Hacking Patched V1 Stuck in RCM & Won't Boot

zach__c

New Member
OP
Newbie
Joined
Feb 25, 2024
Messages
3
Trophies
0
Age
26
XP
31
Country
Canada
I have a bit of an odd situation here. I've successfully modded 7 consoles before this, but none of them were a V1 so far. I normally use the V6S chip which has worked great, but I had no V1 CPU flex cables on hand so I decided to try to modify the V2 flex to work (first mistake?). Here's what I came up with after some research:

V6S CPU Flex on V1.png



I soldered it to the top of the appropriate SP1/SP2 caps (and source points to the shield) and tested multiple times with a multimeter to make sure everything checked out before proceeding. I then did the rest of the mod as usual. After connecting everything, I got an error code flashing from the modchip indicating an issue with the CPU flex, and the console booted into OFW. I touched up the points on the caps a bit, re-seated the CPU flex connection to the chip, and booted again. The modchip LED then pulsed purple like it was trying to glitch but then blinked orange 3-4x quickly and kept doing this in a loop, which didn't match any of the LED codes I could find for the V6S.

After a while of waiting, I interrupted it by holding the power button (mistake #2?), disconnected the battery, disconnected all connections to the modchip and tried to boot to OFW. No sign of life, nothing on the display, etc. I removed the CPU flex completely, same issue. I removed everything else (emmc flex cable & modchip), same issue. Can't find any shorts on the board or anything.

The weird thing is, when I plug it into my computer, it gets recognized and even shows up as "RCM OK" in TegraRcmGUI. And of course if I try to inject a payload, I get the "Smashed the stack with a 0x0000 byte SETUP request!" message indicating it's patched. Every time I unplug the battery or hold power and restart the switch, it seems to get recognized by TegraRcmGUI as in RCM mode on boot. Does this mean the CPU is fine, or not necessarily?

I managed to get a NAND backup by putting the NAND in my V2 and dumping it with Hekate (I'm assuming this means the NAND is at least fine). If it's not possible to get the console working, I at least want to try to extract the game save data from the NAND dump for my friend so I can import them to my V2 switch and give it to him. Unfortunately, I can't decrypt the NAND via HacDiskMount unless I have the correct bis_key_3 which I'm unable to dump from the dead board :(

Lots of lessons learned for me on this one haha. My next move is I ordered some proper V1 CPU flex cables, and I'll use an RP2040 to see if I can at least dump the BIS keys.

Anyone have any other ideas? Any input at all is much appreciated!
 

zach__c

New Member
OP
Newbie
Joined
Feb 25, 2024
Messages
3
Trophies
0
Age
26
XP
31
Country
Canada
look on the picofly, and hwfly modchip threads to installation diagrams so you can learn de differences and the points to solder the Drain and source.
Hey thanks for the reply! I did actually do quite a bit of looking around beforehand and found that for the V1 the points are:

Drain => Top of the SP1/SP2 caps
Source => Ground
Gate => Modchip

I also found this image of the flex cable (along with an exposed version of the flex cable) on those threads which is what lead me to try this out:

v2 cpu flex on v1.png


Do you see any issues with this approach? The only thing I can think of is that the V2 has 2 mosfets instead of 1 like the V1 flex. Would that cause a problem?
 
  • Love
Reactions: impeeza

impeeza

¡Kabito!
Member
Joined
Apr 5, 2011
Messages
6,384
Trophies
3
Age
46
Location
At my chair.
XP
18,826
Country
Colombia
Hey thanks for the reply! I did actually do quite a bit of looking around beforehand and found that for the V1 the points are:

Drain => Top of the SP1/SP2 caps
Source => Ground
Gate => Modchip

I also found this image of the flex cable (along with an exposed version of the flex cable) on those threads which is what lead me to try this out:

View attachment 422308

Do you see any issues with this approach? The only thing I can think of is that the V2 has 2 mosfets instead of 1 like the V1 flex. Would that cause a problem?
You can solder thick wires to connect the caps and the flex.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • Veho @ Veho:
    Nah, a hit gives them mad meth powers, but makes them more difficult to control.
    +1
  • Veho @ Veho:
    Before a hit they're like zombies, persistent but slow.
    +1
  • Veho @ Veho:
    It's a tradeoff.
    +1
  • The Real Jdbye @ The Real Jdbye:
    no i mean, before a hit is after the previous hit
    +1
  • The Real Jdbye @ The Real Jdbye:
    if you keep them well enough fed, it's the same thing
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    By the power of Florida Man, I have the power!!! *Lifts up meth pipe* Meth Man!!! lol
  • BakerMan @ BakerMan:
    Guys, I just learned my little brother is in the hospital because he had a seizure last night.
  • cearp @ cearp:
    Sorry to hear that BakerMan
    +2
  • BakerMan @ BakerMan:
    Just found out he's doing alright, doing a lot of complaining too, rightfully so. Who wouldn't complain after having a seizure and being hospitalized?
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Glad he is OK and complaining is cool :)
    +1
  • K3Nv2 @ K3Nv2:
    Yeah been there had that no fun
    +1
  • K3Nv2 @ K3Nv2:
    They'll give him sleep studies eegs and possibly one week hospital stay
    +1
  • BakerMan @ BakerMan:
    I hope it's not a week.
  • K3Nv2 @ K3Nv2:
    It's standard so doctors can get a idea about what's going on
  • BakerMan @ BakerMan:
    understood
  • BakerMan @ BakerMan:
    well, i'm glad he seems to be doing fine, and ig i'm going to start spewing goofy shit again
  • BakerMan @ BakerMan:
    Update: Turns out he's epileptic
  • K3Nv2 @ K3Nv2:
    Get a 2nd opinion run mris etc they told me that also
  • Psionic Roshambo @ Psionic Roshambo:
    Also a food allergy study would be a good idea
  • K3Nv2 @ K3Nv2:
    Turns out you can't sprinkle methamphetamine on McDonald's French fries
    +1
  • ZeroT21 @ ZeroT21:
    they wouldn't be called french fries at that point
    +1
  • ZeroT21 @ ZeroT21:
    Probably just meth fries
    +1
  • K3Nv2 @ K3Nv2:
    White fries hold up
    +1
    K3Nv2 @ K3Nv2: White fries hold up +1