An “Unpatchable” Hack Just Cracked Every iPhone 11 Forever — In Under 2 Seconds
It’s baked into the chip. No update can kill it. Apple can’t fix your phone — they can only sell you a new one.
Chips hit: A12 + A13. Devices affected: 100M+. Attack time: under 2 seconds. Patch available: never.
Researchers dropped a chip-level exploit called “usbliter8” that lives in the silicon itself — old iPhones, iPads, Watches, even the HomePod mini. Here’s the 9to5Mac writeup.

So the headlines are screaming “UNPATCHABLE!” and “EVERY iPHONE HACKED!” Let’s pump the brakes for a second. The data says this thing needs your phone in hand, plugged into a tiny chip on a wire, held in a special repair mode. It is NOT some dude hacking you from a basement across the ocean. But here’s the thing nobody mentions — “can never be fixed” is exactly the kind of flaw that turns a dying old gadget into a little goldmine. Stick around for that part.
🧩 Dumb Mode Dictionary (read this first, everything clicks)
| Scary Word | What It Actually Means |
|---|---|
| Bootrom / SecureROM | The tiny bit of code frozen into the chip the day it’s made. Like words carved in stone — nobody can edit it later. |
| Unpatchable | Apple literally cannot send an update to fix it. The bug is in the stone, not the software. |
| DFU mode | A special “wipe and reset me” state you trigger by holding the phone’s buttons. Repair shops use it every day. |
| usbliter8 | The nickname the researchers gave this hack. |
| A12 / A13 chip | The “brain” inside iPhone XS, XR, 11, SE 2, plus some older iPads and Watches. |
| Jailbreak | Ripping out Apple’s locks so the phone runs whatever you want on it. This exploit makes that permanent. |
🔧 What actually got cracked (the honest version)
Receipts first. A research crew called Paradigm Shift found a bug in the USB part of Apple’s A12 and A13 chips, plus a small firmware slip-up. Chain the two together and you own the phone before Apple’s security even wakes up during startup.
- Needs the phone in your hands and in DFU (reset) mode
- Runs off a cheap little RP2350 board (a $5 hobby chip) on a USB cable
- Finishes in under 2 seconds
- If you’ve heard of the old checkm8 jailbreak — this is the same family. Hardware-level, forever.
Translation: nobody’s stealing your bank app over WiFi with this. Somebody needs your actual phone, unlocked-into-repair-mode, on a bench. Airport security, a nosy border agent, a jealous ex, a shady repair guy — those are the real threats.
📊 The receipts — who's cooked and who's fine
| Device | Chip | Vulnerable? |
|---|---|---|
| iPhone XS / XR / 11 series | A12 / A13 | |
| iPhone SE (2nd gen) | A13 | |
| iPad Air 3 / mini 5 / iPad 8 | A12 | |
| Apple Watch Series 4 / 5 / SE | S4 / S5 | |
| HomePod mini | S5 | |
| iPhone 12 and newer | A14+ |
The counter-argument you’ll hear: “old phones, who cares.” But the numbers say the iPhone 11 alone sold north of 150 million units, and tons are still in pockets, in drawers, and in the second-hand market across Asia, Africa and Latin America. That’s a massive pile of hardware that just changed status overnight.
⚖️ Plot twist: the researchers got SUED and deleted the proof
Here’s where it gets spicy. In July 2026, forensics giant Magnet Forensics sued Paradigm Shift in Georgia federal court. Their claim: the hack was “substantially identical” to secret research done by a guy named Mario Del Gaudio while he still worked at Magnet — before he jumped ship to Paradigm Shift.
So Paradigm Shift yanked the blog post after the lawsuit landed. Read that again: a company that sells phone-cracking tools to cops and governments is fighting to keep this exploit proprietary. The “public research” everyone celebrated is now a courtroom trade-secret brawl. But here’s the thing nobody mentions — the cat’s already out. The technique is known. Deleting a blog post doesn’t un-carve the stone.
🗣️ What the timeline's saying
- The tinkerers: “checkm8 all over again — permanent jailbreaks incoming, retro-modders eating good.”
- The privacy folks: “Border agents and abusers just got a 2-second skeleton key for 100M devices.” (Privacy Guides is tracking it.)
- The normies: “So… is my phone gonna get hacked?” (Only if someone grabs it physically. Chill.)
- Apple: basically “cool, please buy an iPhone 16.” The official mitigation is upgrade your hardware. That’s it.
Cool. So a Dead iPhone Just Became Un-Killable Hardware… Now What the Hell Do We Do? ( ͡° ͜ʖ ͡°)

Real talk: an “unpatchable, permanently jailbreakable” phone isn’t just a scare story. For the right hustler it’s a feature. When Apple locks a door forever, they also open one. Here’s where the money’s hiding.
