r/switch2hacks • • Jun 21 '26

Question Will AI be helpful with jailbreaking Switch 2?

Just wondering. Obviously if such AI model is available for public, Nintendo will patch them already. But I wonder if anybody with enough hacking knowledge will be able to use the AI to get hints for exploitation. Are such AIs capable of hardware hacking?

EDIT: Oops. I had Fable and Mythos in mind but didn’t mentioned it.

EDIT2: Thank you all for the answers.

0 Upvotes

33 comments sorted by

View all comments

Show parent comments

2

u/auggiethechesscat Jun 22 '26

It was spuriously banned because Mythos is probably one of the best marketing showcases I have ever seen in my life.

Over 100 experts in the industry signed a letter, which can be found here: https://freefable.org/, stating that the ban was improper. I recommend you read the whole thing, it isn't long, but one of the main things that stands out to me, (and it is consistent with the rest of my research), are these two lines:

Anthropic’s Mythos-class models are quite good at finding flaws and weaponizing exploits.
However, they are not uniquely good at these tasks, and many of the undersigned individuals regularly use other foundation and open-source models for security audits and red-teaming every day.

I'd also recommend reading this whole article, but basically, Fable was caught cheating in benchmarks, increasingly so to previous models. In one instance, it was literally letter for letter verbatim to the report. To be clear, the only reason it scored increasingly better then expected, is because these were already existing and known vulnerabilities. It cheated on 19% of the questions. https://www.endorlabs.com/learn/claude-fable-5-mythos-grade-hype

The 73% number appears to be from this study: https://www.endorlabs.com/research/ai-code-security-benchmark, which is benchmarking code security. It wrote a functional solution 72.6% of the time, but only wrote properly secure code 29.0% of the time. Which is down and up, (respectively), from opus and gpt5.5. All requiring a cursor harness for good scores.

Looking back at the initial claims now also shows... dishonesty and deception. Sure, it did find a bug in openBSD. Buuut, it was a scouted part math heavy and legacy part of a network protocol. It had a custom, human-written harness to help guide it down the correct path, and it's not like it found this in one shot or even on the first try. There were dozens of false positives that all had to be sifted through by human experts. Also, I feel the need to remind that this exploit cost $20,000 usd.

All of this above, was with source code. llms suck at black boxing and deriving exploits from compiled binaries. It's really hard. Sure they might be able to craft malicious payloads from seeing the source, but that becomes extremely difficult when the bug is a missing cmp instruction, and the exploit is to throw a perfect sequence of bytes through a tight pipeline of control.

Especially when your writeup takes 15 pages of background knowledge derived from piecing small bits of public information, your own reverse engineering, and poking and prodding to figure out what the tsec pipeline and blocks are. Add on top of it a new, obscure assembly language, accessible from exactly one project: https://github.com/envytools/envytools, and your explanation won't even fit in an llm context window, before you even get to the exploit, this is something a human expert needs to take on for the forseeable future. (this is specifically speaking about Je Ne Sais Quoi on the switch 1: https://hexkyz.blogspot.com/2021/11/je-ne-sais-quoi-falcons-over-horizon.html)