FlatSat – DEFCON 34
Learn real satellite cybersecurity hands-on: a 3-level CTF with instant visual feedback, safe by design so you never touch real satellites or restricted frequencies.
$100.00
Out of stock
Email when stock available
- Works with: CatSniffer, Electronic Cats' LoRa sniffer (single-radio overlay mode)
- Works with: RTL-SDR USB dongle + SDR++ for passive RF verification
- Ships with: a preloaded, intentionally vulnerable firmware that mimics real spacecraft systems
- Works with: Linux, macOS, and Windows -- FlatSat Ground Station (Docker or native Python 3.11+)
In the box
Exclusive DEF CON 34 commemorative patch
Not included
You also need
SDR++ software (free, sdrpp.org), to visualize the RF spectrum and confirm the downlink signal
A second FlatSat unit + a laptop running the FlatSat Ground Station webapp, for the full CTF curriculum’s Base hardware tier and Attack/Defend workshop mode
SWD probe (e.g. a second Raspberry Pi Pico as debugger) + soldering 3 wires to the board’s SWD pads, needed only for the Advanced firmware-hacking tier
Arduino IDE + arduino-pico board package, needed only if compiling or flashing custom firmware instead of the pre-compiled UF2
- 40 GitHub Stars
- Presented at DEF CON 34, with an exclusive DEF CON 34 patch in the bundle.
- Designed and built in Aguascalientes, Mexico
- Hardware CERN-OHL v1.2 ยท firmware GPL-3.0
What is FlatSat?
FlatSat is a hardware-based training board for learning satellite and space-systems cybersecurity hands-on, built to be vulnerable on purpose. It ships preloaded with intentionally vulnerable firmware that mimics real spacecraft systems, so you can practice binary exploitation and reverse engineering safely on hardware you own. Setup starts simple: connect over USB, enter bootloader mode, and drag a precompiled firmware file onto the board — no coding or soldering required to begin. From there, FlatSat guides you through a 3-level CTF (web and RF, systems and the CCSDS protocol, then firmware and crypto), with an onboard NeoPixel LED confirming your progress at each stage. It runs only on license-free ISM radio bands and never touches real satellites or production ground infrastructure, so training stays safely self-contained on your own board. It suits solo learners and instructor-led workshops alike.
Work through a 3-level satellite CTF
Confirm the downlink without touching the board
Run a workshop or classroom lab, solo or in teams
Start in 10 minutes
- Connect the FlatSat board to your computer via USB.
- Enter bootloader mode: hold BOOT, tap RST, then release BOOT — the board mounts as a USB mass-storage drive.
- Download the latest firmware.ino.uf2 file from the FlatSat_Firmware GitHub releases.
- Drag and drop firmware.ino.uf2 onto the board’s mass-storage folder; it unmounts automatically once flashing succeeds.
- Head to the FlatSat wiki to pick your starting CTF level and curriculum format (Home Lab or Workshop).
| MCU | RP2040 (dual-core ARM Cortex-M0+) |
|---|---|
| Radio | 2x SX1262 LoRa transceivers (uplink + downlink) |
| Environmental sensor | BME280 (pressure, humidity, temperature) |
| Accelerometer | LIS2DH12, 3-axis (I2C) |
| Status LED | WS2812B NeoPixel (GPIO 15) |
| Exposed interfaces | I2C, UART, SWD |
| Operating voltage | 3.3V I/O |
| Dimensions | 41 mm x 78 mm |
| Flash memory | 4 MB (no filesystem partition) |
| RF band | 433 MHz / 915 MHz (license-free ISM) |
| Open hardware | CERN Open Hardware Licence v1.2 |









