




The Netherlands has been the home for Hardwear.io since 2015.
We are very excited to host the industry from automotive, healthcare, semiconductor, IoT, industrial control systems and Govt/Defences Institutes to join us for Hardwear.io NL scheduled on 17th Nov to 21st Nov 2025 at Amsterdam Marriott Hotel
Learn, share, build, collaborate with 100+ companies attending Hardwear.io NL from around the globe to examine the current and future challenges in hardware security.
Reverse engineering Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security tools & classes
Reverse engineering Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security tools & classes
Real-World Exploitation of Transient Execution Vulnerabilities to Leak Private Data from Public Clouds
Reverse engineering Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security tools & classes
Reverse engineering Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security tools & classes
Real-World Exploitation of Transient Execution Vulnerabilities to Leak Private Data from Public Clouds
The Hardwear.io CTF organized by Quarkslab and Ledger team is back for this physical event!
Ever wondered – How to reverse a PCB? How to spy on embedded devices? How do car chips work? How to solder under microscope?
Then this CTF is for you!
We’ve got plenty of challenges related to various themes such as RFID, Bluetooth, automotive, 3D, (de)soldering, radio, and much more. We will provide the hardware hacking tools you might need (soldering iron, logic analyzer, …) as well as guidance on how to use them.
Just grab your PC and come try to solve our challenges. You’ll have fun, learn new skills and who knows, maybe use these skills to break real embedded devices and propose a talk for next year!
Requirements:
A PC with Linux is needed for some of the challenges, but we’ve also some other ones that can be done without a PC.
How to Participate:
Once the CTF is open, come to our booth, register a new team and start playing.
CTF Time:
| Position | Prizes |
|---|---|
| 1st Place |
|
| 2nd Place |
|
| 3rd Place |
|
* Top 10 scorer details will be shared with the sponsor for engagement/partnership activities
Please read the entire content below before submitting – even if you are a seasoned speaker.
Hardwear.io is a platform for the hardware and security community where researchers showcase and discuss their innovative research on attacking and defending hardware. We happily open doors for researchers and hackers around the world working on the next Big Thing in security – if you’ve done interesting offence/defence research on any hardware and want to share it to the security community, it’s time to submit your research paper!
We are interested in new and cutting edge security work that has previously not been published. Some security topics for your reference including (but not limited to):
Type: A deep knowledge technical track that includes new research, vulnerabilities, zero days or exploits. And by new we really mean new i.e. if your research or talk has been published/showcased (partially or entirely) before, it will fall under current research category even though there are enhancements/changes to the original research.**
Duration: 45 mins
Benefits:
Either actuals or the below mentioned amounts, whichever is less
Type: Comprises known security issues, research presented/published elsewhere, case studies, twist to an existing research, vulnerability, exploit or research-in-progress.**
Duration: 45 mins
Benefits:
Type: Comprises open source security tools, exploits, hardware etc. This is an excellent opportunity for the original authors to showcase their work to the world.**
Duration: 30 mins
Benefits:
t.l.d.r. We will not publish your research in an academic journal, hence there’s no strict format.
Some of you might wonder what format (number of pages, single/double-column, blind/single-blind, etc.) you should stick to when submitting your research or tool. Well, as we are not an academic conference and we do not publish your research in any academic journals (ieee, acm, springer, open source, etc.), we don’t have a strict format for the submissions.
One can actually submit their research without a full-fledged research paper: if they prefer to just describe the research details under “Full Technical details” in the form, that is also sufficient. Of course, you can also upload your work in the format of a paper: whatever is more convenient for you, works for us. After submission, all research will be subject to review by our review board. The reviewers will not know the names/affiliations of the authors.
The authors of all accepted papers are invited to present their research in-person in the Netherlands between 20 Nov – 21 Nov 2025. We will record the talks and upload them (together with the ppts).
