logo

Researchers Revive 2000s ‘Blinkenlights’ Technique to Dump Smartwatch Firmware via Screen Pixels

ID: 5d722e52-cd7b-5d18-8016-1ecec94452ab

STIX ID: report--5d722e52-cd7b-5d18-8016-1ecec94452ab

Feed Name: cybersecurityNews.com

Threat Score
30/100

Date Published: 2025-12-12

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Quarkslab researchers adapted the two-decade-old “Blinkenlights” technique to extract firmware from a €12 smartwatch by exploiting a dial parser vulnerability (out-of-bounds read) in a JieLi AC6958C6-based device. They soldered connections to the NV3030B screen, used an overclocked Raspberry Pi Pico to sample the RGB565 pixel stream, and delivered malicious custom dials to force the watch to display arbitrary memory; captured data blocks were reassembled via Python scripts to reconstruct the firmware, demonstrating that legacy attack techniques remain effective against modern embedded devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.