PS3 qCFW - Arrives to Slim (2500-3000) & SuperSlim (4000-NOR) PlayStation 3 Models

Major Updates

.
Original Article (Jan. 30): The evolution of PlayStation 3 (PS3) exploits rides high in 2026, In early-mid 2025 we seen developer and researcher @aomsin2526 (aka Chattrapat Sangmanee) show us a hardware exploit that provided some additional power to PS3HEN with the disclosure of the BadHTAB hardware exploit. The hardware exploit was soon replaced with another hardware exploit also from @aomsin2526 that we know as BadWDSD. While BadHTAB provided some additional functionality to PS3HEN like OverClocking & Linux Support. BadWDSD would proved to be the better foundation needed for what would become the next phase of the overall project.

Focusing now on the software side, the next phase from @aomsin2526 came in the form of a "qCFW" , this was a CFW that was built using Evilnat 4.92 PEX for the late Slim (2500) / SuperSlim (NOR) model PS3 Console's !!! While PS3HEN provided those once dubbed "nonCFW models" with many CFW like feature's, there were a number of abilities that were restricted to only CFW user's. Now with the release of BadWDSD with qCFW that gap has shrunk considerably to where 99% of CFW task can now be done on a qCFW installation. The process for installation of a qCFW is different then the traditional PUP installation of a Firmware, but you will still be running what is essentially a ("quasi") custom firmware running the cobra payload and based off Evilnat PEX CFW. Allowing for even DEX features on a SuperSlim (NOR) + Slim (2500).

PS3HEN developer @esc0rtd3w also had some work in this project as PS3HEN is essential in the installation/operation of qCFW/BadWDWD. You must be running v 3.4.1 Beta-test #4 or higher for support of the latest qCFW installation. Checkout this hardware/software modification that will supercharge thoseSlim 2500/3000 & Superslim (NOR) models. Take note of your SuperSlim model as the eMMc models are not supported.

i-have-built-the-ultimate-ps3-super-slim-v0-6vggxy2we1ac1.jpg ps3_white_Superslim.jpg
  • Always view official link for latest updates: https://github.com/aomsin2526/BadWDSD

    .
    BadWDSD












    .
    This is a hardware modchip for Sony PlayStation 3. By using Raspberry Pi Pico (RP2040), It is possible for non-CFW compatible models to boot qCFW.​

    Supported models
    • All CECH-2500
    • All CECH-3000
    • CECH-4x00 with NOR flash
    • 540772857-7066c760-a097-45ba-9697-6022c9cf1e07.png

    Models not Supported
    • CECH-4x00 with eMMC flash is NOT supported
    • 540773712-6592b99e-f80f-4319-a450-10a894aa5164.png

    Notice:
    1. One way to know if your console is eMMC or not is enter safe mode. If you see Change system storage option, It is eMMC.
    2. Other way is try to install Stagex. If it says Flash is not NOR then it is eMMC.












    • .What is qCFW?










      .You still can't install CFW PUP, so new variant of CFW must be made. This is called quasi-CFW.
      It is heavily based on Evilnat PEX CFW. And will support every feature except: Dumping eid_root_key and anything that needed it.

      Note: Cobra must be active at all times or some feature will not work properly.

      qCFW quirks
      • For some unknown reason, When you turn on the console using wireless controller it won't sync. You must power cycle the controller for it to sync.

      Note on DEX mode
      • DEX mode is fully supported. But any kind of firmware installation or update is not possible while in this mode.
      • This means if you somehow need to reinstall the firmware such as corrupted HDD, you are stuck.
      • To recover, use BANKSEL pin on the modchip to go back to OFW.

    • Installation (Software)

      .
      FOR FIRST INSTALLATION, BACKUP FLASH FIRST!!!.

