Uploaded April 2026 | Updated September 2026, 3 weeks ago
The firmware and secrets in automotive processors (such as in ECUs & co) are often protected using a variety of hardware security and safety features, such as read-out protection & co. One such feature is lockstep: Each instruction is basically executed twice, which is commonly interpreted as a mitigation against hardware attacks such as fault-injection. But how effective is it really?
In this talk, we will look at glitching different lockstep processors using different fancy hardware hacking methods, and also demonstrate vulnerabilities allowing us to fully bypass the protection on certain processors - breaking their read-out protection and letting us read-out firmware & secrets!
By:
Thomas 'stacksmashing' Roth | Founder, hextree.io
Full Session Details Available At:
blackhat.com/us-25/briefings/schedule/?#watch-your-lockstep-glitching-into-automotive-processors-46637
The firmware and secrets in automotive processors (such as in ECUs & co) are often protected using a variety of hardware security and safety features, such as read-out protection & co. One such feature is lockstep: Each instruction is basically executed twice, which is commonly interpreted as a mitigation against hardware attacks such as fault-injection. But how effective is it really?
In this talk, we will look at glitching different lockstep processors using different fancy hardware hacking methods, and also demonstrate vulnerabilities allowing us to fully bypass the protection on certain processors - breaking their read-out protection and letting us read-out firmware & secrets!
By:
Thomas 'stacksmashing' Roth | Founder, hextree.io
Full Session Details Available At:
blackhat.com/us-25/briefings/schedule/?#watch-your-lockstep-glitching-into-automotive-processors-46637








