Netherlands 2025

17th Nov - 21st Nov 2025 | Amsterdam Marriott Hotel

Hardwear.io Netherlands 2025

The Netherlands has been the home for Hardwear.io since 2015.

We are very excited to host the industry from automotive, healthcare, semiconductor, IoT, industrial control systems and Govt/Defences Institutes to join us for Hardwear.io NL scheduled on 17th Nov to 21st Nov 2025 at Amsterdam Marriott Hotel

Learn, share, build, collaborate with 100+ companies attending Hardwear.io NL from around the globe to examine the current and future challenges in hardware security.

Voices of Hardwear.io
Talks & Speakers
Trainings
Connected Car Hacking
Trainer(s):
Dates:
17th to 19th Nov 2025
Timing:
9:00am to 5:00pm CET
Venue:
Amsterdam Marriott Hotel
Training Level:
Intermediate to Advanced
Integrated Circuits Reverse Engineering: ROM is your primary target.
Trainer(s):
Dates:
17th to 19th Nov 2025
Timing:
9:00am to 5:00pm CET
Venue:
Amsterdam Marriott Hotel
Training Level:
Intermediate
Bluetooth Low Energy – Full Stack Attack
Trainer(s):
Dates:
17th to 19th Nov 2025
Timing:
9:00am to 5:00pm CET
Venue:
Amsterdam Marriott Hotel
Training Level:
Basic
Unveiling the secrets of AI implementations using side-channel analysis
Dates:
17th to 19th Nov 2025
Timing:
9:00am to 5:00pm CET
Venue:
Amsterdam Marriott Hotel
Training Level:
Intermediate
The Art of Fault Injection: Advanced Techniques & Attacks
Trainer(s):
Dates:
17th to 19th Nov 2025
Timing:
9:00am to 5:00pm CET
Venue:
Amsterdam Marriott Hotel
Training Level:
Intermediate to Advanced
Hands-On Car Hacking
Trainer(s):
Dates:
17th to 19th Nov 2025
Timing:
9:00am to 5:00pm CET
Venue:
NH Leidseplein Hotel
Training Level:
Intermediate to Advanced
FPGA Security and Reverse Engineering
Trainer(s):
Dates:
17th to 19th Nov 2025
Timing:
9:00am to 5:00pm CET
Venue:
Amsterdam Marriott Hotel
Training Level:
Basic to Intermediate
Hands-On TrustZone TEE Security
Trainer(s):
Dates:
17th to 19th Nov 2025
Timing:
9:00am to 5:00pm CET
Venue:
Amsterdam Marriott Hotel
Training Level:
Intermediate to Advanced
Baseband Reverse Engineering & Fuzzing
Dates:
17th to 19th Nov 2025
Timing:
9:00am to 5:00pm CET
Venue:
NH Leidseplein Hotel
Training Level:
Intermediate to Advanced
Monolith Pinout Discovery – enable data recovery from SD cards
Trainer(s):
Dates:
17th to 19th Nov 2025
Timing:
9:00am to 5:00pm CET
Venue:
NH Leidseplein Hotel
Training Level:
Intermediate, Basic
Practical Hardware Hacking Basics + Bonus Day!
Trainer(s):
Dates:
17th - 19th Nov 2025
Timing:
9:00am to 5:30pm CET
Venue:
NH Leidseplein Hotel
Training Level:
Basic
LoRaPWN: from custom/industrial to drone Hacking
Trainer(s):
Dates:
17th to 19th Nov 2025
Timing:
9:00am to 5:00pm CET
Venue:
Amsterdam Marriott Hotel
Training Level:
Advanced
BootPwn: Breaking Secure Boot by Experience
Trainer(s):
Dates:
17th - 19th Nov 2025
Timing:
9:00am to 5:00pm CET
Venue:
Amsterdam Marriott Hotel
Training Level:
Intermediate
CTF

The Hardwear.io CTF organized by Quarkslab and Ledger team is back for this physical event!