      IF SOMETHING GOES TOO WRONG AND YOU DON'T HAVE BACKUP, YOUR CONSOLE
      MAY BE PERMANENTLY BRICKED

      1. Prepare the USB drive by DELETING old qcfw folder if existed, DO NOT OVERWRITE!! then download qCFW and extract it into your drive like this:
      1. Install PS3HEN 3.4.1 or later
      2. Plug your USB drive into RIGHTMOST USB port of your ps3
      3. On XMB, Enable HEN then use Network -> Hybrid Firmware Tools -> qCFW Options -> Install Stagex option. It must show Success
      4. If not already, Install the modchip by following Installation (Hardware) section
      5. After modchip installed and power plugged in, wait until LED of modchip becomes solid. If it doesn't solid after a while, check SC_RX/SC_TX wire
      6. Turn on the console. modchip LED should flash briefly with triple beep right after. This means exploit is successful. If your console keep turning off and on, check CMD/CLK wire and Stagex
      7. You should be on XMB now. now Enable HEN then use Install qCFW option
      8. If it tell you to reinstall firmware and try again, do it ONCE.
      9. Your screen will appear frozen. it is installing. This process take 10-20 minutes. If something goes wrong during this step, you should be still able to recover by entering safe mode and reinstall firmware normally
      10. Then it will reboot itself. you should be on qCFW and see Evilnat logo now.
      11. Congrats! qCFW installation is complete
      • From now on, modchip will be required to boot the console until you go back to OFW again
      • This can be done by reinstalling OFW/HFW firmware normally. Then after this you can disable or uninstall the modchip
      • If thing goes too bad to the point of not being able to enter safe mode at all, you can use BANKSEL pin instead.
      • If you flashed bad Stagex.bin or CoreOS.bin, see Recover from bad Stagex.bin or CoreOS.bin flash section.
      Installation (Hardware)

      .Currently, Raspberry Pi Pico (RP2040) and RP2040-Zero are supported.
      • Only install modchip after Stagex is installed to console flash from above section.Otherwise it won't boot,
        • if you already installed the modchip, You can use HOLD pin to temporary disable the modchip without unsoldering it.

      Since I don't have 2500 and 3000 model to test, it must be done by other people. If you know the solder location please tell me. Thanks.


      Pico
      RP2040-Zero
      3000
      4x00

      • To flash .uf2 file (it is included in qCFW zip), simply connect modchip USB port into your PC while pressing BOOTSEL button. Then new drive will appear, simply drag .uf2 file into it.
      • You should see LED blinking. Flash successful and ready to use. You can disconnect it from your PC.
      • Exclude power and ground, you only need to solder 4 wires that marked red (CMD, CLK, SC_RX, SC_TX). Other pin is optional.
      • It is possible to power the modchip using external power as long as it is active during ps3 standby

      Pin description
      SIGNAL PIN:
      CLK - XDR CLK signal
      CMD - XDR CMD signal
      SC_TX/SC_RX - Syscon UART signal
      DEBUG - Optional modchip UART signal, for debugging and accessing syscon (baud 576000, NOT 57600!)
      CONFIG PIN:
      Short to ground to activate
      HOLD - Disable the modchip without needing to remove power or unsolder
      LITE - TODO
      BANKSEL - Go back to OFW forcefully. It is equal to syscon command w 1224 00. Only use when absolutely needed. You can't turn on the console while this pin is shorted​

    • Update qCFW
      • You can't update qCFW while on qCFW. you must go back to OFW first.
      • Simply reinstall firmware normally, then use Install qCFW option with updated files on USB again. No need to do anything else
      • When updating files on USB, delete whole qcfw folder first. Don't overwrite or it may causes problem.


