DC34 badge
node://dc34-badge
The official DEF CON 34 conference badge is a Baochip-1x SoC running Xous OS, with vault and console firmware in Rust. I own one. The badge team publishes the source, solicits vulnerability reports, and treats key extraction as an in-scope CTF-style goal.
I mapped the attack surface from that public source: token and secret provisioning, CTAP/FIDO paths, and how the bootloader treats development images. The write-up stays in my vault. Confirmed findings go to the badge team, not onto other people's hardware.
This is separate from the AND!XOR 5n4ck3y badge CTF — different badge, different puzzle, different page.