Ever wondered – How to reverse a PCB? How to spy on embedded devices? How do car chips work? How to solder under microscope?

Then this CTF is for you!

We’ve got plenty of challenges related to various themes such as RFID, Bluetooth, automotive, 3D, (de)soldering, radio, and much more. We will provide the hardware hacking tools you might need (soldering iron, logic analyzer, …) as well as guidance on how to use them.

Just grab your PC and come try to solve our challenges. You’ll have fun, learn new skills and who knows, maybe use these skills to break real embedded devices and propose a talk for next year!

Requirements:
A PC with Linux is needed for some of the challenges, but we’ve also some other ones that can be done without a PC.

How to Participate:
Once the CTF is open, come to our booth, register a new team and start playing.

CTF Time:

  • Start: 10:00hrs – 17:00hrs, 20th Nov 2025
  • Ends: 10:00hrs – 13:50hrs, 21th Nov 2025
Prizes
Position Prizes
1st Place
  • Saleae Logic Pro 16

  • iFixit Portable Soldering Station

2nd Place
  • Chipshouter PicoEMP

  • Sensepeek 6003 PCBite kit

  • iFixit Smart Soldering Iron
3rd Place
  • JTAGulator

  • iFixit Smart Soldering Iron

Organized by:

Organized by:

* Top 10 scorer details will be shared with the sponsor for engagement/partnership activities

CFP
Welcome to the Call for Papers of the 11th edition of Hardwear.io Netherlands!

Please read the entire content below before submitting – even if you are a seasoned speaker.

Hardwear.io is a platform for the hardware and security community where researchers showcase and discuss their innovative research on attacking and defending hardware. We happily open doors for researchers and hackers around the world working on the next Big Thing in security – if you’ve done interesting offence/defence research on any hardware and want to share it to the security community, it’s time to submit your research paper!

Submission Topics

We are interested in new and cutting edge security work that has previously not been published. Some security topics for your reference including (but not limited to):

  • Integrated Circuits
  • Processors
  • Internet of Things / Smart Devices
  • Embedded Systems & Cryptography
  • Automobile, Aeroplane, Train Automation Systems and Hardware Components
  • Industrial Control Systems / SCADA
  • Satellite Systems
  • Medical Devices
  • Protocol and Cryptography Attacks and Encryption Technologies
  • Smartphone Firmware, Hardware Firmware
  • Hardware Pentesting
  • Trusted Platform Module
  • Radio Communication Protocols and Hardware
  • Hardware Trust and Assurance Algorithms
  • Multimedia Hardware, Firmware, Protocols
  • Telecom Hardware / Networks
  • Electronic / Physical Locks
  • Attacks & Countermeasures
Categories & Speaker Benefits
A. New Research Category:

Type: A deep knowledge technical track that includes new research, vulnerabilities, zero days or exploits. And by new we really mean new i.e. if your research or talk has been published/showcased (partially or entirely) before, it will fall under current research category even though there are enhancements/changes to the original research.**

Duration: 45 mins

Benefits:

  • Travel Reimbursement:

    Either actuals or the below mentioned amounts, whichever is less

    • Speaker travelling from outside Europe (Based on actuals or Euro 1000, whichever is less)
    • Speaker travelling from within Europe (Based on actuals or Euro 300, whichever is less)
    • If your employer can afford (or covers) your travel, we will not reimburse anything from our end i.e. we will only reimburse if no one is sponsoring your travel)
    • Please provide the receipts/invoice of the travel along with tickets for reimbursement.
  • Complimentary Accommodation for 3 nights
  • Complimentary Corporate Conference Pass
  • Invitation to Hardwear.io Party

 

B. Current Research and Workshop Category:

Type: Comprises known security issues, research presented/published elsewhere, case studies, twist to an existing research, vulnerability, exploit or research-in-progress.**

Duration: 45 mins

Benefits:

  • Complimentary Accommodation for 3 nights
  • Complimentary Corporate Conference Pass
  • Invitation to Hardwear.io Party

 

C. Tool Category:

Type: Comprises open source security tools, exploits, hardware etc. This is an excellent opportunity for the original authors to showcase their work to the world.**

Duration: 30 mins

Benefits:

  • Complimentary Accommodation for 3 nights
  • Complimentary Corporate Conference Pass
  • Invitation to Hardwear.io Party
Submission Format

t.l.d.r. We will not publish your research in an academic journal, hence there’s no strict format.

