The GlitchMod knowledge base

PicoFlasher (Portuguese)

O PicoFlasher, também conhecido como Raspberry Pi Pico, é um dispositivo que pode ser usado para ler/escrever NANDs de Xbox 360 e também como um chip de glitch em placas Trinity. Ele funciona em conjunto com o programa para Windows J-Runne…

8 min readUpdated Oct 9, 2026
Other languages:

O PicoFlasher, também conhecido como Raspberry Pi Pico, é um dispositivo que pode ser usado para ler/escrever NANDs de Xbox 360 e também como um chip de glitch em placas Trinity. Ele funciona em conjunto com o programa para Windows J-Runner with Extras e J-Runner-Pro e pode ser usado para instalações JTAG e RGH. Ele é um dos programadores de NAND mais rápidos e é consideravelmente mais barato que a maioria.

O Raspberry Pi Pico não é feito especificamente para ler e escrever NANDs, no entanto, por cortesia de Balika011, agora pode ser usado como um programador de NAND.

O Raspberry Pi Pico não pode ser usado para programar chips de glitch.

Utilização

Para usar o Pi Pico como um PicoFlasher, você precisa primeiramente programá-lo com um arquivo da versão mais recente do software PicoFlasher daqui

Solder each wire (or connect a pin header wire) to each of the labeled pads on the Raspberry Pi pictured in one of the diagrams below, and then solder the other ends of the wires to each of the corresponding pads on the motherboard.

Once you’ve finished soldering, clean up any flux with isopropyl alcohol and cotton swabs.

Hax360 Firmware

SPI Pinout for NAND/eMMC

Pico / Pico 2 RP2040 Zero Xbox
GP16 GP0 SPI_MISO
GP17 GP1 SPI_SS_N
GP18 GP2 SPI_CLK
GP19 GP3 SPI_MOSI
GP20 GP4 SMC_DBG_EN
GP21 GP5 SMC_RST_XDK_N
GND GND GND

Debug UART Pinout (hax360 firmware only)

PicoFlasher by hax360 also has built-in UART reading functionality. This is for advanced users; if you just want to do NAND reading/writing, you can just ignore this section.

Kernel

Pico / Pico 2 RP2040 Zero Xbox
GP0 (UART0_TX) GP12 (UART0_TX) KER_DBG_RXD
GP1 (UART0_RX) GP13 (UART0_RX) KER_DBG_TXD

SMC

Pico / Pico 2 RP2040 Zero Xbox
GP4 (UART1_TX) GP8 (UART1_TX) SMC_DBG_RXD
GP5 (UART1_RX) GP9 (UART1_RX) SMC_DBG_TXD

Diagrams

Note that 15432's firmware uses the GP0 though GP5 pins instead of the ones on these diagrams.

Phat SPI (J1D1 & J2B1)

Diagram for Phat motherboards

Trinity SPI (J2C1 & J2C3)

Diagram for Trinity motherboards

Corona/Waitsburg/Stingray SPI (J2C1 & J2C3)

These can either be used for 4 GB or 16 MB NAND types if you're using PicoFlasher V4 or newer.

Diagram for Corona motherboards

15432's Firmware

Exclamation-circle-fill.svgDue to 15432's firmware being not as up to date as hax360's fork, 15432's firmware is now considered not recommended. The information has only been kept here for preservation.
Click "Expand" to accept the warning.

Pinout

Pico GPIO Xbox 360 Pinout
GP0 SPI_MISO
GP1 SPI_SS_N
GP2 SPI_CLK
GP3 SPI_MOSI
GP4 SMC_DBG_EN
GP5 SMC_RST_XDK_N
GND GND

Diagram

When using the PicoFlasher fork by 15432, you use the console's SMC programming header regardless of if the console has 4 GB or 16 MB flash memory.

15432 Picoflasher Diagram Corona.jpg

Reading the NAND

  1. Plug your Xbox 360 power supply in, but do not turn the console on. You can leave the RF board disconnected to prevent turning it on by accident.
  2. Plug the white end of the cable into the bottom port of the programmer. Plug the USB cable into the programmer and your PC.
  3. Launch J-Runner. Select "Read NAND" in the top left. It may prompt you for your Xbox 360’s model, make the correct selection and click OK. If everything is wired properly, it will read your NAND twice and automatically compare the dumps. If it says "Device Not Found" or anything about missing CB/CD files, see the troubleshooting steps at the bottom of this page. If you get messages about bad blocks, ignore them. When it has finished, it will tell you if the two dumps are an exact match. If they are, you can close J-Runner and proceed. If they aren’t, take more dumps until you get matching ones.
    • With 4 GB NANDs, a pane will open in the lower right, listing some removable drives. If everything is wired properly, one will show up as Removable Media.
  4. Copy both of the dumps to a safe place such as cloud storage or send it to yourself in an email to keep them safe. They are located in the output folder in the J-Runner directory.

(Phat Only) Checking your CB if it's JTAGable

This section is only if you have a phat Xbox 360 that has a dashboard/kernel version of 2.0.7371.0 or lower.

Open J-Runner and select "…" next to the Load Source field and choose the nanddump1.bin or nanddump2.bin file. On the right-hand side, note the value next to the 2BL [CB] label. If your CB is on the list below, your console is JTAGable. Any newer CB, which is not on the list, will be patched.

