Recovery Mode, or RCM for short, is a feature of the bootROM built into the NVIDIA Tegra series of System on a Chips (SoC). This allowed NVIDIA or the device OEM (in this case, Nintendo) to inject & boot small programs directly on the chip, like to restore devices that have corrupt internal storage, or install the operating system onto a device after manufacturing.
On the Nintendo Switch, it can be accessed by a button combination; POWER + VOL UP, while the right Joy-con rail's pin 10 shorted to ground, such as pin 7, during the button combination. The Switch will also automatically enter RCM if the eMMC is damaged/removed, and/or the system software on the eMMC is too corrupt. Switch Lites don't have a Joy-con rail, so the only way for RCM to be triggered on these models is either grounding a specific pin on the Tegra X1 itself, or through a defective/missing eMMC.
When a Switch is in RCM, the screen will still be turned off, and USB/battery power draw will be extremely low (USB power draw will be around 100 mA, whereas if the Switch is turned on in Horizon OS, it's able to charge normally). The battery power draw will be around 200 mA (visable if you boot a Switch from the battery terminal using a bench power supply), causing the battery to drain to empty if a Switch is left in RCM mode for a long period of time.
While RCM is normally useless to average users, and still is on later Tegra chipsets with the patched bootROM, security vulnerabilities with how the bootROM checks USB payloads on earlier Tegra SoCs were severely flawed, which allows owners of early production Nintendo Switches to then use software like TegraRcmGui or Rekado to inject a custom payload.
Using RCM to boot Homebrew/CFW
Requirements
Software
You will need one of the following RCM injection apps, depending on the devices you have access to:
- If you have a Windows computer, use TegraRCMGUI
- Can also be installed through the terminal, PowerShell, or command line with
winget install eliboa.TegraRcmGUI
- Can also be installed through the terminal, PowerShell, or command line with
- If you have a Mac with macOS Sierra (10.12) or newer, you can either use CrystalRCM (recommended) or NXBoot (terminal app)
- If you have a Linux computer, use fusee-nano
- Can also be installed from the AUR.
- If you have an Android phone/tablet, use Rekado
- Can also be installed from the IzzyOnDroid repository
- If you have an iPhone, iPod Touch, or iPad on iOS 9 or later, and is either jailbroken, or can sideload apps some other way, use the NXBoot app
- If you're located in Europe, and have iOS 18.0 or newer, you can just use the AltStore.
- If you're not located in Europe and your device is compatible (iOS/iPadOS 17.0 or older), a useful sideloading method is TrollStore. Otherwise, you can use the normal sideloading methods.
This JavaScript website can also be used as a cross-platform payload injector for any device running a Chromium web browser, including Chromebooks, Chrome, Brave, Vivaldi, Opera, Edge, etc.
You will also want a payload to inject onto the Switch. As an example payload, you can download the latest version of ums-loader.
Hardware
- Unpatched HAC-001 Switch
- Late HAC-001 Switches got a slightly updated SoC that had new ipatches to make the Fusée Gelée exploit not work, so you need to identify if it's unpatched or not through the serial number.
- Every HAC-001(-01), Switch Lite, and OLED model will always be patched.
- A USB OTG adapter
- This is required if you're using an older Android or iOS/iPadOS device with either microUSB (former), or the Lightning connector (latter).
- If your phone or tablet has USB-C, you should be able to just use a USB-C to USB-C cable, but if that doesn't work, a USB-C OTG cable with a USB-A to USB-C cable can also be used.
- microSD Card that's at least 8 MB or more
- This is the bare minimum to just install Atmosphere and Hekate, but it's recommended to have 64 GB or more to have more storage for games, homebrew, and mods)
- Lastly, you will need a jig for the right Joy-Con rail in order to activate the console's recovery mode. You can 3D print them using publicly available STL files like this one, then insert a copper wire into it so it can bridge the pins in the rail.
- If you can't or don't want to 3D print the jig yourself, you can also buy pre-made jigs from Amazon and AliExpress.
Formatting microSD Card
Usually, brand new SD cards will either be FAT32 (≤32 GB) or exFAT (≥64 GB); either of which are natively compatible with the Switch already. However, if you want to be sure, you can either format the SD card with the Switch's system settings, or the SD Association formatting tool (macOS/Windows/Linux).
Triggering RCM
- Make sure the Switch is fully powered off by holding the power button until the shutdown options show up, then tap the corresponding button for shutting it down.
- Insert the jig in the right Joy-Con rail. Afterword, while holding the Volume + button, press the power button.
- If the Switch displays the Nintendo logo and boots normally, RCM was not successfully triggered, and you will need to repeat the steps.
- If the Switch is still displaying a black screen even after pressing the power button multiple times, then this indicates the console is in RCM.
- This can also be verified with a USB-C voltage meter, as a Switch in RCM will only draw around 100 mA from the USB port, whereas a Switch that has booted into the OS will draw 1-3A depending on the charger and its USB-PD voltage.
Sending a Payload
The steps for this depend on the injector software you're using on your device, so you will need to refer to the software's instructions if applicable. Generally, the interfaces of the RCM injection apps with a GUI are quite straightforward.
Select the bin file in the injection software, like the ums-loader payload suggested earlier in this guide. Afterwords, select the corresponding button to inject it onto the Switch.
Mounting SD Card with ums-loader
If you have ums-loader, you can use this payload allows to mount a Switch's microSD card through the console's USB-C port, making it behave like a USB card reader.
Make sure an SD card is inserted into the Switch for this step. After you injected UMS Loader, use the volume keys to go to Start UMS and activate it with the power button to access the SD card on your computer.
Once the SD card contents are visible on the computer, you can now install any homebrew you like, such as Hekate. Hekate is recommended to have, since it allows you to do a NAND backup. It can be booted later on by injecting the hekate_ctcaer_x.x.x.bin file.
- The version of the Hekate payload file used for injection won't actually matter as long as the Switch has Hekate installed on its microSD card (the
bootloaderfolder), as it will automatically redirect to the payload in Hekate'sbootloaderfolder.
Final Notes
With your microSD card still connected, you can also install CFW such as Atmosphere. Simply download the latest zip file from the releases page, and extract the contents of it to the root of the microSD card. After it has been installed to your microSD card, you just have to inject the fusee.bin file to boot it.
- The version of the fusee payload file used for injection won't actually matter as long as the Switch has Atmosphere installed on its microSD card, as it will automatically redirect to the fusee payload in the
atmospherefolder. - After you boot Atmosphere, make sure to backup your prodinfo file on the microSD card! This file is necessary still allow for your Switch to access NSO accounts if it requires the NAND firmware to be restored from a brick.
It's important to avoid physically removing and inserting the microSD card as much as possible, as the original Switch's SD card slot design is extremely fragile, which is why we're accessing it through the console's USB port instead.
Any future file changes to the Switch's microSD card should be done with one of the methods in Transferring Files because of this.