Smart homes are filling up with devices that promise to be trustworthy by design. Certified silicon, encrypted links and signed firmware: the modern smart device ships with an entire cryptographic identity baked into its flash memory. But what happens when an attacker does not attack the mathematics, and instead attacks the physical device itself?
This is the question we asked in our white paper "Trust Matters: Attacking Smart Device Authenticity", where Nozomi Networks Labs demonstrated how a fault injection attack against a commercial, Matter-certified smart motion sensor allowed us to bypass its debug protection, dump its firmware and extract the private key the device uses to prove that it is genuine.
Hardware attacks of this kind are never a one-shot affair. They demand a target you can power cycle thousands of times, probe, re-flash and break without regret, long before a single commercial device is put at risk. In this post we describe the piece of open hardware that made our research possible: a custom CW308 target board for the Nordic nRF52840, which we are releasing to the community together with its KiCad design files, a license and a disclaimer.
The CW308: a Common Denominator for Hardware Attacks
ChipWhisperer is the best-known open-source toolchain for side-channel power analysis and fault injection. Its capture hardware, however, is only half of the story: every attack needs a victim. Attacking raw evaluation boards is possible, but messy: power rails, reset lines and serial interfaces differ from board to board, decoupling capacitors smooth out exactly the power ripples a side-channel attack feeds on, and there is rarely a clean place to inject a glitch.
Enter the CW308 UFO board, released by NewAE Technology in 2016. The CW308 is a universal motherboard for embedded security research: it hosts interchangeable "victim" target boards that plug into three 20-pin female headers, and provides everything a target needs to be attacked in a repeatable way: multiple voltage regulators (1.2 V, 1.8 V, 2.5 V, 3.3 V, 5 V and an adjustable rail), a crystal driver with clock-routing jumpers that allow a glitched clock to be fed to the target, a 20-pin ChipWhisperer connector, JTAG headers and SMA connectors for power measurements. It can be used with ChipWhisperer capture hardware or completely stand-alone with an oscilloscope.
Target boards (the CW308T family) snap into the UFO baseboard like cartridges. Each one carries a specific microcontroller, wired to a standardized 60-pin connector that exposes power, clock, reset, a debug interface, UART and SPI lines, and, crucially for power analysis, a dedicated position for a shunt resistor in the supply path. Dozens of these target boards exist, from 8-bit AVR to ARM Cortex-M and even FPGAs. Their schematic and layout files are public, and NewAE encourages building your own.
Why the nRF52840?
Nordic Semiconductor's nRF52840 is everywhere. This single-chip SoC couples a 64 MHz Arm Cortex-M4F with 1 MB of flash and 256 KB of RAM, a multiprotocol 2.4 GHz radio (Bluetooth Low Energy 5, IEEE 802.15.4, Thread and Zigbee), a full-speed USB interface, an NFC-A tag and a CryptoCell-310 security accelerator, all in a 7×7 mm aQFN-73 package. It is one of the most widely deployed SoCs in smart home and IoT products, including the commercially available Matter devices we examined in our research.
Matter is the Connectivity Standards Alliance' flagship smart home standard, and it leans heavily on device attestation: every certified device carries a Device Attestation Certificate (DAC) and protects its private key, so that a commissioner can verify that a device is genuine before letting it into a Matter fabric. Protecting that key is left to each manufacturer. When the protection relies on disabling the SoC's debug port (Nordic's APPROTECT mechanism), a well-known voltage glitching vulnerability, documented in Nordic's advisory IN-133, can bring the debug interface back to life.
That is exactly the class of attack we published in "Trust Matters", and exactly why we needed a controlled nRF52840 platform on our bench.
Standing on Shoulders: Our Take on the CW308T-nRF52840
When we set out to build our target, we discovered that NewAE's GitHub repository for CW308T targets (chipwhisperer-target-cw308t) already contains a CW308T_NRF52840 folder, but the project is clearly unfinished: it ships schematic PDFs and gerbers with no documentation, and their own README warns that some boards are untested and provided at your own risk. We therefore took their design as inspiration, studied their approach, and designed our own PCB from scratch in KiCad, with a different EDA toolchain, different footprints (all chosen to be hand-solderable) and a number of additions of our own.
Since our board is an independent reimplementation rather than a copy of NewAE's files, this kind of inspiration is legitimate: NewAE's design carries a GPL notice on its schematic title block, the CW308 target interface itself is an openly documented standard meant to be extended by the community, and we credit NewAE prominently for both the platform and the idea. To keep the chain of openness intact, we are releasing our own design under the CERN Open Hardware Licence Version 2, Strongly Reciprocal (CERN-OHL-S v2), a copyleft license designed specifically for hardware, so anyone can use, study, modify and re-share the board under the same terms.
