AUTO-UPDATED

Spoofed Serial Number Unlocks Cricut Machine

A hardware hacker known as xssfox successfully bypassed the deactivation lock on a discarded Cricut Maker by intercepting and spoofing USB communications between the device and its software.

Key Points

  • The researcher salvaged a discarded Cricut Maker and repaired its damaged rollers to restore physical functionality.
  • The device was initially unusable because Cricut’s software marked the machine as deactivated, likely following a warranty replacement.
  • Analysis revealed that the machine transmits its serial number to the host computer via USB without encryption or checksums.
  • By installing an RP2040 microcontroller as a man-in-the-middle device, the hacker successfully spoofed the serial number to unlock the machine.
  • The project demonstrates that a software-only bypass may also be possible for future users looking to reactivate locked hardware.

Why it Matters

This project highlights significant security vulnerabilities in proprietary hardware that relies on cloud-based deactivation to control device lifecycles. It raises broader questions about the right to repair and the ability of manufacturers to remotely disable consumer electronics after they have been discarded or sold.
Hackaday Published by Zoe Skyforest
Read original