Security researcher Markus "Doom" Gaasedelen demonstrated the first full compromise of the Xbox One using a new attack dubbed Bliss, ending the console's long-standing reputation as effectively unhackable. The technique uses voltage glitch hacking (VGH) rather than the older reset-pin approach seen in the Xbox 360's Reset Glitch Hack, and reportedly relies on two precisely timed glitches: one to bypass ARM memory protection setup and another to hijack a memcpy operation during header parsing, redirecting execution to attacker-controlled code.
Because the attack targets the boot ROM burned into silicon, the weakness is not patchable through software or firmware updates, leaving all manufactured Xbox One systems theoretically exposed. The reported impact is full execution of unsigned code at every privilege level, including access to the hypervisor and operating system, with potential implications for firmware and game decryption, modding, and emulation research. Both reports attribute the disclosure to Gaasedelen's presentation at RE//verse 2026 and frame it as the Xbox One's equivalent of the Xbox 360's fall to hardware glitching.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Gaasedelen said the exploit targets the Xbox One boot ROM in silicon, making it effectively unpatchable by Microsoft and affecting Xbox One consoles permanently. The disclosed impact includes unsigned code execution at all privilege levels, including the hypervisor and operating system, plus access enabling decryption of games and firmware.
At the RE//verse 2026 conference, security researcher Markus "Doom" Gaasedelen revealed 'Bliss,' a hardware exploit that achieves a full compromise of the Xbox One. The attack uses a double voltage glitch against the boot process to bypass protections and redirect execution to attacker-controlled data.
Microsoft released the Xbox One in 2013, and the console was widely regarded as highly resistant to hacking for years afterward. The platform's security reputation set the context for later research into a full compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
boingboing.net
Open sourcetomshardware.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.