September 29, 2026

Advanced Hardware Security Under Siege: Inside the Ledger Donjon Laser Fault Injection Attack on the Raspberry Pi RP2350 Microcontroller

advanced-hardware-security-under-siege-inside-the-ledger-donjon-laser-fault-injection-attack-on-the-raspberry-pi-rp2350-microcontroller

advanced-hardware-security-under-siege-inside-the-ledger-donjon-laser-fault-injection-attack-on-the-raspberry-pi-rp2350-microcontroller

Main Facts

The ongoing cat-and-mouse game between hardware security engineers and silicon manufacturers has yielded another fascinating chapter. Raspberry Pi has officially acknowledged a sophisticated security research disclosure from Ledger Donjon, the renowned security evaluation lab of hardware wallet manufacturer Ledger. The researchers successfully bypassed the robust security architectures of the RP2350 microcontroller—Raspberry Pi’s flagship secure chip launched in August 2024—using a high-end laser fault injection (LFI) technique.

The vulnerability, had it been submitted during the initial phases of Raspberry Pi’s structured bug-bounty initiatives, would have easily secured a top-tier prize. To achieve this breakthrough, the Ledger Donjon team deployed approximately $250,000 worth of specialized laboratory microscopy and infrared laser equipment. Their objective was clear: pierce the physical defenses of a secured RP2350-A4 chip, re-enable the locked-down debug interface, and read out sensitive One-Time Programmable (OTP) memory—a feat Raspberry Pi engineers had explicitly designed to be impossible.

Despite the elegance and severity of the attack, Raspberry Pi has confirmed that this specific discovery does not warrant a physical silicon respin. Unlike earlier vulnerabilities discovered shortly after the chip’s commercial debut, the current A4 stepping and its associated ecosystem remain robust enough against this vector to not necessitate a costly manufacturing overhaul. Meanwhile, the broader cryptographic and hardware security community continues to eye Raspberry Pi’s ongoing, highly publicized Hacking Challenges, with the second challenge focusing on side-channel analysis (SCA) hurtling toward its final weeks.


Chronology of Events

To understand the weight of Ledger Donjon’s discovery, one must trace the timeline of the RP2350’s security lifecycle, from its highly anticipated debut to the iterative hardening of its silicon architecture.

August 2024: The Launch and the Gauntlet

Raspberry Pi officially unveiled the RP2350, marking a massive leap forward for the company by introducing advanced security features, including Arm TrustZone, signed boot capabilities, and dedicated hardware cryptographic accelerators. Recognizing that no secure element is truly impenetrable without real-world stress testing, Raspberry Pi took an aggressive and transparent approach: they launched a public Hacking Challenge alongside the product launch. Hackers and security researchers worldwide were actively invited to find vulnerabilities, bypass the security measures, and claim substantial cash rewards.

Late 2024: The First Breakthroughs and Respins

The initial Hacking Challenge was an overwhelming success, yielding multiple valid security exploits. Most notably, an independent security researcher known in the community as Courk managed to use a homebuilt infrared laser setup to glitch the earlier A2 stepping of the RP2350. Courk’s methodology forced the chip into unexpected states, effectively bypassing security controls.

Everything is better with lasers

In response to these findings, Raspberry Pi did something rare for a low-cost microcontroller vendor: they took the findings seriously, redesigned parts of the chip, and respinned the silicon. This resulted in the updated A4 die revision, which incorporated boot ROM revisions specifically engineered to patch the laser fault injection vectors discovered by community researchers like Courk.

Early 2025: Ledger Donjon Enters the Lab

Even after the silicon respin to the A4 stepping, elite evaluation labs continued probing the silicon. The engineers at Ledger Donjon turned their high-powered optical benches toward the newly hardened RP2350-A4. Utilizing precision micro-machining, backside silicon preparation, and microscopic infrared targeting, the Donjon team systematically mapped the chip’s internal layout to identify vulnerable registers.

Mid 2026: Responsible Disclosure and Public Recognition

Ledger Donjon formally contacted Raspberry Pi with their comprehensive research findings. Following a professional and transparent responsible disclosure process, Ledger Donjon published their technical whitepaper detailing the laser fault injection methodology. Raspberry Pi formally evaluated the risk, concluded that the high barrier to entry (a quarter-million-dollar lab setup) mitigated widespread practical threats, and praised the Ledger team for their professionalism.


Supporting Data and Technical Breakdown

The attack executed by Ledger Donjon is a masterclass in modern hardware hacking, specifically combining Optical Fault Injection (OFI) with deep micro-architectural analysis.

The Physics of Laser Fault Injection

Integrated circuits are composed of millions of microscopic transistors switching state via electrical signals. When these transistors are struck by photons of a specific wavelength—typically in the near-infrared spectrum when attacking from the backside of silicon—the light energy generates localized electron-hole pairs. This phenomenon, known as a transient photoelectric effect, can temporarily alter the state of a specific flip-flop or register, causing a bit-flip without permanently damaging the physical silicon.