      Go back to OFW using PUP method (Recommended)
      • Always use this method when possible. Simply reinstall firmware as normal. No extra steps required.
      • If you want to uninstall the modchip, you can do so after this


      Go back to OFW using BANKSEL pin
      Avoid this unless absolutely needed.
      DO NOT GO STRAIGHT TO THIS PIN WITHOUT TRYING TO BOOT THE CONSOLE WITHOUT MODCHIP FIRST!, IF IT SHUT IFSELF OFF, THEN YOU CAN FOLLOW BELOW

      1. Unplug your console
      2. Short BANKSEL pin to ground
      3. Plug in your console, wait until modchip LED flashes very fast. Then it is successful. You can't turn on the console while this pin is shorted
      4. Unplug your console and unshort the pin. If necessary remove or use HOLD pin to disable the modchip
      5. Plug in your console again and turn it on, you will likely to get black screen. This is expected since dev_flash is still qCFW but you're on OFW now
      6. Enter safe mode and reinstall firmware normally to get full recovery

      Recover from bad Stagex.bin or CoreOS.bin flash
      • No worries, your console isn't really bricked.
      • FIRST, disable the modchip then try to boot the console if it boots then all is good.
      • If it shut itself off, Simply follow Go back to OFW using BANKSEL pin section above. But this time disable modchip before boot as well.

      Downgrading
      • After booting the console with modchip, It is possible to downgrade the firmware up to 4.80. It can't be done in XMB. You must use safe mode.

    • OtherOS
      It is different from CFW. Simply follow these steps.
      1. Download dtbImage.ps3.zfself and put it into root of your USB drive
      2. Plug your USB drive into RIGHTMOST USB port of your ps3
      3. On XMB, use Network -> Custom Firmware Tools -> OtherOS Tools -> Install OtherOS (qCFW) option. It should show Success
      4. Use Boot OtherOS (qCFW) option. It should enter petitboot right away

      Accessing Syscon
      You can't access syscon the old ways anymore. It must be done through modchip. Simply connect DEBUG pin of modchip into your UART adapter.


    • NoBT
      • TODO. It requires LITE pin and hardware flasher for first installation if you are already on update loop.

      eMMC Support?
      In very short summary, What modchip is doing is writing these code into ram at boot:
      Code:
      stage_entry:
          // Jump to 0x2401F031000, aka 0x31000 on NOR flash where Stagex.bin is stored
      
          bl 4
          mflr %r3
          addi %r3, %r3, -4
          ld %r4, 24(%r3)
          mtctr %r4
          bctr
      
          .quad 0x2401F031000

      Do we have something like 0x2401F031000 on eMMC? If answer is yes, then eMMC can be supported (with more porting work).

  • Always view Official Link for latest updates:
    via esc0rtd3w > PS3HEN 3.4.1 has been released!

    If you have Auto Updates turned on, then HEN will automatically update the next time its enabled. If not, use whatever other method of your choosing to update. The ps3xploit.me site has been updated.

    CHANGELOG
    HEN Plugin Changes

    • Added detection of BadWDSD via LV1 peek check on hen enable (thanks aomsin2526)
    Payload Changes
    • Enabled LV1 peek and poke to support BadHTAB and BadWDSD exploits (thanks aomsin2526)
    • Added conditional timer for Retail and NPDRM self to reduce hanging when launching homebrew (thanks Joonie, aomsin2526)
    • Added support for 3k3y/Redump ISOs on-the-fly (thanks Joonie, Evilnat)
    Resource Changes
    • Added support for installing qCFW with xai (quasi-CFW for NOR 3000x and SS) (thanks aomsin2526)
    • Added BD Game Disc Fix (thanks LuanTeles)
    • Now using fork of Evilnats xai plugin as base to take advantage of updated features (thanks Evilnat)

  • qcfw-20260220-release
    Based on Evilnat 4.92.2 PEX

    qCFW Changelog:

    • Stagex code improvements
    • Implement controller sync workaround. If you turn on the console using controller while on qCFW it will always power cycle once first (.uf2 must be updated)
    • Fix a loophole that can made BANKSEL useless under certain circumstance
    .uf2/Modchip Changelog:
    • Code improvements
    • Better self retry/power cycling
    • Handle controller sync workaround
    • Modchip now runs at stock clock speed (no longer overclocked)

    .uf2 update is optional but RECOMMENDED or controller sync workaround may not work properly.

