Firmware on these is pretty tight. They’re usually using CC2510s or CC2530s. The CC2510 has a voltage glitch hack that you can use to attempt to read the contents via the DCOUPL capcitor, but it’s not very effective and you can only read a few bytes per attack.
You can see a github some tools some have created here. Eventually someone is going to read the firmware off theses and be able to hack them, it’s just a matter of time.
Firmware on these is pretty tight. They’re usually using CC2510s or CC2530s. The CC2510 has a voltage glitch hack that you can use to attempt to read the contents via the DCOUPL capcitor, but it’s not very effective and you can only read a few bytes per attack.
You can see a github some tools some have created here. Eventually someone is going to read the firmware off theses and be able to hack them, it’s just a matter of time.