SpaceX spent years hardening its terminals after KU Leuven researcher Lennert Wouters demonstrated a voltage fault injection attack against first-generation Starlink hardware at Black Hat USA 2022. SpaceX responded by disabling UART debug output via eFuse and tightening secure boot chain integrity, making subsequent terminals substantially harder to crack. Multiple international research teams reportedly hit walls. Then, in late August 2026, Darknavy — a cybersecurity research institute operating between Singapore and Shanghai — posted a claim on social media: full administrative root access to the latest Starlink Standard Actuated terminal, the square-antenna revision, achieved via hardware attack. To be clear upfront: this is a lab exploit requiring physical access, not a remote mass hack.
The Attack That Wasn’t Supposed to Be Possible
Darknavy’s firmware groundwork, laid since March 2025, made this moment look less like luck and more like a systematic long game.
That earlier work involved:
- Purchasing a Standard Actuated terminal in Singapore
- Extracting firmware directly from the eMMC chip
- Emulating terminal services — including httpdWebSocket, and gRPC — under QEMU for systematic analysis
Critically, large portions of Starlink firmware across multiple terminal versions remained unencrypted, a fact publicly documented by the broader research community. The security chip identified in the terminal ecosystem, an STSAFE-A110, handles identity and key operations — but the surrounding architecture, reportedly, had seams. Darknavy claims it found one, cracking the boot chain and achieving arbitrary code execution on the device.
Full root access means researchers can now simulate, intercept, and analyze communication protocols between the terminal and Starlink’s satellites — not just probe the network from outside.
Why This Matters Beyond the Lab
When your satellite dish doubles as a battlefield communication node, “lab exploit” stops being a reassuring qualifier.
In Ukraine, Starlink terminals route battlefield communications through satellites connected to ground gateways in neighboring countries, bypassing destroyed local infrastructure. Each terminal is a critical infrastructure node, not a consumer gadget. A compromised device at that layer raises pointed questions about authentication integrity and the security of update flows across the constellation. As Darknavy stated, “developers and hackers contend not only in the digital realm but also against the constraints of cosmic physics.” The group describes its access as “legal exploration” conducted on its own purchased equipment, consistent with responsible-disclosure norms.
Verification, though, remains pending. Darknavy has withheld technical details, citing forthcoming publication on its official website. SpaceX, contacted by the South China Morning Post, had not publicly responded as of early September 2026. No independent third party has confirmed the exploit. What exists is a researcher claim — built on documented prior work and prior reputation — not yet a published proof-of-concept.
What Comes Next
For SpaceX, another hardware revision cycle looms. For every other LEO operator watching, the warning is blunt.
If Darknavy’s claim survives scrutiny, SpaceX faces another hardening sprint — firmware updates, potential hardware redesign, deeper encryption across the boot chain. For competing satellite internet providers, the lesson arrives pre-packaged: your edge device is your weakest link, and determined researchers with soldering irons will eventually find the seam.





