Project Links
 
Last edited:
This did not happen to me, Super Slim CECH-4200C
@Louis Garry : pourriez-vous me fournir des photos des points de soudure que vous avez utilisé car je possède une CECH4204C ainsi qu'une CECH4004C. Faut-il que je vous donne le modèle des cartes mères de ces PS3 ou non ? Merci par avance.
@Louis Garry: Could you provide me with photos of the solder points you used, as I have a CECH4204C and a CECH4004C? Do I need to give you the motherboard models of these PS3s or not? Thank you in advance.
 
Savez-vous où je peux trouver ces photos s'il vous plait ?

Do you know where I can find these photos, please?
 
@Louis Garry :
Je viens de consulter ces 2 photos mais il n'y a pas les points où souder les différents fils 3,3v; 5v; GNG et les deux autres ? Où sont-ils SVP ?

I just looked at these two photos, but the points where the different wires (3.3V, 5V, GNG, and the other two) are soldered aren't shown. Where are they, please?

Hi,

Work done,

Found the clue : it was clk resistor, slightly broken, when pushing the probe to test i got the 55.5 ohms...while on the wire other side 1.46 Mohms...something stupid as always...

here's my wiring, everything went fine qCFW installed and working great.

Thanks aomsin for the work.
If i can help in anyway it'll be a pleasure.

Motherboard :KTE-001 / CECH 3004B
Salut @Yoplay :

Toutes les CECH 3004B ont elles des cartes mères KTE-001 ? Si c'est oui, alors je vais pouvoir mettre en place le qCFW sur cette console. Pouvez-vous me le confirmer SVP ?

Do all CECH 3004B consoles have KTE-001 motherboards? If so, then I'll be able to install qCFW on this console. Can you please confirm this?

Question complémentaire : La régulation de température avec webMAN-Mod est-elle sur statique ou sur variable chez vous (chez moi, elle est sur variable uniquement sur console en CFW) ?

Follow-up question: Is the temperature regulation with webMAN-Mod static or variable on your system (on mine, it's variable only on console with CFW) ?
 
Last edited by a moderator:
Je confirme : tous les modèles cech 3004 A/B ont une CM kte-001...

"For sure" all CECH 3004 A&B got KTE-001 motherboard...

En dynamique avec température de consigne a 60°...

Variable mode on mine with max température 60°.

Some user (very few) said that sometimes qCFW randomly reboot itself to recovery mode (System cannot be run correctly) If they just reboot it it will work as normal.

But if user try to reinstall firmware while on that screen it will brick.

qCFW should be 100% stable. Such random reboot should never happen.

Crazier part is the brick part, this made no sense in anyway. Since firmware updater is identical to safe mode and xmb. I also install firmware on recovery mode myself (That is how downgrading is done in early days before we are able to enter safe mode).

And I update the firmware this way countless of time.
No such bricks happen. Even people in the group.

Since I can't reproduce the problem myself, I can only guess what I can do.

So I made a new build testing it in the group and hope that problem is gone.

I'm waiting for flash dump and logs from user to investigate.


I got this kind of problem too...i think old HDD maybe guilty i checked mine on pc ....many unstable sectors...manage to install qCFW anyway...but when i install pkg some work and install but others won't install or install and console shutdown (no light) with a loud noise on HDD side...

Happens only on CECH 2504, my CECH 3004 work like charm, no bugs no reboot but got brand New SSD...
 
Last edited by a moderator:
i need help i tried installing a pico modchip on my cech 3001a ps3 slim but when my ps3 booted into xmb it was blinking like the modchip did not saw my console, i even tried rewiring the sc wires and the clk and cmd wires but to avail. and i also tried measuring both the clk wire and the cmd wire with a multimeter on the on the opposite of the wire and it did got around 55 ohms so i am confused and i need help. well im gonna provide some pictures ignore my horrible kapton tape job, im going to redo it once i get it working, and if all fails im just going to uninstall it
 

Attachments

  • 20260212_165644.webp.png
    20260212_165644.webp.png
    479.8 KB · Views: 89
  • 20260212_165635.webp.png
    20260212_165635.webp.png
    572.3 KB · Views: 86
  • 20260212_165628.webp.png
    20260212_165628.webp.png
    581 KB · Views: 99
Je confirme : tous les modèles cech 3004 A/B ont une CM kte-001...

