DEF CON badges have long been electronic art pieces, but for 2026 founder Jeff Moss asked hardware hacker Andrew “bunnie” Huang to build the badge around the Baochip-1x, Huang's “mostly” open-source microcontroller: the source for its operating system, firmware, RISC-V processor core, cryptographic engines and I/O is published on GitHub. The chip had existed only in a small development release; the 27,000 conference badges are its first major distribution. Making a chip normally costs millions of dollars in fabrication — a run Huang could never have funded alone.

Three years earlier, a company called Crossbar asked Huang to help create an open, secure chip. He agreed on one condition: he could piggyback his CPU on their wafer, sharing the manufacturing run. “They look at it as, if they put me on the chip, they get two products for the price of one,” Huang told WIRED — a practice he says is not unusual, though the industry rarely discusses it publicly.

The second trick is the packaging. Even earlier open-source chips shipped in opaque plastic, leaving a supply-chain problem: users had to trust nothing was added during manufacturing. The Baochip is packaged so infrared light can pass through the back of the silicon, letting researchers inspect internal structures against the published design. Moss added one requirement: the badge must have a life beyond the conference — its transparent core module detaches into a security token for one-time passwords and QR registration.

Open-source chips fixed the design-trust problem but not the supply-chain one: an opaque package still forces users to trust that no backdoor was inserted during manufacturing.

A wafer run is a lumpy, million-dollar purchase; sharing one turns a fixed cost into a marginal sliver for both parties.

A hardware conference full of expert attackers is a stress-test distribution channel — adoption and free security auditing arrive in the same move.

The detachable token gives the chip a post-conference life, satisfying the conference founder's requirement that badges not end up in a drawer or landfill.

Expensive shared infrastructure can be ridden for free if the ride is worth something to its owner — and trust claims become verifiable when people can inspect the thing itself.

WIRED revealed the badge on July 31, 2026, ahead of DEF CON 34. Huang planned to demonstrate infrared inspection at the conference and expects attendees to find zero-days: “It’s actually one of the features of launching at Defcon.” The chip runs a Rust OS with secure boot, a true random number generator and resistive RAM; Huang estimates it withstands attacks costing tens of thousands of dollars but not a state-scale lab, and calls it probably the world’s first security token inspectable down to the bootloader and transistors.

FOLLOW THE EVIDENCE

The sources

  1. The New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security Key wired.com