1) Submit early – Submitting early increases the chance of acceptance in the first round of reviews. The more you delay, the more competition you have with other papers that are submitted later.
2) Technical description – The more clear-cut technical details you provide, the better chance you have of getting accepted. Reviewers usually give a low score to submissions that have very short/vague abstract and may not request more details. The best way is to provide a supporting full technical paper that explains all the vulnerabilities, exploits, etc. in detail. Product/company marketing and vendor-related pitches will be rejected. We request you not to submit any product-specific talk.
3) Live demos – please note we really like talks/workshops with live demos. Of course it is also possible to submit a paper without demos – this will not affect the score of your paper.
4) Rejection of a paper – Many security professionals aim to publish and present their findings at renowned security conferences. However, publishing such research is no easy task, and rejection is a common occurrence. Please take rejection as a suggestion for improvement of the paper. Declining a paper doesn’t mean your submission is not good enough – there are numerous parameters we consider when reviewing a paper. Quite often we have to let go of really good talks since there is already an accepted paper on a similar subject, or because your submission is already presented/published elsewhere. Cheer up and get ready for the next submission, we’re always looking for new research!
5) Review panel & comments – The review will be conducted by our external review board. Final decision on acceptance/rejection of papers is based on this scoring and any internal critical decision. We do not ask our review board to provide comments/feedback for the submitters .
6) Category – If the submission is (being) presented prior to Hardwear.io or if it is an enhancement of an already presented research, please DO NOT mark it as new research, as it falls under current research.
7) New research – At Hardwear.io we focus on new research that has not yet been published/presented prior to Hardwear.io conference dates. New research submissions get priority over current research. If your submission is a rework/enhancement or your existing research or similar presentation to what is already delivered/published elsewhere, it will get a lower score when compared to new research.
8) Past talks – Please visit hardwear.io/archives and have a look at previous conference speeches for reference purposes.
| Date | Time | Activity Schedule |
|---|---|---|
| 17 Nov | 10:00 AM - 4:00 PM | Setup - Hardpwn Team |
| 18 Nov | 10:00 AM - 5:00 PM | Hack Stuff & Report Bugs Presentation by hardpwn team & OEM's [Optional] |
| 19 Nov | 10:00 AM - 5:00 PM | Hack Stuff & Report Bugs Presentation by hardPwn team [Optional] |
| 20 Nov | 10:00 AM - 5:00 PM | Hack Stuff & Report Bugs Presentation by hardPwn team & OEM's [Optional] |
| 21 Nov | 10:00 AM - 3:30 PM | Hack Stuff & Report Bugs Shutdown, Pack and Event Presentation |
Please Note: It is mandatory for individuals to have a valid conference pass (Student / Individual / Corporate) to participate in HardPwn
The Eighth edition of HardPwn contest will be held during Hardwear.io 2025 in Amsterdam Marriott Hotel, Netherlands. At Hardpwn, you will be able to hack fearlessly (it is actually the vendor who is asking you to) and get rewarded. Companies might even recruit you if they really like your skills & hacks – why not participate?
What can I expect at the HardPwn contest?
| CISCO | |
|---|---|
| Google Pixel Phone 9a | CW9162I-MR AP |
| Google Pixel Watch | CW9172H AP |
| Google Nest Indoor Camera | CW9178I AP |
| Google TV Streamer | C9800 WLC |
| MS150 Switch | |
| MS130 Switch |
CISCO : Scope Link
We are open to meeting vendors/OEMs willing to test their devices at our HardPwn challenge. Your devices will be tested by top security researchers attending Hardwear.io! Interested? Then shoot us an email: [email protected]
Note: To make your hacking experience even smoother, we’ll have the following hardware hacking tools available at the HardPwn booth (but in limited quantities): JTAGulator, Chipwisperer, Expliot NANO, Hydra Bus, USB Microscope, Rework Station, USB- TTL, Proxmark3, Ubertooth, TNM5000, Jlink, Saleae Logic Analyzers, Mini Hot plate Pre-heater , electric screwdriver kit, VNR eMMC kit, iFixit FixHub Soldering Iron’s etc.
