Skip to content
Products/FaultyCat
Hardware Fault Injection CC BY-SA 3.0 (remix of ChipSHOUTER PicoEMP)

FaultyCat

Glitch past secure boot, for $120

A low-cost evaluation device for security testing in embedded systems: electromagnetic fault injection, voltage glitching and SWD/JTAG pin detection. A KiCad remix of the ChipSHOUTER PicoEMP.

Currently out of stock on the store. Check the link for restock dates.

Overview

FaultyCat is an evaluation device designed for security testing in embedded systems. It integrates advanced capabilities for vulnerability exploitation through Electromagnetic Fault Injection (EMFI), glitching techniques on critical signals, and analysis of undocumented debugging interfaces such as SWD and JTAG.

It is a low-cost EMFI tool designed specifically for self-study and hobbyist research. FaultyCat is a remix of the ChipSHOUTER PicoEMP project. Electronic Cats ported it to KiCad and integrated the RP2040 directly into the design instead of using a Raspberry Pi Pico board.

Firmware v3 is a from-scratch rewrite for the v2.x hardware that ships two fault-injection engines (EMFI and Crowbar voltage glitching) and two operational modes (Direct single-shot and Campaign parameter sweeps).

Highlights

  • Electromagnetic Fault Injection (EMFI) for authentication bypass & key extraction
  • Integrated glitcher for precise voltage / reset manipulation
  • Automatic SWD / JTAG debug-pin detection
  • Trigger pins + voltage reference for accurate, repeatable glitches
  • Analog input to monitor target status during glitching