News
MARKET SIGNAL:

Defcon Badge Makes Open Security Chip Inspectable As Hardware Token

Newsroom brief

WIRED via Ars Technica reported that Defcon's 2026 badge uses Andrew Huang's Baochip-1x, a mostly open source microcontroller with a removable module that works as a hardware security token and exposes the silicon for infrared inspection.

Verified against source materialEdited by SendTech Times Cybersecurity DeskSource: WIRED via Ars Technica
Defcon Badge Makes Open Security Chip Inspectable As Hardware Token
Image source: WIRED via Ars Technica

A new Defcon conference badge is turning the event's collectible hardware into an inspection test for open security silicon, with WIRED via Ars Technica reporting that the removable core module can continue working after the conference as a hardware security token.

The badge was designed by hardware hacker Andrew Huang around Baochip-1x, a mostly open source microcontroller that has been in development for three years, according to WIRED via Ars Technica.

Public Baochip repositories expose the device software stack, processor implementation, crypto components and I/O design, giving researchers a reference design to compare against the shipped device.

Transparent Packaging Targets Supply Chain Trust

The security claim rests on inspection rather than only published code.

Baochip-1x is packaged so infrared light can pass through the back of the silicon, allowing researchers to look at internal structures and compare the physical chip with the public design files.

That packaging changes the usual trust model for hardware tokens.

Conventional chips and earlier open source silicon projects may publish specifications while still hiding the manufactured die inside opaque plastic, leaving buyers to trust that fabrication or packaging did not introduce an unexpected component.

The Defcon badge gives attendees a removable module that can be examined, carried away and reused.

Badge Distribution Becomes Field Testing

Defcon founder Jeff Moss backed the badge because the conference theme centers on agency, and WIRED via Ars Technica reported that the 27,000 badges represent Baochip's first major distribution.

The rollout moves the project from a small development release into the hands of a community that is likely to inspect, modify and attack it.

The module can act as a FIDO hardware security token and supports time-based one-time passwords and password management.

It also includes a low-resolution camera for QR-code enrollment, while the default software uses black-and-white data and avoids photo storage to fit Defcon's privacy rules.

Open Design Does Not Remove All Risk

Baochip-1x runs a Rust operating system, while The report listed secure boot, hardware attack resistance and a true random number source among the design features.

Huang also pointed to resistive RAM as a memory choice intended to make physical extraction harder than conventional flash storage.

proprietary low-level physical-design and manufacturing elements tied to TSMC's 22-nanometer process remain closed, and the project still depends on users trusting parts of the fabrication chain that cannot be published in the same way as software.

The report said Huang's estimate that attacks costing tens of thousands of dollars may be within the chip's defensive range, but a multimillion-dollar laboratory effort would probably break it.

The badge therefore becomes a public stress test for how much verifiable silicon can fit into a mass conference device.

The technical headroom leaves room for post-conference use beyond badge puzzles.

Baochip-1x uses a 350 MHz RISC-V processor, 2 megabytes of SRAM, 4 megabytes of RRAM and four 700 MHz PicoRV32 input-output cores, with MicroPython plus C and Rust development kits already available.

Defenders and hardware researchers now have a visible target for checking whether open inspection can improve authentication hardware without overstating what any chip can prove.

Share this article
inXf

Related articles

More
TONTOU CPU Attack Tests Spectre Defenses On Linux Systems
Cybersecurity

TONTOU CPU Attack Tests Spectre Defenses On Linux Systems

Researchers showed a Time-of-Neutralization to Time-of-Use technique that can repollute branch prediction state after Spectre v2 mitigations and leak Linux kernel data in lab tests.

Rails Fixes Critical Active Storage File-Read Vulnerability
Cybersecurity

Rails Fixes Critical Active Storage File-Read Vulnerability

BleepingComputer reported that Rails maintainers patched CVE-2026-66066, a critical Active Storage flaw tied to libvips image processing and possible file exposure in vulnerable applications.

China Opens Security Review Of Palo Alto Networks Products
Cybersecurity

China Opens Security Review Of Palo Alto Networks Products

China's cyberspace regulator opened a security review of Palo Alto Networks products, with no named product line, technical flaw or decision timetable disclosed.

G42 Joins Nvidia Open AI Alliance As Security Debate Widens
AI

G42 Joins Nvidia Open AI Alliance As Security Debate Widens

The National reported that Abu Dhabi's G42 has joined Nvidia's Open Secure AI Alliance, putting a Gulf AI company inside a 38-member push to defend open-weight models after the Hugging Face incident sharpened security scrutiny.

Hugging Face Says AI Agent Drove Production Infrastructure Intrusion
Cybersecurity

Hugging Face Says AI Agent Drove Production Infrastructure Intrusion

Hugging Face said an autonomous AI agent system drove an intrusion into part of its production infrastructure, reaching internal datasets and service credentials. The company said public models, datasets and Spaces were not tampered with, while its assessment of partner or customer data remains unfinished.

