Original Xbox One Console Successfully Hacked at Security Conference


At the RE//verse 2026 security conference, security researcher Marcus Gasserdalen demonstrated a successful hardware-based attack on the original Xbox One console. The presentation detailed a physical hacking method that bypasses the console’s security protections through precise voltage manipulation during system boot. Unlike software vulnerabilities that can be patched remotely, this attack requires direct physical access to the device’s motherboard. The demonstration highlights ongoing security challenges for legacy gaming hardware, even years after its initial release.
The hacking technique differs from typical software exploits by requiring physical intervention on the console’s motherboard. Researchers discovered that precise voltage interference at specific moments during the system boot process can bypass security protections. This attack targets the console’s fundamental hardware security architecture rather than exploiting software flaws. The method involves carefully timed electrical manipulation that disrupts normal boot procedures, allowing unauthorized access to the system’s core functions.

The attack specifically targets the console’s built-in 64KB bootrom memory, which serves as the root of trust for the entire security architecture. Through two precise voltage fault injections, Gasserdalen successfully bypassed memory protection mechanisms and gained code execution control. This bootrom vulnerability represents a fundamental security weakness since it exists in hardware that cannot be updated through software patches. The demonstration showed how attackers could potentially run unauthorized code on the compromised console.

This hardware-based attack demonstrates that even older gaming consoles remain vulnerable to sophisticated physical attacks. While requiring physical access limits its practical threat compared to remote software exploits, it raises questions about long-term hardware security design. The original Xbox One launched in 2013, and this vulnerability highlights how security researchers continue to find new attack vectors years after a product’s release. For collectors and users of legacy hardware, this serves as a reminder that physical security remains important alongside software updates.