She Found a Bricked Cricut in E-Waste and Unlocked It with a $1 Raspberry Pi Chip
In July 2026, Australian security researcher xssfox was taking out the rubbish when she spotted a Cricut Maker in e-waste — a $400+ cutting machine, cosmetic condition fine except for perished rollers, which were probably why it was thrown away.
She took it home. It passed self-tests. Then Design Space greeted her with the message that haunts the Cricut community:
“Machine deactivated”
Cricut is notorious for remotely locking its machines. But xssfox — a hacker — decided the lock was a puzzle, not a verdict. What followed is one of the cleanest hardware bypasses of 2026: a $1 microcontroller that rewrites your printer’s identity in-flight.
Why machines get bricked in the first place
Cricut’s cloud DRM deactivates machines for reasons that have enraged users for years:
- Warranty replacements: the old machine is remotely deactivated before the replacement arrives — leaving home businesses without a working cutter for 7-14 days
- Support tells you to trash it: instead of returning the deactivated unit, users report being told to throw it away, “turn it into a flower pot,” or keep it as a display piece
- On-selling and loaning: a Reddit user loaned their Maker to a friend; the friend created a new account, Design Space pushed a firmware update, and the out-of-warranty machine was permanently bricked. Cricut refused to unbrick it
- Help desk statements: support chats circulated showing agents saying devices would be bricked if sold second-hand
The 2021 precedent made the pattern undeniable: in March 2021, Cricut tried capping free users at 20 uploads/month, the community exploded (Etsy sellers, class-action talk, ACCC complaints), and CEO Ashish Arora reversed course twice in three days — ending with unlimited free uploads for everyone, forever.
The unlock: plaintext serials and a $1 proxy
xssfox’s attack surface of choice wasn’t the cloud — it was the cable.
- Wireshark on the USB CDC link → the cutter sends its serial number to the computer in plaintext. No checksums. No cryptography.
- A Raspberry Pi RP2040 (the $1 chip from the Pico), overclocked to 240MHz, acting as USB host + client simultaneously (TinyUSB examples, CDC echo)
- The RP2040 sits between cutter and PC, and when it sees the serial packet, rewrites it to a different, active serial number
The software is none the wiser. The deactivated e-waste unit registers in the user’s account and works as if brand new — after replacing the perished rollers (hint: hot water softens them) and 3D-printing a little case for the RP2040.
The collateral vulnerability she flagged
Here’s the uncomfortable part: Cricut serial numbers are issued sequentially, and the status of every unit is queryable on Cricut’s own status page. xssfox could register serial numbers that don’t exist on that page.
Which means — as she carefully noted — the same unencrypted system could allow a stranger to register active users’ serials to their own account, or lock out other people’s machines. The lock that protects Cricut’s business model doesn’t even protect its customers from each other.
The legal grey zone
xssfox published the full story but withheld the code, citing Australian anti-circumvention law. The context:
- US: DMCA §1201 bans circumvention, but the EFF has won exemptions for repairing digital devices, appliances, and vehicles — and keeps litigating against the provision itself
- Australia: the Productivity Commission’s December 2021 right-to-repair report recommended amending the Copyright Act to permit TPM circumvention for diagnosis and repair
- The consumer path: during the 2021 controversy, Australian law made retailers jointly liable — Harvey Norman refunded full AUD$600 purchases
Why this matters
This is e-waste rescue as security research. A machine Cricut considered dead — killed by a server-side flag, not any hardware fault — was returned to full function with a $1 chip and an afternoon.
It also proves something the right-to-repair movement has argued for years: these locks are artificial. They exist to protect business models, not to protect users — and when the “protection” is a plaintext serial number on a USB wire, the business model is exactly as strong as the cable it ships with.
The flower pot can cut again. ✂️
無程式碼也能輕鬆打造專業LINE官方帳號!一鍵導入模板,讓AI助你行銷加分!