Inside the Board
Our target follows the CW308T "must-have" checklist from NewAE's design guidelines, adapted to the nRF52840:
- A standardized connector. Three 1×20, 2.54 mm pin headers reproduce the 60-pin CW308 victim-board interface: clock in and out, nRST, GPIO1–4, SPI (SCK/MISO/MOSI), the VREF/JTAG row, the five buffered LED lines and the shunt-measurement pins (SHUNTH/SHUNL), plus all the grounds. Any CW308 practice, including the ChipWhisperer tooling built around it, simply works.
- A real shunt for power measurement. A 12 Ω resistor sits in the classic UFO shunt position, with low-noise routing and decoupling on both sides, so the capture hardware can measure the target's current consumption as a voltage drop, the raw material for both side-channel analysis and glitch detection.
- A power network designed to be attacked. Decoupling follows the Nordic reference design, but selected capacitors are deliberately left unmounted (DNP), in the spirit of NewAE's targets: fewer reservoirs between the injector and the silicon means cleaner, more reproducible glitches.
- Clock control. An onboard 32 MHz crystal feeds the MCU, but the CW308's CLKIN line is AC-coupled and terminated straight to the crystal pad behind a solder jumper: close the jumper and the ChipWhisperer can drive, or glitch, the chip's high-frequency clock. A second resistor routes the chip's own clock back out on CLKOUT for synchronization and monitoring.
- Debug and trigger. SWDIO, SWDCLK, SWO and nRST are wired to the CW308's JTAG row, and GPIO4, the standard CW308T trigger pin, is available for synchronizing captures with the target's activity.
- A radio you can measure. The 2.4 GHz antenna pin is matched with a minimal discrete network (two 1 pF shunt capacitors and a 3.9 nH series inductor) into a U.FL connector, so the board can drive a real antenna or be connected directly to a spectrum analyzer or a controlled RF source.
- Room to grow. The NFC1/NFC2 pins (P0.09/P0.10, usable as GPIOs) are broken out both on a pin header and on a 5-way FFC connector; GPIO1/2 provide a UART, and five extra GPIOs (HDR1–5) reach the CW308's generic header rows. Three mounting holes keep the board locked down under an EM probe.
Every component is mounted on hand-solderable 0603/0402 footprints, because a board that researchers need to hack, rework and sometimes un-modify should not require a reflow oven.


How This Board Made Our Research Possible
This little board is not a hobby project that happens to exist alongside our work: it is one of the foundations of the research we published in "Trust Matters: Attacking Smart Device Authenticity".
In that white paper, we attacked a commercially available, Matter-certified motion sensor built around the nRF52840. The vendor had protected the device by disabling the SWD debug port through Nordic's APPROTECT mechanism and by encrypting and obfuscating the DAC private key in firmware. Using a voltage glitching (crowbar) attack timed to the boot sequence, we skipped the very instruction that disables the debug port, re-enabled SWD, dumped the entire 1 MB of flash and, after reverse engineering MCUBoot, Zephyr OS and the vendor's custom obfuscation routine, recovered the DAC private key in clear text, the key that would let a malicious actor commission rogue devices into a Matter fabric as if they were genuine, certified products.
None of that would have been practical without this target board. The commercial sensor was a scarce, soldered-shut resource: every failed experiment risked a dead sample and a dead end. The CW308T-nRF52840 gave us the same silicon (same core, same package, same boot-time behavior) on a board we could power cycle freely, probe, and break without consequences. On it we characterized the glitch window, tuned the glitch width and timing offsets, validated the SWD recovery procedure, and rehearsed the exact measurement setup (oscilloscope on the power rail, trigger synchronization) that we later transferred to the real device, where we identified the equivalent injection point on its PCB. In other words: the board turned a one-shot, high-stakes attack on a consumer product into a methodical, repeatable experiment.
Releasing the Design
The complete project (KiCad schematics and layout, gerbers, pick-and-place files and the bill of materials) is being released on GitHub together with:
- a LICENSE file adopting CERN-OHL-S v2, so that anyone can use, study, modify and re-share the design under the same reciprocal terms, and
- a DISCLAIMER file stating clearly that the Design is provided "as is", for research and educational purposes only, that hardware attacks can permanently damage devices and must only be performed on equipment you own or are authorized to test, and that the project is not affiliated with or endorsed by NewAE, Nordic Semiconductor or any other vendor.
Our board stands on the shoulders of the ChipWhisperer ecosystem: our thanks go to NewAE Technology for the CW308 platform and for publishing their unfinished nRF52840 target, which gave us a head start, and to the broader community of researchers whose open tools make this kind of work possible.
Conclusion
Side-channel analysis and fault injection are no longer academic curiosities: they are practical techniques against the chips that populate our smart homes and critical infrastructure. Studying them properly requires targets that are open, repeatable and honest about their power behavior, which is exactly what the CW308 platform provides, and what our nRF52840 target board delivers on top of it.
If you are reproducing the attack described in our white paper, exploring glitching on Nordic silicon, or simply looking for a robust BLE-capable victim for your ChipWhisperer, we hope this board saves you the weeks of design work it saved us. Follow the Nozomi Networks Labs blog for follow-up research and use the design responsibly.




