Skip to content
safemode.space
All incidents
2022-08-10 (approximate)
firmware exploitation
user

Starlink user-terminal voltage fault-injection (Wouters, 2022)

Confidence in this reading:
high

What happened

At Black Hat USA 2022 on 10 August 2022, Lennert Wouters of KU Leuven presented a black-box security evaluation of the SpaceX Starlink user terminal. He built a custom modchip from a Raspberry Pi microcontroller, flash storage, electronic switches and a voltage regulator, costing roughly 25 US dollars, and attached it to the terminal's printed circuit board. The modchip performs a voltage fault-injection attack that glitches the ROM bootloader at the point where it verifies the firmware signature, causing the check to pass and permitting execution of unsigned code on the terminal. Because the glitch is re-run at each boot, control persists. Wouters disclosed the finding to SpaceX before publication and was placed in the company's bug bounty hall of fame. SpaceX published a six-page response describing how it secures the system and shipped a firmware update which, on Wouters' assessment, makes the attack harder but not impossible. Wouters published the modchip design.

Authorised research with a disclosure path and a vendor response, not an adversary operation. The finding's weight is not that a terminal can be broken given unlimited physical access, which is true of most consumer hardware, but that the cost is about 25 US dollars and the result is unsigned code running on a device the operator's network authenticates. That is the user-segment trust boundary, and it is why the record maps IA-0009.03 even though no onward movement into the SpaceX network was demonstrated or claimed. SpaceX's own assessment of its firmware fix, as reported, is that the attack becomes harder rather than impossible, so the finding is not closed.

Attack vector

Physical attachment of a custom modchip to the user terminal PCB, performing voltage fault injection against the ROM bootloader's firmware signature check to permit execution of unsigned code, re-applied at each boot for persistence.

Operational impact

None. Authorised security research, disclosed to SpaceX before publication. No Starlink service was affected and no data taken.

Affected segments

user

Disclosed

2022-08-10

SPARTA techniques evidenced

Each row is a technique this record evidences, with the reasoning and the source that attests to it.

What relationship, confidence, and evidence mean on the rows below
Relationship

What kind of link this is between the technique and the target.

Mitigates: the target actively prevents, detects, or recovers from the technique.

Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.

Triggers obligation: the technique occurring is what triggers the duty the target imposes.

Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.

Confidence

How strongly the source supports this mapping, not how severe the technique is.

High: the source supports the mapping squarely.

Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.

Low: the source reaches the technique only in part.

Evidence

How close to the source text the mapping was made.

Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.

Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.

Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.

Considered and not mapped

These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.

Sources

The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.

A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.

Every source SafeMode Space reproduces, and on what terms: sources and attribution.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.