Some of you might wonder what format (number of pages, single/double-column, blind/single-blind, etc.) you should stick to when submitting your research or tool. Well, as we are not an academic conference and we do not publish your research in any academic journals (ieee, acm, springer, open source, etc.), we don’t have a strict format for the submissions.

One can actually submit their research without a full-fledged research paper: if they prefer to just describe the research details under “Full Technical details” in the form, that is also sufficient. Of course, you can also upload your work in the format of a paper: whatever is more convenient for you, works for us. After submission, all research will be subject to review by our review board. The reviewers will not know the names/affiliations of the authors.

The authors of all accepted papers are invited to present their research in-person in the Netherlands between 20 Nov – 21 Nov 2025. We will record the talks and upload them (together with the ppts).

Tips For Submitting

1) Submit early – Submitting early increases the chance of acceptance in the first round of reviews. The more you delay, the more competition you have with other papers that are submitted later.

2) Technical description – The more clear-cut technical details you provide, the better chance you have of getting accepted. Reviewers usually give a low score to submissions that have very short/vague abstract and may not request more details. The best way is to provide a supporting full technical paper that explains all the vulnerabilities, exploits, etc. in detail. Product/company marketing and vendor-related pitches will be rejected. We request you not to submit any product-specific talk.

3) Live demos – please note we really like talks/workshops with live demos. Of course it is also possible to submit a paper without demos – this will not affect the score of your paper.

4) Rejection of a paper – Many security professionals aim to publish and present their findings at renowned security conferences. However, publishing such research is no easy task, and rejection is a common occurrence. Please take rejection as a suggestion for improvement of the paper. Declining a paper doesn’t mean your submission is not good enough – there are numerous parameters we consider when reviewing a paper. Quite often we have to let go of really good talks since there is already an accepted paper on a similar subject, or because your submission is already presented/published elsewhere. Cheer up and get ready for the next submission, we’re always looking for new research!

5) Review panel & comments – The review will be conducted by our external review board. Final decision on acceptance/rejection of papers is based on this scoring and any internal critical decision. We do not ask our review board to provide comments/feedback for the submitters .

6) Category – If the submission is (being) presented prior to Hardwear.io or if it is an enhancement of an already presented research, please DO NOT mark it as new research, as it falls under current research.

7) New research – At Hardwear.io we focus on new research that has not yet been published/presented prior to Hardwear.io conference dates. New research submissions get priority over current research. If your submission is a rework/enhancement or your existing research or similar presentation to what is already delivered/published elsewhere, it will get a lower score when compared to new research.

8) Past talks – Please visit hardwear.io/archives and have a look at previous conference speeches for reference purposes.

Terms
  • Only the New Research category is eligible to receive Travel Reimbursement, but an exception can be made for the Current Research / Tool Category if the talk scoring is high from the review team. Please note, we do not share review scores/comments with any individual.
  • Only one speaker will be eligible for Travel Reimbursement benefits in case of two or more speakers for a talk.
  • The process to redeem the Travel Reimbursement will begin a week after the conference is over. It is mandatory to submit a soft copy of your passport and e-visa for reimbursement purposes.
  • We do not provide Travel Reimbursement in cash.
  • The provided accommodation will be shared among speakers in case of two or more speakers for a talk.
  • Once a talk is accepted, it is not allowed to add more speakers to the talk.
  • By submitting a paper and agreeing to talk, the speakers give Payatu BV & Hardwear Inc the right to post, publish, re-distribute online and offline, soft and/or hard copies of their presentation material including slides, source code, design specifications, detailed paper and the recorded video of the talk.
  • All proposals must be submitted through the Call For Papers (CFP) form. Proposals submitted through any other way will not be considered for CFP review.
  • The talk submitted for a specific event will only be considered for that event only.
Contact
Last three steps: to engage with the community & keep up to date with what’s up this year.
If you have any queries, feel free to reach us at: cfp AT hardwear DOT io cfp AT hardwear DOT io
HardPwn