Model Exploitable CB Versions
Xenon 1888, 1897, 1902, 1903, 1920, 1921
Elpis 8192
Zephyr 4540, 4558, 4570, 4580
Falcon/Opus 5760, 5761, 5766, 5770
Jasper 6712 & 6723
Tonasket none

Writing XeLL to the NAND

Wb2k.jpg
Winbond W641GG2KB-14 RAM on an Xbox 360 E
  1. In J-Runner, select "…" next to the Load Source field and choose your nanddump1.bin or nanddump2.bin.
  2. Select the appropriate radio button in the top right of the window:
    • JTAG - For JTAG, R-JTAG, or R-JTOP.
    • Glitch - For RGH1.
    • Glitch2 - For RGH1.2, RGH2, RGH3, EXT_CLK, Muffin/Mufas, or S-RGH.
    • Glitch2m - Same as Glitch2 but only used if your eFuses are in a non-bootable state. Rather than using the real eFuses from the console's CPU, it uses virtual eFuses stored on the NAND instead.
  3. Put a check in the appropriate checkbox (if applicable) in the top right of the window:
    • If you are using JTAG, select JTAG and leave the R-JTAG checkbox disabled.
      • If you are using R-JTAG or R-JTOP, the R-JTAG checkbox would be enabled.
      • If you are not on a Xenon console, enable Aud_Clamp for either of these three modifications.
    • If you are using RGH1.2 or S-RGH, enable SMC+
    • If you are on a non-Xenon console with EXT_CLK, enable SMC+
    • If you are using Project Mufas, enable SMC+
    • If you are using RGH2 with an X360ACE, enable SMC+
    • If you are using RGH2 or RGH2+ with a CR3/CR4, enable CR4
    • If you are using RGH3, select RGH3
    • If you have an Xbox 360 E Stingray motherboard, enable WB 2K
      • Some Stingray motherboards use Winbond W641GG2KB-14 RAM, which is incompatible with older Corona bootloaders. This setting just installs a newer bootloader that's compatible with this new RAM type, which was already installed on Corona/Waitsburg through system updates. This means that it can also still be enabled on Xbox 360 S Corona/Waitsburg motherboards, though it won't gain any benefits. You can leave this setting disabled if you know your board has Samsung RAM, but if you forgot or are unsure, then just enable the option to be safe.
    • If you have an Elpis motherboard, enable Elpis
      • Many Elpis motherboards have Samsung RAM, which is incompatible with the Falcon bootloader that's used by default with Xenon Glitch2 images. This setting just installs an Elpis bootloader that's compatible with this new RAM and GPU configuration, which was already installed on refurbished/remanufactured Elpis motherboards from the factory. This means it can still be used on Elpises with Infineon/Qimonda RAM, though it won't gain any benefits. You can leave this setting disabled if you know your board has Infineon/Qimonda RAM, but if you forgot or are unsure, then just enable the option to be safe.
  4. Select the Create XeLL button and wait for it to finish.
  5. Select the Write XeLL button, select your system, and press OK. It will write the XeLL to the first 50 blocks of the motherboard's NAND.
    • If it says "Device Not Found" or Flash Config 0x00000000, see the troubleshooting steps at the bottom of this page.
  6. Once it has successfully written to the motherboard, unplug the power cable from your Xbox 360 and unplug the USB cable from the computer and programmer.
  7. Go back to the page you were originally on for wiring instructions.

Troubleshooting

  • "Device Not Found"
    • Re-insert the USB cable
    • Check that the drivers are properly installed
  • "Flash Config 0x00000000"
    • Check that your power brick is plugged in, with an amber colored LED, and that it is plugged into your console completely (console turned off).
    • Check your soldering to your motherboard. Each point should be solidly connected and have a shiny round joint.
    • Check that you’ve cleaned up any flux you had used. Depending on the type, it may be conductive and cause issues. MG 835 is strongly suggested to avoid this.
  • "Wrong Version"
    • Re-insert the USB cable
  • What should I do if I ripped off a soldering pad?
    • Look online for an alternate point to solder onto. Practice more on junk electronics before attempting to continue.

DirtyJTAG Usage

Make sure to download the latest J-Runner with Extras in order to use DirtyJtag.

  1. Flash the latest pico-DirtyJtag.uf2 to your Pico.
  2. Open Zadig and install the LibUSB-win32 driver to the device labeled DirtyJtag
  3. Use the following pinout for connecting your Pico to the glitch chip:

Pinout

TDI GPIO16 21
TDO GPIO17 22
TCK GPIO18 24
TMS GPIO19 25
GND 23
VCC 36

Diagram

DirtyJtag Diagram.png

Utilização como um Chip de Glitch

Não está claro como usá-lo como um chip de glitch mas foi demonstrado functionar como uma prova de conceito aqui.

While the RP2040 can be used to glitch a system, it has the major disadvantage of not being able to run in sync with STBY_CLK, which normal glitch chip designs can use. This means that the Pico cannot achieve the same rate of success as a normal glitch chip, and it can take more tries to successfully boot a system, especially with approaches requiring more precise timings, like EXT_CLK.