Xbox one’s ‘unhackable’ fortress falls to two nanosecond-perfect voltage stabs
Markus Gaasedelen calls it Bliss. Microsoft once called Xbox One the most secure consumer device it had ever built. On Friday, at RE//verse 2026, both statements collided when Gaasedelen showed a palm-sized glitching rig injecting unsigned code into a launch-day console in 34 seconds. The steel curtain that dropped in 2013 now has a tear no patch can sew.
The trapdoor is in the power rail, not the firmware
Previous Xbox 360 exploits abused race conditions in the reset line. Redmond welded that shut with a custom ARM Cortex block that verifies every boot micro-second. Gaasedelen simply moved upstream. By drooping the CPU voltage 320 mV for 8.3 ns while the security coproster configures memory protections, he forces a mis-fetch. A second droop, 11 ns later, diverts the DMA engine into attacker-controlled RAM. Two pulses, two dollars in capacitors, total pwnage.
The demo looks low-tech: a hobby PCB taped to the heat spreader, a Li-Po cell, and a Python script. Under the hood, a 4 GS/s scope synchronizes the injections to the exact clock tick. Microsoft can’t retro-fix it; the boot ROM is baked into the SoC. Every Xbox One ever shipped is now a homebrew sandbox waiting to happen.

What it unlocks and why it still matters
With the Secure Processor sidelined, pirates can decrypt disk images, tinkerers can swap the OS for Linux, and researchers can finally audit the 2013 hypervisor that still underpins Series X|S backward compatibility. Microsoft downplayed the reveal, noting that One sales are “statistically zero” in 2026. Yet the PR sting is real: the company paraded the console’s unbroken record for twelve straight years. That marketing cudgel is gone.
Gaasedelen hasn’t tested Series hardware, but the boot path is a direct descendant. If the same power-management IC sits on the newer boards, the Bliss recipe may already scale. Microsoft declined to confirm any silicon revisions, repeating only that “customers enjoying modern Xbox consoles benefit from additional hardware mitigations.” Translation: they’re hoping no one tries.
The exploit drops on GitHub next week, schematic and all. Expect a spike in second-hand Xbox One prices—homebrew crews pay a premium for hackable silicon. For everyone else, the takeaway is blunt: every secure boot chain is only as strong as its weakest millivolt.