- Sources: primary, discussion
- Summary: Ledger Donjon located the DEBUGEN bit sites with differential photon-emission microscopy, then set PROC1 and PROC1_SECURE with laser pulses at two positions a few micrometres apart on a revision A4 part with glitch detectors at maximum sensitivity, restoring Secure debug. The permanent debug-disable flag sits in OTP with three-of-eight and majority-vote redundancy, but the memory-mapped DEBUGEN register that can override it has no documented redundancy, parity or vote, DEBUGEN_LOCK did not prevent the fault, and a pulse could set a lock bit so firmware could not restore the disabled value. Separately, an RP-AP rescue reset halts the chip in boot-ROM wait paths before firmware applies its runtime OTP page lock, which let the researchers read the full challenge secret.
- Why it matters: The attack needs destructive backside decapsulation, physical access and roughly $250,000 of equipment, so the result is a design lesson about the whole enforcement path rather than a remote risk to shipped parts.
- Follow-up: Track a Raspberry Pi response to the 2026-07-28 disclosure.
send feedback on this story