Please join us hardwear.io Discord Server and engage with other researchers to on the
Hardpwn Channel : https://discord.gg/8frukrk
| START | END | Talks (Salon A+B+C) | |
|---|---|---|---|
| 08:15 | 09:15 | Registration | |
| 09:20 | 09:30 | Opening Note | |
| 09:30 | 10:10 | [KEYNOTE] Towards End-User Verifiable Silicon by Andrew 'bunnie' Huang | |
| 10:15 | 10:55 | Arise from the Wireless: Breaking the Security Barrier in Wi-Fi by Wei-Che Kao | |
| 10:55 | 11:15 | Coffee Break | |
| 11:20 | 12:00 | Texas Incidents - How we broke the OMAP-L138 Trusted Execution Environment by Wouter Bokslag and Carlo Meijer | |
| 12:05 | 12:45 | Of Boot Vectors and Double Glitches: Bypassing RP2350's Secure Boot by Marius Muench and Thomas Roth | |
| 12:45 | 14:00 | Lunch Break | |
| 14:00 | 14:40 | Real-World Exploitation of Transient Execution Vulnerabilities to Leak Private Data from Public Clouds by Mathé Hertogh | [Workshop] Blue2thprinting: identifying the form and function of the Bluetooth devices by Xeno Kovah |
| 14:45 | 15:25 | Setresuid(⚡): Glitching Google's TV Streamer from adb to roott by Niek Timmers | |
| 14:00 | 15:25 | [Workshop] Blue2thprinting: identifying the form and function of the Bluetooth devices by Xeno Kovah | |
| 15:30 | 16:10 | Watch Out! A Security Case Study of a COROS Sports Watch by Moritz Abrell | |
| 16:10 | 16:25 | Coffee Break | |
| 16:25 | 17:05 | Low Power, High Risk: Fuzzing the Chips Behind IoT by Noah Holmdin and Ravishankar Borgaonkar | |
| 19:00 | 21:30 | Invite Only Dinner & Drinks | |
| START | END | Talks (Salon A+B+C) |
|---|---|---|
| 09:30 | 10:10 | Reverse engineering Realtek RTL8761B* Bluetooth chips, to make better Bluetooth security tools & classes by Xeno Kovah |
| 10:15 | 10:55 | Hacking to the Gate(way): Take Over Samsung SmartThings with a Single API Call by TingYu Chen |
| 10:55 | 11:15 | Coffee Break |
| 11:20 | 12:00 | Overflow not needed: faulting a smartphone SOC into a ROP chain at EL3 by Charles Christen and Léo Benito |
| 12:05 | 12:45 | Bypassing PQC Signature Verification with Fault Injection: Dilithium, XMSS, SPHINCS+ by Fikret Garipay |
| 12:45 | 14:00 | Lunch Break |
| 14:00 | 14:40 | When Timers Fail: Discovering Hidden Cache State Leaks on ARM CPUs by Fabian Thomas |
| 14:45 | 15:25 | [Panel] Hardware Vulnerabilities: Lessons from the Vendor Frontlines |
| 15:30 | 16:10 | SoC Exploitation In A Nutshell: Unisoc History by Kozlov Alexander and Sergey Anufrienko |
| 16:10 | 16:25 | Coffee Break |
| 16:25 | 17:00 | Prize Ceremony |
| Date | Time | Talks (Studio 7) | |
|---|---|---|---|
| Start | End | ||
| 21st Nov 2025 | 11:15 | 11:45 | Security-First DRAM Design: Coping with Data-Disturbance Errors of Today and Tomorrow by Aamer Jaleel |
| 11:15 | 11:45 | Security-First DRAM Design: Coping with Data-Disturbance Errors of Today and Tomorrow by Aamer Jaleel | |
| 11:45 | 12:30 | GPUHammer: Flipping Bits in GPUs for Fun and Profit by Gururaj Saileshwar | |
| 12:30 | 13:00 | Fuzzing in the Trenches: Challenges and Lessons Learned by Elia Geretto | |
| Lunch | |||
| 14:00 | 14:30 | Mitigating and Breaking RowHammer in Modern DRAM-based Systems by Giray Yağlıkçı | |
| 14:30 | 15:00 | Breaking the Illusion of Security: Rowhammer is back on DDR5 by Patrick Jattke | |
| 15:00 | 15:30 | Modern memory error exploitation via speculative execution attacks by Dr.-Ing. Anil Kurmus | |
| 15:30 | 16:00 | When Memory Lies: Breaching Processor Security via Rogue Memory Modules by Luca Wilke and Jesse De Meulemeester | |
