Coldforest: New Xbox One Modchip Based on Bliss Exploit Revealed

5 augusti 2026Källa:Se7ensins

A new modchip named Coldforest, intended for the Xbox One, has received a comprehensive technical review on the forum se7ensins. User Venator38 presents details about the chip's development, which is based on the so-called Bliss exploit. Coldforest promises root access to the console's System-on-Chip (SoC), opening the door for in-depth manipulation of security features and the system's core.

The chip is described as a dual-MCU system. A primary MCU handles eMMC flashing, bypassing SoC security, and injecting code developed through reverse engineering of the SoC's ROM data. This MCU communicates with the SoC via GPIO. A secondary MCU manages remote control, over-the-air (OTA) updates of firmware and NAND, and remote access to an interactive SoC terminal. An SPI interface also enables the connection of a touchscreen. The NAND memory can be read and written over WiFi via a high-speed interface.

Coldforest utilizes a firmware architecture that supports multiple operating modes and provides access to a real-time virtual console for the Xbox One SoC. This is intended to facilitate the development of new firmware and software. The foundation is XOCore, a modified version of coreboot for the Xbox One SoC, which initializes the CPU and RAM before establishing communication via GPIO. XOCore also enables decryption of keys, firmware modification, and bypassing of security systems, based on leaked source code.

The developer states that the system, which is intended to be fully open-source, will in the future be able to bypass side-channel monitoring for specific SoC models via a firmware update. The goal is to enable easy installation of Linux and custom Xbox One firmware. Development is being conducted in secrecy, and there is no public repository for code or files yet. Some functionality is verified, while the rest is still being tested. All technical data and source code will be made available to the community without any usage restrictions, but the development environments for firmware and software will not be shared.

The developer is aware that Microsoft may become interested in the project, but emphasizes that the identity is anonymous and the technology is designed to be untraceable. No sales of pre-made kits will occur, as this would pose an identification risk. Instead, the hardware will be open-source, and users will be able to order circuit boards directly from manufacturers and flash them themselves. An official archive via Radicle is planned for the future. As development is ongoing, there is no set release date.