
Explore how the DEF CON badge's BaoChip brings open-source silicon to life as a FIDO2 security key, challenging proprietary hardware and empowering researchers.
Every August, thousands of hackers descend on Las Vegas for DEF CON, the world’s most iconic security conference. Every attendee receives a badge—a coveted credential that signals belonging and status. But this year’s badge is far more than a collectible. It is built around a custom open-source security chip called the BaoChip, designed by renowned hardware hacker Andrew “bunnie” Huang. What makes it remarkable? The BaoChip functions as a real FIDO2/WebAuthn security key, allowing attendees to use their badge for passwordless authentication even after the conference ends. At the same time, it pushes open-source principles into silicon: the chip design, firmware, and supporting tools are all publicly inspectable. For security researchers, it is both a conference credential and a hands-on platform for studying cryptographic hardware design.
Conference badges have come a long way from simple laminated paper tags. Over the past 10 to 15 years, DEF CON and other hacker conferences have transformed badges into hackable, functional devices. They’ve featured LEDs, sensors, radios, and even custom CPUs, blending craftsmanship with playful engineering. The goal is twofold: give attendees something to tinker with and showcase what’s possible in embedded hardware.
The BaoChip takes this tradition to a new level. Designed by bunnie Huang—the author of The Hardware Hacker, a well-known open-source hardware advocate, and a veteran of prior badge projects—the badge substitutes novelty electronics with a genuine secure element. That shift changes what a badge can do. It isn’t just a credential to scan; it’s a piece of security infrastructure you can carry in your pocket.
For cryptography enthusiasts, the BaoChip is rare for another reason: it is a secure element built with transparency in mind. Secure elements in phones, credit cards, laptops, and dongles are typically proprietary. Vendors restrict access to design files and firmware. The BaoChip, by contrast, is designed for public inspection from the start. That’s a radical departure from convention, and it places DEF CON at the center of the open-source secured hardware movement.
The most striking feature of the BaoChip is that it works as a legitimate FIDO2/WebAuthn security key. Attendees can use it for account registration and passwordless authentication. Once configured, the badge can verify login challenges, generate digital signatures, and prove knowledge of a private key stored in the secure element. In other words, it behaves like the commercial keys many organizations use to protect sensitive accounts.
This matters because FIDO2 and WebAuthn have become the standard for phishing-resistant, passwordless authentication. Major platforms and browsers support the protocol, and many organizations now require hardware security keys for privileged users. By shipping a real FIDO2 authenticator in a conference badge, the DEF CON badge moves from a nerdy accessory to a genuinely practical security tool.
Attendees can put the badge to work right away:
This makes the badge a working case study for passwordless infrastructure, not just a prototype. It also provides a subtle lesson: open-source security chips can meet the functional requirements of enterprise-grade authentication.
The BaoChip is also a statement about silicon trust. Most secure chips are black boxes. Designers can’t easily audit them, and users rely on vendor certifications. The BaoChip flips this assumption: the chip design, firmware, and toolchain are open. Anyone can inspect them for design flaws, backdoors, or questionable defaults.
This aligns with the broader rise of open-source silicon. Over the last decade, development around RISC-V and open-core designs has gained real momentum. While the BaoChip is not itself a RISC-V implementation, it shares the movement’s ambition: to make hardware verifiable and auditable at every level. For security professionals, a verifiable root of trust is a major selling point. Instead of “trust our opaque hardware,” the badge says “check our work.”
Mass-producing such a chip for a large conference is itself an achievement. It demonstrates that open-source secure elements can be manufactured reliably and deployed at scale. That’s a necessary step toward broader adoption in consumer devices, enterprise security products, and identity infrastructure.
The BaoChip also serves as an educational tool. DEF CON has always been a learning environment, and the badge extends that spirit into silicon. Researchers can examine the cryptographic logic, follow the FIDO2 implementation, and learn how secure elements protect private keys.
Why does that matter? Because hardware security knowledge is less common than software security knowledge. Most researchers are comfortable with web vulnerabilities and network protocols, but secure-chip design is often opaque. The BaoChip’s open structure lowers the barrier to entry. It lets curious engineers trace the full lifecycle of a secure element—from design and fabrication to programming and authentication.
The badge’s open design also gives researchers an unusual gift: the ability to compare a real secure element against its public documentation. In most products, the gap between spec and silicon is hidden behind non-disclosure agreements. Here, everything is open for study, enabling a deeper understanding of how cryptographic keys are generated, stored, and used in practice.
For organizations exploring open-source hardware, the badge is a useful reference. It illustrates a practical path for producing transparent security devices, and it raises important questions about certification, supply chain, and reproducibility that will define the future of trustworthy hardware.
The DEF CON badge’s BaoChip is not just a gadget; it signals a shift in how we think about trust in hardware. As open-source silicon continues to grow, expect more devices to adopt transparent, verifiable designs. Phones, laptops, routers, and IoT products may all benefit from open roots of trust.
Security keys are already following this path. FIDO2 adoption has risen steadily since the protocol’s expansion in the late 2010s. Hardware keys are increasingly viewed as essential security tools rather than niche accessories. The BaoChip demonstrates that such keys can be produced with open components—pointing toward a future where users don’t have to rely solely on corporate assurances.
That doesn’t mean proprietary secure elements will vanish. Certification programs, enterprise compliance, and vendor support will keep closed ecosystems in play. But the BaoChip sets a benchmark for what’s achievable in open hardware.
Open-source silicon will not replace all proprietary chips overnight, but it offers a growing ecosystem of alternatives. For enterprises, verifiable hardware reduces the risk of supply-chain tampering. For creators, it opens the door to custom security logic that can be shared and improved by a global community.
Andrew “bunnie” Huang’s DEF CON badge, powered by the open-source BaoChip, is a milestone for both conference culture and security hardware. It embeds a genuine FIDO2/WebAuthn security key into a conference credential, proving that open-source secure elements can be mass-produced and useful. It also gives security researchers a rare hands-on platform to study cryptographic hardware.
For attendees, the badge is a practical tool for passwordless authentication. For the broader tech community, it’s a statement: transparent silicon is possible, valuable, and worth pursuing. If you’re a builder or decision-maker evaluating security hardware, the BaoChip is a compelling reason to explore open-source roots of trust. The badge is more than a memento. It’s a preview of the future.
The BaoChip is a custom open-source security chip built into the DEF CON conference badge. Designed by hardware hacker Andrew "bunnie" Huang, it functions as a real FIDO2/WebAuthn security key and is fully open for public inspection, including its chip design, firmware, and supporting tools.
The badge includes the BaoChip secure element, which implements FIDO2/WebAuthn protocols. This allows attendees to plug the badge into a device and use it for passwordless authentication just like a dedicated security key, even after the conference ends.
Open-source silicon refers to hardware designs—such as chip schematics, firmware, and tooling—that are publicly available for anyone to review and modify. With the BaoChip, this transparency lets security researchers inspect the cryptographic implementation instead of trusting a closed, proprietary black box, which is a major shift in secure hardware design.
Unlike commercial security keys, whose internal designs and firmware are kept proprietary, the BaoChip is built for transparency from the start. It also serves dual purpose as both a conference badge and a FIDO2 authenticator, while YubiKeys are dedicated security devices with closed-source internals.
The BaoChip demonstrates that secure elements can be open-source without sacrificing functionality. It challenges the assumption that cryptographic hardware must be proprietary and could inspire more transparent design practices in phones, laptops, and other devices, ultimately giving researchers and users greater trust in the security of their hardware.