The GlitchMod knowledge base

Dumping your NAND and CPU Key

This guide will walk you through dumping your console's NAND and obtaining its CPU Key. These come in handy when updating your system software and can also help you recover you from a possible brick, or if you want to do an RGH mod with Ba…

4 min readUpdated Oct 9, 2026

This guide will walk you through dumping your console's NAND and obtaining its CPU Key. These come in handy when updating your system software and can also help you recover you from a possible brick, or if you want to do an RGH mod with Bad Update instead of through a NAND flasher.

The methods listed in this guide require a working modified console (RGH, JTAG, or Bad Update) that can run homebrew programs. If you need to dump the NAND of a bricked console, you need to follow the corresponding guides for a 4 GB Corona/Waitsburg/Stingray NAND or all other NAND types.

Using XeLL

By default, if you boot XeLL when an Ethernet cable is plugged in, it will either pull an IP from your router via DHCP or it will use the default IP of 192.168.1.99 if you are not connected to a router. You must unplug any wireless USB adapters if you have them plugged in, as it will halt the boot process. By entering the IP address shown toward the bottom of XeLL on a web browser, it should pull up a XeLL Reloaded web page. The following are displayed:

  • CPU Key
    • Make sure to copy and paste this to somewhere on your computer, or directly in J-Runner.
  • DVD Key
  • Raw Flash (download)
    • This will download a dump of your flash chip straight to the device you are using.
  • Key Vault
    • This will download a decrypted keyvault file straight to the device you are using.
  • Fuses
    • This will download a file listing the status of your CPU fuses straight to the device you are using.
  • Startup Log
    • This will display a text file of all the events that have been printed to the screen since boot, some of which you can't normally see.
  • Shutdown
  • Reboot

A video demonstration of using XeLL to dump and flash a NAND can be found on MrMario2011's channel.

Using Simple 360 NAND Flasher 1.4b

  1. Download and launch Simple 360 NAND Flasher (source) on your console. You can also use the Homebrew Store to access it.
  2. Press X to dump NAND. If everything went fine, you should get message saying, "NAND Dumped!". Press any button to exit.
  3. There should now be a file called "flashdmp.bin" in the Simple 360 NAND Flasher directory. Copy this file to your PC.
  4. Download and run X360 NAND Dump Checker. Press "check NAND" and select the flashdmp.bin file. If the NAND is fine, then you should see a message saying, "NAND Verified as OK!". As long as the verification is OK, then bad blocks do not matter. If bad blocks are causing verification to fail, you should go back to step 1 and try to dump NAND again.
  5. Your CPU key will be automatically saved into "cpukey.txt" file along with the NAND dump, which is "flashdmp.bin".
  6. Make a copy of flashdmp.bin to a safe location, preferably outside of your PC (to a cloud, external media, etc).
    • At least one or more copies in as many locations possible for you to access is ideal.

Decrypting the NAND

Once you have successfully obtained your CPU key and NAND dump, you may want to extract the contents of your NAND before going further for backup purposes, like your original keyvault. Here is how to do so.

  1. Add your original NAND dump to J-Runner using the Load Source button. It will be either named flashdmp.bin or nanddump(1/2).bin depending on what you dumped with.
  2. Paste or type the CPU key in the corresponding text box. J-Runner will automatically decrypt the NAND dump once you put in the matching CPU key, though there's some additional files you'll want to dump after this stage.
    • You also have the option of automatically getting the CPU key from XeLL with the console connected to your LAN. Enter the IP address XeLL gives you into the lower right of the app. You can then click Get CPU Key and J-Runner will automatically decrypt the NAND dump you put into the "Load Source" field.
  3. Select the button above the Source NAND's text field named Extract Files.
  4. You will now have backups of the original console's keyvault, SMC configuration, and SMC firmware.