Independent researchers published detailed reverse-engineering of SpaceX Starlink user terminals, showing that the devices’ firmware, boot chain, and runtime services can be closely inspected through hardware teardown, eMMC extraction, and emulation. Analyses of v2, v3, and Standard Actuated Rev3/GenV2 terminals found large portions of firmware left unencrypted, documented custom integrity controls including ECC and sxverity, and mapped a Linux-based architecture in which user-space C++ networking components handle much of the terminal logic. Researchers also identified an STSAFE-A110 security chip used for device identity and key operations, observed telemetry-related Ethernet recording components, and reported that one terminal initialized 41 SSH public keys while leaving port 22 open on the local network.
Separate work demonstrated that Starlink secure boot could be bypassed in a lab by voltage fault injection against the BL1 stage on the custom ARM SoC, yielding root-level access despite secure-boot protections. Researchers built QEMU-based environments to debug services such as httpd, WebSocket, and gRPC, examined the internal user_terminal_frontend interface, and found an unauthenticated SoftwareUpdateRequest on the internal network that could start the update flow, although fuzzing did not uncover a practical remote exploit path. Black-box testing also triggered out-of-memory crashes in the Go-based frontend through malformed localhost-bound IPC traffic, while SpaceX reportedly reproduced the fault-injection proof of concept and mitigated part of it by disabling UART output via eFuse.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
In its March 2025 publication, DARKNAVY reported building a basic QEMU-based emulation environment for the Rev3 firmware. Within emulation, the team successfully ran and debugged components including httpd, WebSocket, and gRPC services.
On 26 March 2025, DARKNAVY published a preliminary analysis of the Starlink Standard Actuated Rev3/GenV2 user terminal antenna. The researchers disassembled the hardware, extracted firmware from the eMMC chip, and reported that much of the firmware was unencrypted, exposing the boot chain, kernel, filesystem components, and runtime layout.
The Quarkslab research found that the user_terminal_frontend process exposed an unauthenticated SoftwareUpdateRequest on the internal network. The request could trigger the software update flow, with sxverity becoming the first component to parse the supplied update bundle.
On 29 August 2023, Carlo Ramponi published a detailed reverse-engineering analysis of Starlink User Terminal v2 and v3 firmware. The study documented the boot chain, custom integrity mechanisms, runtime internals, Slate Sharing IPC, and QEMU-based emulation of the device environment.
At Black Hat USA 2022, Lennert Wouters presented a lab attack showing that voltage fault injection against the BL1 boot stage could bypass secure boot on the SpaceX Starlink user terminal and yield root-level researcher access. The presentation also described eMMC extraction, boot-chain analysis, and a custom modchip approach.
After SpaceX's UART mitigation, the researcher refined the attack approach and regained access to the Starlink terminal. The updated method triggered on eMMC D0 rather than UART activity.
Following the fault-injection research, SpaceX deployed a mitigation that blew a previously unused eFuse to disable UART output on the terminal. This removed the UART-based trigger path and forced the researcher to adapt the attack to monitor eMMC activity instead.
After the Black Hat research, SpaceX PSIRT reproduced the demonstrated proof-of-concept attack against the Starlink terminal. This confirmed the feasibility of the hardware fault-injection technique under lab conditions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
darknavy.org
Open sourceblog.quarkslab.com
Open sourcei.blackhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.