HardPwn - Hardware Hacking Contest @hardwear.io Netherlands 2025 #HackFearlessly

Date Time Activity Schedule
17 Nov 10:00 AM - 4:00 PM Setup - Hardpwn Team
18 Nov 10:00 AM - 5:00 PM Hack Stuff & Report Bugs
Presentation by hardpwn team & OEM's [Optional]
19 Nov 10:00 AM - 5:00 PM Hack Stuff & Report Bugs
Presentation by hardPwn team [Optional]
20 Nov 10:00 AM - 5:00 PM Hack Stuff & Report Bugs
Presentation by hardPwn team & OEM's [Optional]
21 Nov 10:00 AM - 3:30 PM Hack Stuff & Report Bugs
Shutdown, Pack and Event Presentation

Please Note: It is mandatory for individuals to have a valid conference pass (Student / Individual / Corporate) to participate in HardPwn

The Eighth edition of HardPwn contest will be held during Hardwear.io 2025 in Amsterdam Marriott Hotel, Netherlands. At Hardpwn, you will be able to hack fearlessly (it is actually the vendor who is asking you to) and get rewarded. Companies might even recruit you if they really like your skills & hacks – why not participate?


What can I expect at the HardPwn contest?

  • We provide hardware devices (target) to the security researchers who have expertise in side-channel attacks, RFID/NFC hacking, breaking crypto, reverse-engineering firmware, etc.;
  • If you find an issue, you will report the vulnerability to the OEM directly in a controlled manner at the conference;
  • In return, the OEM will reward you with a prize, depending on the severity of the finding;
  • There would be an NDA signed and you and the other participants would not be allowed to disclose the finding in public till the issue is fixed by the vendor.
Target Device:
Google CISCO
Google Pixel Phone 9a CW9162I-MR AP
Google Pixel Watch CW9172H AP
Google Nest Indoor Camera CW9178I AP
Google TV Streamer C9800 WLC
MS150 Switch
MS130 Switch

CISCO : Scope Link

What's in it for the vendors?

We are open to meeting vendors/OEMs willing to test their devices at our HardPwn challenge. Your devices will be tested by top security researchers attending Hardwear.io! Interested? Then shoot us an email: [email protected]

 

Note: To make your hacking experience even smoother, we’ll have the following hardware hacking tools available at the HardPwn booth (but in limited quantities): JTAGulator, Chipwisperer, Expliot NANO, Hydra Bus, USB Microscope, Rework Station, USB- TTL, Proxmark3, Ubertooth, TNM5000, Jlink, Saleae Logic Analyzers, Mini Hot plate Pre-heater , electric screwdriver kit, VNR eMMC kit, iFixit FixHub Soldering Iron’s etc.

