Xbox One boot ROM exploit shown at RE//verse 2026, Gaasedelen says work is about preservation, not piracy

Security researcher Markus Gaasedelen used his RE//verse 2026 talk to present a boot ROM-level exploit for the original Xbox One, a result that matters partly because the console had long been treated as the generation that never received a public piracy-enabling break. During the demo, Gaasedelen said the attack gives access to patch, decrypt, and boot code “from the boot ROM down,” placing it below the normal firmware chain.
Source: Re//verse
Microsoft openly highlighted Xbox One’s resistance to physical attacks years ago. In Tony Chen’s 2019 Platform Security Summit session, Microsoft said the Xbox One and PS4 had been on the market for close to six years without being cracked to enable piracy, calling it the first time consoles had lasted that long. Gaasedelen’s own talk makes clear why it took so long, describing a design packed with compartmentalization, hardened boot logic, and multiple anti-fault measures. And yes, he used AI for some of the tools to break the code, but it’s not clear if Microsoft Copilot was of any help.
Source: Re//verse
The attack itself is not a software mod or an easy end-user hack. Gaasedelen said the exploit uses two voltage glitches against the Xbox One’s platform security processor boot ROM, first bypassing MPU setup and then hijacking execution during a later header read, which opens the door to supervisor-level control. He also said the current result applies to the 2013 Xbox One “fat,” while Xbox One S, Xbox One X, and Xbox Series systems were not claimed as compromised in the presentation.
Source: Re//verse
This also did not appear out of nowhere. Gaasedelen has been publishing Xbox-related security work for years, including a 2023 RET2 Systems post on dumping the original Xbox boot ROM through Intel CPU JTAG, and RE//verse 2025 previously hosted his talk on full-stack reverse engineering of the original Microsoft Xbox.
Near the end of the talk, he said, “I haven’t played games in years,” and added that he did not come back to hack the Xbox One to “pirate a few games.” Instead, he explained the work around preservation and repairability, and said he would be curious to see whether others can replicate the research and do something useful with it.
Piracy aside, unlocking older hardware gives users a choice to install 3rd party software, including new operating system. If Microsoft ever gave a way to run full operating systems for otherwise locked hardware for gaming, this probably wouldn’t be so significant.
Source via Tom’s Hardware