Malaysia AI Agency Launch Leaves Sovereign Cloud Question Unassigned
Capital & Policy

Malaysia AI Agency Launch Leaves Sovereign Cloud Question Unassigned

Tech Wire Asia reported that Prime Minister Anwar Ibrahim launched AI Malaysia while raising unresolved sovereign cloud, US CLOUD Act and cybersecurity questions around the country’s AI governance plan.

Keep Reading

More Stories

Latest
Hugging Face Hack Pushes AI Agents Into Cybersecurity SpotlightAIAug 8, 2026Hugging Face Hack Pushes AI Agents Into Cybersecurity SpotlightCNBC reported that Black Hat cybersecurity leaders treated the Hugging Face AI-agent breach as a turning point for governing autonomous cyber models rather than a one-off failure.Alibaba Tests Revenue Sharing For Commercial Qwen AI UseAIAug 8, 2026Alibaba Tests Revenue Sharing For Commercial Qwen AI UseAI News reported that Alibaba plans revenue-sharing terms for some commercial users of its next Qwen open-weight AI model, following a licensing pattern already used by Moonshot for Kimi K3.Meta Ordered To Fund $567M New Mexico Youth Mental Health PlanCapital & PolicyAug 8, 2026Meta Ordered To Fund $567M New Mexico Youth Mental Health PlanArs Technica reported that a New Mexico judge ordered Meta to provide $567 million for treatment, screening, awareness and prevention after finding that its platforms contributed to a public nuisance.Harvey Funding Talks Could Lift Legal AI Startup To $15.5B ValuationAIAug 8, 2026Harvey Funding Talks Could Lift Legal AI Startup To $15.5B ValuationSiliconANGLE reported that Harvey AI is seeking at least $500 million in new funding that could value the legal AI startup at $15.5 billion after annualized revenue passed $350 million.Vietnam Shows Shopee-TikTok Shop Race Tightening In Southeast AsiaScience & TechAug 7, 2026Vietnam Shows Shopee-TikTok Shop Race Tightening In Southeast AsiaTech Collective SEA wrote that Shopee’s Vietnam share fell from 61% to 53% between May 2025 and April 2026 as TikTok Shop rose from 33% to 44%, showing how social commerce is reshaping regional ecommerce infrastructure.AI Pioneers Split Over Risk As Compute Buildout AcceleratesAIAug 7, 2026AI Pioneers Split Over Risk As Compute Buildout AcceleratesData Center Knowledge reported that Geoffrey Hinton, Fei-Fei Li and Andrew Ng disagreed at Ai4 over AI risk, jobs, openness and regulation, leaving infrastructure investors to plan capacity amid unsettled deployment rules.SpaceX Asks FCC To Wind Down $4.5bn Rural Broadband SupportTelco & ConnectivityAug 7, 2026SpaceX Asks FCC To Wind Down $4.5bn Rural Broadband SupportLight Reading reported that SpaceX urged the FCC to sunset High-Cost rural broadband subsidies, while rural telecom and electric-cooperative groups said LEO satellite coverage cannot replace terrestrial network support.OpenAI Expands Free ChatGPT Access In GPT-5.6 RolloutAIAug 7, 2026OpenAI Expands Free ChatGPT Access In GPT-5.6 RolloutBleepingComputer reported that OpenAI is rolling out GPT-5.6 Sol for paid ChatGPT users and GPT-5.6 Luna for Free and Go users, pairing unlimited free text chats with a new reasoning control and additional safeguards for users believed to be under 18.JLL Data Centre Report Shows Middle East Pipeline Pause As FLAPD GrowsCapital & PolicyAug 7, 2026JLL Data Centre Report Shows Middle East Pipeline Pause As FLAPD GrowsData Center Dynamics reported that JLL's EMEA Mid-Year Data Centre Report 2026 put FLAPD live capacity at 3.8GW, while the Middle East had 2.6GW in development paused and 13.8GW in planning.AWS Adds Persistent Runtime Instances For Production AI AgentsCloud & Data CentersAug 7, 2026AWS Adds Persistent Runtime Instances For Production AI AgentsAWS announced runtime instances for Amazon Bedrock AgentCore Runtime, adding managed infrastructure for multi-agent workflows, shared sessions lasting up to 14 days and GPU-supported production agent deployments.AI Patch Study Keeps Humans In Vulnerability ReviewsCybersecurityAug 7, 2026AI Patch Study Keeps Humans In Vulnerability ReviewsThe Register reported that 1Password Off-by-1 Labs tested 6,080 AI-generated patches across six CVEs and found clean autonomous fixes in 26.0 percent of cases, leaving security teams with a supervision problem rather than a replacement for vulnerability review.DOJ Trade-Fraud Unit Raises Payment Compliance ExposureFintech & Digital PaymentsAug 7, 2026DOJ Trade-Fraud Unit Raises Payment Compliance ExposurePYMNTS reported that a new U.S. Justice Department trade-fraud section and more than $1 billion in recent task-force recoveries are pushing banks to compare payment flows with customs and supply-chain records.