Phreakbyte edition is an independent firmware and tooling distribution for the ChameleonUltra hardware, focused on fast, frictionless flashing and iteration.
It is a standalone project with its own roadmap. It is derived from RfidResearchGroup/ChameleonUltra and remains GPLv3. See Credits and license.
The stock firmware ships a signed Nordic Secure DFU bootloader, so every update
means nrfutil, signed packages, and driver handling. Phreakbyte replaces that
with a UF2 drag-and-drop bootloader. Day-to-day updates become "copy a .uf2
onto a USB drive." That is the whole point: shorter build-flash-test loops.
- UF2 bootloader. Firmware is flashed by copying a
.uf2file onto theCHAMELEONmass-storage drive. Nonrfutil, no signed packages, no driver install for routine updates. - Multi-image DFU flashing. Combined images can be pushed in a single pass.
- Stock-compatible. The bootloader lives at the stock address and speaks
the stock serial/BLE DFU as well as UF2, so stock firmware installs straight
through it — no bootloader swap. See
firmware/tools/RECOVERY_BUILD.md. - Native cross-platform BLE. The desktop CLI connects over BLE (Nordic UART) as well as USB.
The RFID/NFC research feature set and the client protocol are carried forward, so existing tooling such as ChameleonUltraGUI continues to work.
Prebuilt UF2 (recommended): follow
firmware/tools/UF2_INSTALL.md. In short: enter
the bootloader, then drag the .uf2 onto the CHAMELEON drive.
Build from source:
cd firmware
./build.sh
Then flash with the UF2 helper:
./flash-uf2-app.sh
Other flash paths (flash-dfu-app.sh, flash-dfu-full.sh) remain available
for SWD and signed-DFU workflows.
You don't need to change the bootloader to run stock firmware — this fork's
bootloader is a superset of the stock one. Just flash the stock app through
it: enter serial DFU (hold button B, plug USB) and push the upstream app zip
with nrfutil or any stock DFU flasher. Full steps in
firmware/tools/RECOVERY_BUILD.md.
Details and the recovery-image build are documented in
firmware/tools/RECOVERY_BUILD.md.
The Python CLI lives in software/script.
cd software/script
python3 -m pip install -r requirements.txt
python3 chameleon_cli_main.py
Connect over USB or BLE from the hw connect command. Run hw version to see
the running firmware and build.
Device version is derived at build time from git describe against v*.* tags
(firmware/Makefile.defs). Releases are tagged vMAJOR.MINOR, and hw version
reports the tag plus the short commit.
A complete list and arguments for all CLI commands in this fork.
docs/command.md.
Phreakbyte is built on the work of the RfidResearchGroup ChameleonUltra project and its contributors. Thanks to Iceman and the RRG team. The detachment into a standalone project was made with their knowledge.
This project is licensed under the GNU General Public License v3.0. Upstream
copyright notices and AUTHORS.md are preserved. See LICENSE.