Winbond Electronics Corporation is a leading global supplier of semiconductor memory solutions. The Company provides customer-driven memory solutions backed by the expert capabilities of product design, R&D, manufacturing, and sales services. Winbond’s product portfolio, consisting of Specialty DRAM, Mobile DRAM, Code Storage Flash, and TrustME® Secure Flash, is widely used by tier-1 customers in communication, consumer electronics, automotive and industrial, and computer peripheral markets. Winbond is headquartered in Central Taiwan Science Park (CTSP) and it has subsidiaries in the USA, Japan, Israel, China, Hong Kong, and Germany. Based on Taichung and new Kaohsiung 12-inch fabs in Taiwan, Winbond keeps pace to develop in-house technologies to provide high-quality memory IC products.
Visit us on – https://www.winbond.com
Cisco is the worldwide technology leader that securely connects everything to make anything possible. Our purpose is to power an inclusive future for all by helping our customers reimagine their applications, power hybrid work, secure their enterprise, transform their infrastructure, and meet their sustainability goals.
Visit us on – https://jobs.cisco.com/jobs
Since 2015, eShard has been providing independent security assessment services, lab equipment and esDynamic, a software platform dedicated to physical attacks on chips (Side Channel Attacks, Power and Clock Glitching, Electromagnetic Fault Injection, Laser Fault Injection, Photonic Emission) as long as extensive knowledge and know-how on the matter.
eShard also offers a binary analysis platform esReverse combining static and dynamic tools to offer all-in-one reverse capabilities to expert teams.
Visit us on – https://eshard.com/
uncover both known and zero-day flaws in firmware, container images, and binaries. Close gaps proactively and harden every layer before attackers strike.
Visit us on – https://byteray.co.uk/
Keysight Technologies is a world leader in high value, mission critical electronic design and test solutions that is relied upon by world-leading technology companies. Everywhere the electronic signal goes, Keysight is there to help design, test, manufacture and optimize. With over 80 years of innovation, measurement science expertise and deep customer relationships, Keysight helps customers bring breakthrough electronic products and systems to market faster and at a lower cost. Customers span the worldwide communications ecosystem, Internet infrastructure, aerospace and defense, automotive, semiconductor and general electronics end markets. Keysight’s legacy includes the original Hewlett-Packard electronic measurement business founded in 1939 by Bill Hewlett and Dave Packard, which spun off with Agilent Technologies in 1999. In 2014, Agilent spun off its electronic measurement division as Keysight Technologies.
Visit us on https://www.keysight.com/us/en/products/network-test/device-vulnerability-analysis.html
Ledger, celebrating its 10th anniversary in 2024, is the global leader in digital asset security. With 6M+ devices sold worldwide, Ledger secures over 20% of global crypto assets. Their renowned Donjon team is crucial for safeguarding the digital asset ecosystem. Amidst $14B lost to hacks in 2023, Ledger offers uncompromising security and self-custody, bringing peace of mind to consumers and institutions alike.
Visit us on – https://www.ledger.com
Visit us on – https://trust.mi.com/misrc