"For sure" all CECH 3004 A&B got KTE-001 motherboard...

En dynamique avec température de consigne a 60°...

Variable mode on mine with max température 60°.




I got this kind of problem too...i think old HDD maybe guilty i checked mine on pc ....many unstable sectors...manage to install qCFW anyway...but when i install pkg some work and install but others won't install or install and console shutdown (no light) with a loud noise on HDD side...

Happens only on CECH 2504, my CECH 3004 work like charm, no bugs no reboot but got brand New SSD...

Your HDD is clearly dying...

Replace HDD then try again

i need help i tried installing a pico modchip on my cech 3001a ps3 slim but when my ps3 booted into xmb it was blinking like the modchip did not saw my console, i even tried rewiring the sc wires and the clk and cmd wires but to avail. and i also tried measuring both the clk wire and the cmd wire with a multimeter on the on the opposite of the wire and it did got around 55 ohms so i am confused and i need help. well im gonna provide some pictures ignore my horrible kapton tape job, im going to redo it once i get it working, and if all fails im just going to uninstall it

Did you try swapping SC_TX/RX point at least? This is very common mistake.
 
@aomsin2526 I managed to install QCFW on my PS3 Super Slim running 4.85 HFW without a Bluetooth module.
I connected the debug pins and accessed the Syscon using Termite software. By running the command, I read the value at offset 48C24 as 'FF,' which I believe was the reason I previously couldn't install CFW and was prompted to "reinstall firmware then retry". I then dumped the firmware and used DumpChecker to confirm that both ros0 and ros1 are on version 4.85. Consequently, I used the Syscon command w 48C24 00 to force a bank switch. After rebooting and reinstalling HEN, the QCFW was able to install this time.​
The installation process went smoothly; the screen froze, hard disk yellow lignt blink and after waiting for about 5 minutes, it rebooted. However, it has been stuck on a black screen since the restart. Is it because I cannot install it directly on top of the 4.85 firmware?It can only install from 4.92?
 
@aomsin2526 I managed to install QCFW on my PS3 Super Slim running 4.85 HFW without a Bluetooth module.
I connected the debug pins and accessed the Syscon using Termite software. By running the command, I read the value at offset 48C24 as 'FF,' which I believe was the reason I previously couldn't install CFW and was prompted to "reinstall firmware then retry". I then dumped the firmware and used DumpChecker to confirm that both ros0 and ros1 are on version 4.85. Consequently, I used the Syscon command w 48C24 00 to force a bank switch. After rebooting and reinstalling HEN, the QCFW was able to install this time.​
The installation process went smoothly; the screen froze, hard disk yellow lignt blink and after waiting for about 5 minutes, it rebooted. However, it has been stuck on a black screen since the restart. Is it because I cannot install it directly on top of the 4.85 firmware?It can only install from 4.92?

I already said "Nothing you can do for now" Yet you are doing it anyway.

Try enter safe mode to reinstall firmware, if cobra payload is active then it should succeed.

You are pretty much bypassed anti-brick measure.

This means if safe mode doesn't work then you are bricked. Only way to recover is hardware flasher. No other way. That bank check exist because it want you to switch bank the natural way (Normal update). Not syscon hack like this. With hacky methods like this you are no longer able to boot without modchip as well.

Because ros0 has been replaced with qCFW. And that is also active bank "hash" on syscon.

In normal usage active bank hash must be ros1. Can only switched by firmware updater. Not syscon eeprom.
 
Last edited:
I already said "Nothing you can do for now" Yet you are doing it anyway.

Try enter safe mode to reinstall firmware, if cobra payload is active then it should succeed.

You are pretty much bypassed anti-brick measure.