🕳️ The Bootrom Bargain Bin
Panic makes people dump gear cheap. Watch local resale apps as scared owners offload iPhone XR/11 units at fire-sale prices “because it’s hacked.” You know the truth: it’s only “hacked” if someone physically steals it. Buy the fear, flip to people who don’t care — or to tinkerers who want a permanently-jailbreakable device.
Example: A 24-year-old reseller in Lagos, Nigeria scoops iPhone 11 units off Jiji at a 25% “exploit panic” discount, wipes them clean, and resells to students who just want a solid cheap phone. ~$40 margin each, 15 units a month.
Timeline: First flips in 1–2 weeks. The fear discount fades in ~2 months once people realize it needs physical access — so front-load hard.
🎮 The Retro Pocket Rocket
A permanently jailbroken A12/A13 phone makes a perfect emulation handheld — huge screen, great chip, dirt cheap now. Buy dead-cheap iPhone 11s, load emulators the legit way (your own game backups), sell them as ready-to-play retro machines to people who’d never figure out the setup themselves.
Example: A 19-year-old in Manila, Philippines buys cracked-panic iPhone XRs, swaps a $12 screen, sets up emulation, and sells “retro pocket consoles” on Facebook Marketplace for a clean $90 flip. Check r/EmulationOnAndroid and emulation forums for the demand.
Timeline: First sale in ~10 days once you’ve got the setup dialed. Stays alive as long as cheap A12/A13 stock exists — plenty for a year+.
🖥️ The One-Job Kiosk Flip
Small shops pay real money for locked-down tablets that only run one app — a menu, a booking screen, a review kiosk. A jailbroken A12 iPad can be frozen into single-app mode for a fraction of what a “commercial kiosk tablet” costs. Buy used, configure, sell the solution, not the hardware.
Example: A 27-year-old in Nairobi, Kenya grabs used iPad 8s, locks each to a café’s digital menu app, and charges salons and cafés $120 setup + a small monthly. Five installs = his rent. Learn the lockdown basics via Apple’s Guided Access plus jailbreak kiosk tools.
Timeline: First paying shop in ~3 weeks (selling is the slow part). Recurring income once installed. Solid for 6–12 months per client.
🔓 The Photos-From-The-Dead Desk
Here’s a real one people will pay for: recovering photos off their own old, locked, half-dead iPhones — a passed relative’s phone, a forgotten passcode on grandma’s iPad. This bootrom access is exactly what forensics firms charge thousands for. You offer it human-scale, cheap, with proof of ownership required (keep it legal — owned or consented devices only).
Example: A 30-year-old tech-shop owner in Karachi, Pakistan advertises “recover memories from old locked iPhones (proof of ownership needed).” Charges $60–150 a job, does 8 a week off word-of-mouth. Study the legit side at the Magnet Forensics blog.
Timeline: First paying job within days of putting up a sign. Word-of-mouth compounds. The ethics line is the whole business — cross it and you’re cooked, so don’t.
📉 The Panic-Dip Signal Trade
Reverse the data flow. Every scary headline about a phone model quietly moves its resale price. Track the daily average price of affected models on resale sites, spot the fear-driven dip, buy the bottom, and sell when the panic fades and prices snap back. Boring public data → private money signal.
Example: A 22-year-old in São Paulo, Brazil built a free Google Sheet that logs iPhone 11 listing prices on OLX each morning. When prices dropped 20% on exploit headlines, he bought 10, held 6 weeks, flipped as prices recovered. ~$35/unit, zero drama.
Timeline: First buy-the-dip window opens the moment a scare hits (right now). Each panic cycle lasts weeks. Works every time a new “old phone hacked” story drops — and they always drop.
🛠️ Follow-Up Actions
| If you want to… | Do this |
|---|---|
| Check if YOUR phone is affected | Match your model to this list |
| Protect an old device | Set a strong 6+ digit passcode, turn on USB Restricted Mode, don’t hand it to strangers |
| Understand the tech | Read up on checkm8, its spiritual ancestor |
| Start flipping | Watch OLX / Jiji / FB Marketplace for panic dips |
| Go legit forensics | Learn from Magnet Forensics |
Quick Hits
| You Want… | Do This |
|---|---|
| Keep the phone in your pocket — remote hack isn’t a thing here | |
| Strong passcode + USB Restricted Mode + never lend it | |
| Buy the fear-dip, flip to people who know the truth | |
| Turn a dead iPhone 11 into a retro handheld | |
| It’s checkm8 for a new chip generation — carved in silicon |
Apple can’t patch the stone. But you can absolutely turn everyone else’s panic into your side income.
!