Participating Companies:

Please join us hardwear.io Discord Server and engage with other researchers to on the
Hardpwn Channel : https://discord.gg/8frukrk

Schedule
Date Timing Training Name Training Room Hotel
17th Nov - 19th Nov 2025
(3 Days)
8:15 to 9:00 Registration
Start 9:00 The Art of Fault Injection: Advanced Techniques & Attacks Salon A Marriott Amsterdam
BootPwn: Breaking Secure Boot by Experience Salon B
LoRaPWN: from custom/industrial to drone Hacking Salon C
Coffee Break 11:00 to 11:15 Bluetooth Low Energy - Full Stack Attack Salon D
Connected Car Hacking Salon E
Hands-on TrustZone TEE Security Studio 5
Lunch Break 13:00 to 14:00 IC Reverse Engineering: ROM is your primary target. Studio 6
Unveiling the secrets of AI implementations using side-channel analysis Studio 3
FPGA Security and Reverse Engineering Studio 7
Coffee Break 15:45 to 16:00 Monolith Pinout Discovery - enable data recovery from SD cards Amstelpark NH Leidseplein Hotel
Practical Hardware Hacking Basics + Bonus Day! Rembrandtpark
Hands-on Car Hacking Beatrixpark
End 17:30 Baseband Reverse Engineering & Fuzzing Vondelpark
START END Talks (Salon A+B+C)
08:15 09:15 Registration
09:20 09:30 Opening Note
09:30 10:10 [KEYNOTE] Towards End-User Verifiable Silicon by Andrew 'bunnie' Huang
10:15 10:55 Arise from the Wireless: Breaking the Security Barrier in Wi-Fi by Wei-Che Kao
10:55 11:15 Coffee Break
11:20 12:00 Texas Incidents - How we broke the OMAP-L138 Trusted Execution Environment by Wouter Bokslag and Carlo Meijer
12:05 12:45 Of Boot Vectors and Double Glitches: Bypassing RP2350's Secure Boot by Marius Muench and Thomas Roth
12:45 14:00 Lunch Break
14:00 14:40 Real-World Exploitation of Transient Execution Vulnerabilities to Leak Private Data from Public Clouds by Mathé Hertogh [Workshop] Blue2thprinting: identifying the form and function of the Bluetooth devices by Xeno Kovah
14:45 15:25 Setresuid(⚡): Glitching Google's TV Streamer from adb to roott by Niek Timmers
14:00 15:25 [Workshop] Blue2thprinting: identifying the form and function of the Bluetooth devices by Xeno Kovah
15:30 16:10 Watch Out! A Security Case Study of a COROS Sports Watch by Moritz Abrell
16:10 16:25 Coffee Break
16:25 17:05 Low Power, High Risk: Fuzzing the Chips Behind IoT by Noah Holmdin and Ravishankar Borgaonkar
19:00 21:30 Invite Only Dinner & Drinks
START END Talks (Salon A+B+C)
09:30 10:10 Reverse engineering Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security tools & classes by Xeno Kovah
10:15 10:55 Hacking to the Gate(way): Take Over Samsung SmartThings with a Single API Call by TingYu Chen
10:55 11:15 Coffee Break
11:20 12:00 Overflow not needed: faulting a smartphone SOC into a ROP chain at EL3 by Charles Christen and Léo Benito
12:05 12:45 Bypassing PQC Signature Verification with Fault Injection: Dilithium, XMSS, SPHINCS+ by Fikret Garipay
12:45 14:00 Lunch Break
14:00 14:40 When Timers Fail: Discovering Hidden Cache State Leaks on ARM CPUs by Fabian Thomas
14:45 15:25 [Panel] Hardware Vulnerabilities: Lessons from the Vendor Frontlines
15:30 16:10 SoC Exploitation In A Nutshell: Unisoc History by Kozlov Alexander and Sergey Anufrienko
16:10 16:25 Coffee Break
16:25 17:00 Prize Ceremony
Date Time Talks (Studio 7)
Start End
21st Nov 2025 11:15 11:45 Security-First DRAM Design: Coping with Data-Disturbance Errors of Today and Tomorrow by Aamer Jaleel
11:15 11:45 Security-First DRAM Design: Coping with Data-Disturbance Errors of Today and Tomorrow by Aamer Jaleel
11:45 12:30 GPUHammer: Flipping Bits in GPUs for Fun and Profit by Gururaj Saileshwar
12:30 13:00 Fuzzing in the Trenches: Challenges and Lessons Learned by Elia Geretto
Lunch
14:00 14:30 Mitigating and Breaking RowHammer in Modern DRAM-based Systems by Giray Yağlıkçı
14:30 15:00 Breaking the Illusion of Security: Rowhammer is back on DDR5 by Patrick Jattke
15:00 15:30 Modern memory error exploitation via speculative execution attacks by Dr.-Ing. Anil Kurmus
15:30 16:00 When Memory Lies: Breaching Processor Security via Rogue Memory Modules by Luca Wilke and Jesse De Meulemeester
Sponsors & Partners Netherlands 2025
Silver Sponsor
Winbond Electronics Corporation

