Starlink user-terminal voltage fault-injection (Wouters, 2022)
What happened
At Black Hat USA 2022 on 10 August 2022, Lennert Wouters of KU Leuven presented a black-box security evaluation of the SpaceX Starlink user terminal. He built a custom modchip from a Raspberry Pi microcontroller, flash storage, electronic switches and a voltage regulator, costing roughly 25 US dollars, and attached it to the terminal's printed circuit board. The modchip performs a voltage fault-injection attack that glitches the ROM bootloader at the point where it verifies the firmware signature, causing the check to pass and permitting execution of unsigned code on the terminal. Because the glitch is re-run at each boot, control persists. Wouters disclosed the finding to SpaceX before publication and was placed in the company's bug bounty hall of fame. SpaceX published a six-page response describing how it secures the system and shipped a firmware update which, on Wouters' assessment, makes the attack harder but not impossible. Wouters published the modchip design.
Authorised research with a disclosure path and a vendor response, not an adversary operation. The finding's weight is not that a terminal can be broken given unlimited physical access, which is true of most consumer hardware, but that the cost is about 25 US dollars and the result is unsigned code running on a device the operator's network authenticates. That is the user-segment trust boundary, and it is why the record maps IA-0009.03 even though no onward movement into the SpaceX network was demonstrated or claimed. SpaceX's own assessment of its firmware fix, as reported, is that the attack becomes harder rather than impossible, so the finding is not closed.
Attack vector
Physical attachment of a custom modchip to the user terminal PCB, performing voltage fault injection against the ROM bootloader's firmware signature check to permit execution of unsigned code, re-applied at each boot for persistence.
Operational impact
None. Authorised security research, disclosed to SpaceX before publication. No Starlink service was affected and no data taken.
Affected segments
user
Disclosed
2022-08-10
SPARTA techniques evidenced
Each row is a technique this record evidences, with the reasoning and the source that attests to it.
What relationship, confidence, and evidence mean on the rows below
- Relationship
What kind of link this is between the technique and the target.
Mitigates: the target actively prevents, detects, or recovers from the technique.
Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.
Triggers obligation: the technique occurring is what triggers the duty the target imposes.
Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.
- Confidence
How strongly the source supports this mapping, not how severe the technique is.
High: the source supports the mapping squarely.
Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.
Low: the source reaches the technique only in part.
- Evidence
How close to the source text the mapping was made.
Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.
Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.
Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.
EX-0005's own description names MCU/SoC boot ROM fallbacks and the leveraging of physical phenomena and timing to induce faults as its subject. That is a literal description of what was done: a voltage glitch, timed against the ROM bootloader's signature check, steering behaviour beneath the software stack. Raised from the existing row's moderate because the technique's text and the researcher's method coincide term for term.
The attack exploits an inherent property of the hardware and logic design, the bootloader's lack of glitch resistance at the signature-check branch, rather than injecting new code, which is EX-0005.01's distinguishing clause. Confidence is moderate rather than high because no source characterises the susceptibility as a documented erratum or an acknowledged defect.
The modchip seizes control in the pre-OS boot chain before the integrity check completes and thereby shapes what the system subsequently trusts, which is EX-0010.04's definition. The edge is derived rather than direct because Wouters does not use the term and the mechanism is an attached device re-running a glitch rather than resident code in the boot chain.
IA-0009.03 covers end users and their equipment interacting with mission services, where a compromised user domain becomes a springboard into the mission core. The Starlink terminal is exactly that class of device and it is authenticated by the operator's network. The edge is derived because what was demonstrated is control of the terminal; no source claims onward movement into SpaceX's network was attempted or achieved.
The modchip is added hardware providing durable, low-visibility re-entry that survives resets, which is PER-0002.01's subject. It differs from the technique's central examples in being installed by the attacker after delivery rather than being present in the shipped design, so the edge is derived from the persistence property rather than from the insertion route the technique usually describes.
Considered and not mapped
These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.
The modchip is installed by someone who already has the device, not inserted before delivery.
Also in the bibliography here. IA-0002's subject is the radio's own pipeline: waveforms, bitstreams, DSP coefficients, calibration tables, update channels. The attack targets the SoC boot chain, and no source describes anything being done to the radio as a radio.
Also in the bibliography here. Nothing was stolen. This is disclosed research with a bug bounty.
In SPARTA's bibliography against the Wired article on this research, and a category error. RD-0001.01 is about assembling one's own RF ground stack, steerable mounts, band-appropriate apertures, TT&C baseband, to reach a spacecraft. Wouters bought a consumer user terminal.
Wouters performed extensive board-level and firmware analysis, but REC-0008's scope is mapping the manufacturing and build pipeline, component lots, screening levels, signing services, promotion policies, in order to prepare pre-delivery manipulation. Black-box analysis of a purchased device is not that. Its sibling
REC-0008.02is rejected on the same ground, which is the parent's scope.Wouters performed extensive board-level and firmware analysis, but REC-0008's scope is mapping the manufacturing and build pipeline, component lots, screening levels, signing services, promotion policies, in order to prepare pre-delivery manipulation. Black-box analysis of a purchased device is not that. Its sibling
REC-0008.01is rejected on the same ground, which is the parent's scope.
Sources
The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.
A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.
- Glitched on Earth by Humans: A Black-Box Security Evaluation of the SpaceX Starlink User TerminalConference paper
Tier 2: First-party material from the researcher who performed the work, presented at a reviewed industry conference. Authoritative on method and result; not peer-reviewed.
Tier 2: Named technology reporting with direct comment from the researcher and from SpaceX. Carries material the primary slide deck does not, namely the vendor response.
Tier 3: Technology trade press reporting a conference briefing. Corroborates the primary; adds no independent measurement.
Every source SafeMode Space reproduces, and on what terms: sources and attribution.