Hack.lu 2026

Voltage Glitching Basics with the Pico Glitcher

In the present era, where embedded systems are increasingly deployed in security-critical environments, securing microcontrollers against physical attacks is important. This training course provides an introduction to fault-injection techniques, with a particular emphasis on voltage glitching as a method for attacking protected microcontrollers. In a hands-on session, participants will acquire practical experience in how hardware vulnerabilities can be exploited by fault-injection techniques.


The course "Voltage Glitching Basics with the Pico Glitcher" gives a practical introduction to fault injection, focusing on how voltage glitching can be used to attack protected microcontrollers. It starts with the fundamentals of power and voltage glitching, showing how short voltage disturbances can disrupt a device's normal operation.

Participants will program microcontrollers and look at how code protection mechanisms actually work. This includes the proprietary Read-Out Protection (RDP) feature from STMicroelectronics and how it prevents unauthorized access to firmware. The hands-on exercises use the Pico Glitcher along with the open-source "findus" Python library. Participants will also learn the basics how to analyze signals using logic analyzers and oscilloscopes.

In the final part, participants will attack a protected STM8 device and extract its firmware using the Pico Glitcher and findus. Methods and techniques to protect microcontrollers against fault-injection attacks are discussed.

Note to participants: Please bring your own laptop with a native Linux or macOS installation. A Linux virtual machine should also work, but a native installation is recommended.

Dr. Matthias Kesenheimer

Matthias Kesenheimer is an experienced IT security professional with a passion for hardware hacking. As a senior IT security consultant and penetration tester for the German pentest company SySS GmbH, he specializes in the practical exploitation of vulnerabilities and advises clients on how to eliminate them. He also regularly conducts security research and has a keen interest in fault injection and voltage glitching attacks.