒██▒▒▓█    ▄ ▒███      ▒██▒▒▓█    ▄ ▒███      ▒██▒ ▄██▒██  ▀█▄  ▒██▒ ▄██▒██ ██░   ▒██░▄▄▄░▒██░    ▒██▒▒ ▓██░ ▒░▒▓█    ▄ ▒██▀▀██░▒███   ▓██ ░▄█ ▒\n░██░▒▓▓▄ ▄██▒▒▓█  ▄    ░██░▒▓▓▄ ▄██▒▒▓█  ▄    ▒██░█▀  ░██▄▄▄▄██ ▒██░█▀  ░ ▐██▓░   ░▓█  ██▓▒██░    ░██░░ ▓██▓ ░ ▒▓▓▄ ▄██▒░▓█ ░██ ▒▓█  ▄ ▒██▀▀█▄ \n░██░▒ ▓███▀ ░░▒████▒   ░██░▒ ▓███▀ ░░▒████▒   ░▓█  ▀█▓ ▓█   ▓██▒░▓█  ▀█▓░ ██▒▓░   ░▒▓███▀▒░██████▒░██░  ▒██▒ ░ ▒ ▓███▀ ░░▓█▒░██▓░▒████▒░██▓ ▒██▒\n░▓  ░ ░▒ ▒  ░░░ ▒░ ░   ░▓  ░ ░▒ ▒  ░░░ ▒░ ░   ░▒▓███▀▒ ▒▒   ▓▒█░░▒▓███▀▒ ██▒▒▒     ░▒   ▒ ░ ▒░▓  ░░▓    ▒ ░░   ░ ░▒ ▒  ░ ▒ ░░▒░▒░░ ▒░ ░░ ▒▓ ░▒▓░\n ▒ ░  ░  ▒    ░ ░  ░    ▒ ░  ░  ▒    ░ ░  ░   ▒░▒   ░   ▒   ▒▒ ░▒░▒   ░▓██ ░▒░      ░   ░ ░ ░ ▒  ░ ▒ ░    ░      ░  ▒    ▒ ░▒░ ░ ░ ░  ░  ░▒ ░ ▒░\n ▒ ░░           ░       ▒ ░░           ░       ░    ░   ░   ▒    ░    ░▒ ▒ ░░     ░ ░   ░   ░ ░    ▒ ░  ░      ░         ░  ░░ ░   ░     ░░   ░\n ░  ░ ░         ░  ░    ░  ░ ░         ░  ░    ░            ░  ░ ░     ░ ░              ░     ░  ░ ░           ░ ░       ░  ░  ░   ░  ░   ░    \n    ░                      ░                        ░                 ░░ ░                                     ░                               \niCE iCE Baby Glitcher v0.5 by Matthias Deeg - SySS GmbH\nA very simple voltage glitcher implementation for the Lattice iCEstick Evaluation Kit\nBased on and inspired by voltage glitcher implementations by Dmitry Nedospasov (@nedos)\nand Grazfather (@Grazfather)\n---\nusage: ./glitcher.py [-h] [--start_offset START_OFFSET] [--end_offset END_OFFSET] [--start_duration START_DURATION] [--end_duration END_DURATION] [--offset_step OFFSET_STEP] [--duration_step DURATION_STEP] [--retries RETRIES]\n \noptional arguments:\n  -h, --help            show this help message and exit\n  --start_offset START_OFFSET\n                        start offset for glitch (default is 100)\n  --end_offset END_OFFSET\n                        end offset for glitch (default is 10000)\n  --start_duration START_DURATION\n                        start duration for glitch (default is 1)\n  --end_duration END_DURATION\n                        end duration for glitch (default is 30)\n  --offset_step OFFSET_STEP\n                        offset step (default is 1)\n  --duration_step DURATION_STEP\n                        duration step (default is 1)\n  --retries RETRIES     number of retries per configuration (default is 2)\n```\n\nThe configuration of a voltage glitching attack can be changed via different command line arguments, for example:\n```\npython ice-glitcher.py --start_offset 5400 --end_offset 5430 --start_duration 10 --end_duration 25 --retries 3\n```\n\n## Demo\n\nThis demo video exemplarily shows how the code read protection (CRP) of an [NXP LPC1343 chip](https://www.nxp.com/docs/en/user-guide/UM10375.pdf) can be bypassed by using a voltage glitching attack in order to dump the flash memory containing the firmware.\n\nIn this proof-of-concept video, the [iCEstick Glitcher](https://github.com/SySS-Research/icestick-glitcher) was used, which works in the same way as the iCEBreaker glitcher.\n\n[![SySS PoC Video: Voltage Glitching Attack using SySS iCEstick Glitcher](/images/icestick_glitcher_poc_video.jpg)](https://www.youtube.com/watch?v=FVUhVewFmxw \"Voltage Glitching Attack using SySS iCEstick Glitcher\")\n\n## References\n\n- [iCEBreaker FPGA Board](https://www.crowdsupply.com/1bitsquared/icebreaker-fpga)\n- [Breaking Code Read Protection on the NXP LPC-family Microcontrollers](https://recon.cx/2017/brussels/resources/slides/RECON-BRX-2017-Breaking_CRP_on_NXP_LPC_Microcontrollers_slides.pdf)\n- [Toothless Arty-Glitcher](https://github.com/toothlessco/arty-glitcher)\n- [NXP LPC1343 Bootloader Bypass (Part 1) - Communicating with the bootloader](https://toothless.co/blog/bootloader-bypass-part1/)\n- [NXP LPC1343 Bootloader Bypass (Part 2) - Dumping firmware with Python and building the logic for the glitcher](https://toothless.co/blog/bootloader-bypass-part2/)\n- [NXP LPC1343 Bootloader Bypass (Part 3) - Putting it all together](https://toothless.co/blog/bootloader-bypass-part3/)\n- [Grazfather's glitcher for the iCEBreaker FPGA board](https://github.com/Grazfather/glitcher)\n- [Glitching the Olimex LPC-P1343](http://grazfather.github.io/re/pwn/electronics/fpga/2019/12/08/Glitcher.html)\n\n## Disclaimer\n\nUse at your own risk. Do not use without full consent of everyone involved.\nFor educational purposes only.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsyss-research%2Ficebreaker-glitcher","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fsyss-research%2Ficebreaker-glitcher","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsyss-research%2Ficebreaker-glitcher/lists"}