This means if safe mode doesn't work then you are bricked. Only way to recover is hardware flasher. No other way. That bank check exist because it want you to switch bank the natural way (Normal update). Not syscon hack like this. With hacky methods like this you are no longer able to boot without modchip as well.

Because ros0 has been replaced with qCFW. And that is also active bank "hash" on syscon.

In normal usage active bank hash must be ros1. Which is can only switched by firmware updater. Not syscon eeprom.
Yeah, I just wanted to give it a shot. I have an E3 Flasher and I've already made backups, thanks for the heads-up. :) Fortunately, I was able to switch back to the other bank via syscon. The console automatically entered recovery mode upon boot, allowing me to reinstall 4.85 HFW. It still got stuck in an update loop, but I used the HDD hot-swap method to bypass it and successfully restored the 4.85 HFW system. Is there another way to install qcfw thru hardware flasher?
 
Je confirme : tous les modèles cech 3004 A/B ont une CM kte-001... "For sure" all CECH 3004 A&B got KTE-001 mother...

En dynamique avec température de consigne a 60°...
Mode variable sur le mien avec température max 60°.

Merci mon ami, je te remercie énormément pour tout ceci.
Mais je peux aussi t'aider et te fournir gratuitement un DD Sata de 250Go en parfait état (vérifié). Seul le port sera à ta charge. Passe en MP si tu le désires. Ce n'est pas un SSD !!!

Thank you, my friend, I'm so grateful for all of this.
But I can also help you and provide you with a 250GB SATA hard drive in perfect condition (verified) for free. You'll only have to pay for shipping. Message me privately if you'd like.

Algol "le papy".
 
Yeah, I just wanted to give it a shot. I have an E3 Flasher and I've already made backups, thanks for the heads-up. :) Fortunately, I was able to switch back to the other bank via syscon. The console automatically entered recovery mode upon boot, allowing me to reinstall 4.85 HFW. It still got stuck in an update loop, but I used the HDD hot-swap method to bypass it and successfully restored the 4.85 HFW system. Is there another way to install qcfw thru hardware flasher?

Yes, I will made a new thread about this later.

It seems since public release this mod get a lot of hate from many places.

Which is very demotivating. I'm not sure why I'm doing this anymore.

You can get your E3 setup ready first.
 
Yes, I will made a new thread about this later.

It seems since public release this mod get a lot of hate from many places.

Which is very demotivating. I'm not sure why I'm doing this anymore.

You can get your E3 setup ready first.
Yeah, I've noticed that too. There are people on Reddit who follow almost every thread about badwdsd just to scream about how 'risky' it is. I honestly don't get it—doesn't every mod involve risk? Do they really think we need to be reminded like we're seven-year-olds?
Adults are perfectly capable of deciding what they want to do for themselves, rather than mindlessly trashing the hard work someone else has put in. I'm incredibly grateful for everything you've done. I've been following this mod since day one about half year ago, and it's been a blast for me. I'll keep supporting you no matter what—and as for the haters, they can go to hell.​
 
@aomsin2526 : Les gens qui te critiques sont des idiots, ils ne savent pas combien de temps il faut pour en arriver là où tu en es. Moi je te remercie énormément même quand tu ne fais qu'aider ceux qui ont des soucis avec leurs installations. La critique est très facile mais l'art est fortement difficile. Tu es, pour moi, un excellent modeur, chercheur et je t'en remercie encore une fois.

Algol "le papy".

The people who criticize you are idiots; they don't know how long it takes to get where you are. I thank you immensely, even when you're just helping those who have problems with their setups. Criticism is very easy, but art is extremely difficult. You are, in my opinion, an excellent modder and researcher, and I thank you again.
 
For me, it's working very well and there are no bugs. I fixed the procedure on 3 Super Slim models. Working without problems! The chip installation should preferably be done using enameled wires. I did it using headphone wires, the QCFW is working very well and the functions too, download etc...
 

Featured content

Trending content

Back
Top