Security

Hack Nintendo's alarm clock to show cat pics? Let's-a-go!

How 'Gary' defeated Bowser broke into the interactive alarm clock


A hacker who uses the handle GaryOderNichts has found a way to break into Nintendo's recently launched Alarmo clock, and run code on the device.

Nintendo bills Alarmo as a way to "make waking up fun" – a tall order. The clock looks like a cartoony take on a vintage, red round alarm clock, but with an interactive screen.

Alarmo plays sounds and music from Nintendo's signature games to rouse owners from their slumber – which honestly sounds like a whole new level of Hell. But apparently, a lot of people are willing to pay $99.99 to have Bowser's angry face staring at them if they don't leap out of bed.

Upon receiving his shiny, new device, Gary opened up the Alarmo – which required removing a single screw next to its USB-C port.

Gary was already aware of posts by graduate computer science researcher Naomi Smith, known as Spinda on X, who had already found Serial Wire Debug (SWD) pins on the device's board. Smith had also been poking the Alarmo for exploitable holes and wrote code to dump the embedded multimedia card (eMMC) – which contains an encrypted content folder with files for each of the video game themes, a system file, a factory file, and a file called 2ndloader.bin.

Using Spinda's findings, his own research, a Raspberry Pi connected to the SWD pins, and with assistance from the vulnerability researcher Mike Heskin (aka hexkyz), Gary found and exploited a vulnerability in the cryptographic processor's interface, then obtained the AES-128-CTR key used to encrypt and decrypt the Alarmo content files. Using the newfound visibility the key afforded, he was able to figure out the device's boot process and load firmware binaries over USB. This was how he created and ran his custom payload that displays a cat picture.

Gary has shared his testing USB payload (the cat picture), along with a project that allows anyone to brute-force the Alarmo's AES key. So we may be seeing some interesting Alarmo custom code being developed and deployed in the near future.

The Register sought comment from Nintendo to inquire whether the Super Mario shop maker is aware of the hack being used for other purposes. We didn't immediately receive a response, but will update this story if and when we do.

If you want to see the cat photo, here it is. We can't think of a better post-Halloween treat. ®

Send us news
21 Comments

Wanted. Top infosec pros willing to defend Britain on shabby salaries

GCHQ job ads seek top talent with bottom-end pay packets

Just how private is Apple's Private Cloud Compute? You can test it to find out

Also updates bug bounty program with $1M payout

Five Eyes nations tell tech startups to take infosec seriously. Again

Only took 'em a year to dish up some scary travel advice, and a Secure Innovation … Placemat?

Windows Themes zero-day bug exposes users to NTLM credential theft

Plus a free micropatch until Redmond fixes the flaw

Sophos to snatch Secureworks in $859M buyout: Why fight when you can just buy?

Private equity giant Thoma Bravo adds another trophy to its growing collection

The billionaire behind Trump's 'unhackable' phone is on a mission to fight Tesla's FSD

Dan O'Dowd tells El Reg about the OS secrets and ongoing clash with Musk

Millions of Android and iOS users at risk from hardcoded creds in popular apps

Azure Blob Storage, AWS, and Twilio keys all up for grabs

Beijing claims it's found 'underwater lighthouses' that its foes use for espionage

Release the Kraken!

Perfctl malware strikes again as crypto-crooks target Docker Remote API servers

Attacks on unprotected servers reach 'critical level'

Merde! Macron's bodyguards reveal his location by sharing Strava data

It's not just the French president, Biden and Putin also reportedly trackable

Brazen crims selling stolen credit cards on Meta's Threads

The platform 'continues to take action' against illegal posts, we're told

AWS Cloud Development Kit flaw exposed accounts to full takeover

Remember Bucket Monopoly? Yeah, it gets worse