Winbond Electronics Corporation is a leading global supplier of semiconductor memory solutions. The Company provides customer-driven memory solutions backed by the expert capabilities of product design, R&D, manufacturing, and sales services. Winbond’s product portfolio, consisting of Specialty DRAM, Mobile DRAM, Code Storage Flash, and TrustME® Secure Flash, is widely used by tier-1 customers in communication, consumer electronics, automotive and industrial, and computer peripheral markets. Winbond is headquartered in Central Taiwan Science Park (CTSP) and it has subsidiaries in the USA, Japan, Israel, China, Hong Kong, and Germany. Based on Taichung and new Kaohsiung 12-inch fabs in Taiwan, Winbond keeps pace to develop in-house technologies to provide high-quality memory IC products.

Visit us on – https://www.winbond.com

Cisco

Cisco is the worldwide technology leader that securely connects everything to make anything possible. Our purpose is to power an inclusive future for all by helping our customers reimagine their applications, power hybrid work, secure their enterprise, transform their infrastructure, and meet their sustainability goals.

Visit us on – https://jobs.cisco.com/jobs

Bronze Sponsor
eShard

Since 2015, eShard has been providing independent security assessment services, lab equipment and esDynamic, a software platform dedicated to physical attacks on chips (Side Channel Attacks, Power and Clock Glitching, Electromagnetic Fault Injection, Laser Fault Injection, Photonic Emission) as long as extensive knowledge and know-how on the matter.

eShard also offers a binary analysis platform esReverse combining static and dynamic tools to offer all-in-one reverse capabilities to expert teams.

Visit us on – https://eshard.com/

ByteRay

uncover both known and zero-day flaws in firmware, container images, and binaries. Close gaps proactively and harden every layer before attackers strike.

Visit us on – https://byteray.co.uk/

T-Shirt Sponsor
Keysight Technologies

Keysight Technologies is a world leader in high value, mission critical electronic design and test solutions that is relied upon by world-leading technology companies. Everywhere the electronic signal goes, Keysight is there to help design, test, manufacture and optimize. With over 80 years of innovation, measurement science expertise and deep customer relationships, Keysight helps customers bring breakthrough electronic products and systems to market faster and at a lower cost. Customers span the worldwide communications ecosystem, Internet infrastructure, aerospace and defense, automotive, semiconductor and general electronics end markets. Keysight’s legacy includes the original Hewlett-Packard electronic measurement business founded in 1939 by Bill Hewlett and Dave Packard, which spun off with Agilent Technologies in 1999. In 2014, Agilent spun off its electronic measurement division as Keysight Technologies.

Visit us on https://www.keysight.com/us/en/products/network-test/device-vulnerability-analysis.html

Lanyard Sponsor
Ledger

Ledger, celebrating its 10th anniversary in 2024, is the global leader in digital asset security. With 6M+ devices sold worldwide, Ledger secures over 20% of global crypto assets. Their renowned Donjon team is crucial for safeguarding the digital asset ecosystem. Amidst $14B lost to hacks in 2023, Ledger offers uncompromising security and self-custody, bringing peace of mind to consumers and institutions alike.

 

Visit us on – https://www.ledger.com

Happy Hour Sponsor

Visit us on – https://trust.mi.com/misrc

Community Partners