However, targeting a specific register on a modern, densely packed microcontroller is akin to hitting a moving target the size of a pinhead from across a football field, while the target is operating at hundreds of megahertz.

Everything is better with lasers

The Ledger Donjon Methodology

To overcome these physical hurdles, the Ledger Donjon team utilized:

  1. Backside Silicon Preparation: Modern microchips have metal routing layers on the top surface that block light. To bypass this, researchers ground down the silicon substrate from the backside, creating a transparent window through which lasers can directly hit the active transistor gates.
  2. High-Precision Microscopy: Using advanced optical systems, they mapped the physical layout of the RP2350-A4 to locate the exact bus structures and registers responsible for access control and debug authentication.
  3. Timed Photon Emission: Using a tightly focused infrared laser pulse synchronized precisely with the chip’s internal clock cycles, they induced a fault at the exact microsecond the security check for the debug interface was evaluated.

When successful, this laser "glitch" tricked the RP2350 into skipping its security authorization routine, re-enabling the Arm CoreSight debug interface and permitting the reading of protected One-Time Programmable (OTP) memory fuses.

Comparison with Courk’s Homebrew Attack

It is worth noting the engineering delta between Courk’s earlier community exploit and Ledger Donjon’s enterprise-grade attack:

  • Courk (Hacking Challenge 1): Utilized a resourceful, lower-cost, homebrew IR laser setup against the vulnerable A2 stepping. The vulnerability was primarily software/ROM-logic based, which allowed Raspberry Pi to patch it via a boot ROM update integrated into the subsequent A4 die.
  • Ledger Donjon: Utilized $250,000+ in professional laboratory equipment (advanced optical benches, high-precision galvo mirrors, and specialized microscopy) to defeat the hardened A4 stepping. This attack exploits the fundamental physical properties of silicon under photon bombardment rather than a simple logic flaw in the boot ROM.

Official Responses and Industry Implications

When a security vulnerability of this magnitude is disclosed, the immediate question from developers, industrial designers, and hobbyists alike is: How secure is my hardware? Both Raspberry Pi and Ledger Donjon have provided transparent technical assessments.

Raspberry Pi’s Security Calculus

Raspberry Pi’s decision not to respin the RP2350 chip a second time comes down to a fundamental concept in cybersecurity: threat modeling and cost-to-attack ratios.

Security is never absolute; it is about economics. If a successful attack requires a specialized laboratory, a $250,000 microscope/laser apparatus, deep domain expertise, and physical access to the device’s naked silicon die (having stripped away packaging and polished the backside of the silicon), the vulnerability is largely irrelevant to remote attackers or casual bad actors. It does not threaten mass-market IoT deployments, consumer electronics, or standard embedded projects where physical lab-grade invasive attacks are economically unviable.

Everything is better with lasers

For high-security applications requiring absolute physical tamper resistance, systems engineers understand that invasive microprobing and laser fault injection can defeat almost any commercially available general-purpose microcontroller. Against such threats, multi-layered architectures, hardware tamper meshes, or specialized secure elements are required.

Ledger Donjon’s Perspective

For Ledger Donjon, publishing this research serves a dual purpose: advancing the collective understanding of semiconductor physics and demonstrating the rigorous evaluation standards applied to modern hardware components. By testing microcontrollers like the RP2350—which bridges the gap between low-cost hobbyist boards and industrial silicon—Ledger helps raise the security baseline for the entire embedded systems industry.


What’s Next? The Ongoing Battle

While the first Hacking Challenge concluded with vital lessons and silicon improvements, the war for RP2350 security is far from over.

Raspberry Pi’s Second Hacking Challenge has been running for an extended period, shifting the battlefield from optical and voltage glitching to Side-Channel Analysis (SCA). Unlike active fault injection—which forces a chip to misbehave—SCA is a passive attack technique. It involves monitoring the power consumption, electromagnetic emissions, or acoustic output of the RP2350 while it performs cryptographic operations, attempting to mathematically deduce secret keys without ever opening the package.

Despite multiple deadline extensions, the second challenge remains unbeaten as of this writing. However, rumor and community updates suggest that several elite security research teams are inching dangerously close to a breakthrough. With the challenge window closing at the end of next month, the Raspberry Pi engineering community is bracing itself for the next major disclosure.

The transparency with which Raspberry Pi handles these vulnerabilities sets a gold standard for the semiconductor industry. Rather than sweeping physical security flaws under the rug, embracing ethical hackers, evaluation labs like Ledger Donjon, and open community challenges ensures that the RP2350 evolves into one of the most thoroughly tested and hardened microcontrollers in its class.