A conference badge is about to become the exception
DEF CON 34 opens on 6 August at the Las Vegas Convention Center West Hall, and its badge is not the usual blinking souvenir. It was built by Andrew Huang, the hardware researcher known as bunnie, around a chip he designed called Baochip-1x. The organisers describe it as a full-fledged, first-of-its-kind inspectable platform, and list what it is meant to do afterwards: security token, password manager, hardware security module, pretty light generator.
The specification is not toy-grade. Baochip-1x is a TSMC 22-nanometre part on a dedicated mask set, roughly four millimetres a side, with a 350MHz VexRiscv processor and a memory management unit, four 700MHz input-output cores, 4MiB of resistive RAM and 2MiB of static RAM, cryptographic accelerators, a true random number generator, a secure mesh, glitch sensors and hardware-protected key slots. Production-qualified wafers are in Hsinchu, with a few thousand bare chips targeted for late 2026.
What makes it worth an owner's attention is not the silicon. It is that several thousand people are about to hold a security token whose construction they can check, which is something almost nobody holding a security token today can do.
Inspectable means something specific, and it stops somewhere
The claim is narrower and more interesting than open source usually implies. Huang pioneered a technique called IRIS, for infra-red in-situ, which uses infrared light to look at a chip's transistors without unmounting or destroying it. Baochip-1x was deliberately packaged to be compatible with it. The point is not that you can read the design. It is that you can look at the physical part in your hand and check that the pattern printed on the die is the one that was supposed to be there.
Huang calls the design mostly-open, and that qualifier is the most credible thing about it. The computational blocks are published for inspection. The bus framework, the USB interface and the analogue components including the phase-locked loop, the voltage regulators and the input-output pads stay closed. His argument for why that is acceptable is precise: all the closed source components are effectively wires, meaning the data that goes in one side should match the data coming out the other.
You can disagree with that boundary. What you cannot do is get a straighter answer from any mainstream vendor, because no mainstream vendor draws the boundary at all. A commercial secure element is closed from the pads inwards, and the only assurance offered is a certification document describing a process rather than the part on your desk.
Now look at what is already on your keyring
Run the same test against the roots of trust your business already depends on. The security keys your administrators carry. The trusted platform module soldered into every laptop you issue. The hardware security module holding your signing keys. The secure element in the payment terminals on your counters. Each of those exists precisely to be the thing you do not have to trust anything else about, and for each of them your evidence is a supplier's word and a certificate.
That is not an accusation of wrongdoing, and it is not an argument for replacing anything. Most of these parts are well made and the certification regimes behind them are real work. The point is narrower: you have accepted an unverifiable component at the exact place in your stack where verification matters most, and you have done it because until now there was no alternative to accept instead.
The reason this matters commercially rather than philosophically is that the assurance you hold is about a manufacturing process, not about the individual unit that arrived in your building. A certificate says a design was assessed. It does not say the die in this package is that design. IRIS is interesting because it addresses the second question, which is the one an auditor would actually ask if the vocabulary existed to ask it.
Europe is about to mandate transparency for the wrong layer
The timing is what turns this from a curiosity into a planning item. The Cyber Resilience Act starts biting on 11 September 2026, when reporting obligations apply: a manufacturer of a product with digital elements must give ENISA and the relevant national computer security incident response team an early warning within 24 hours of learning about an actively exploited vulnerability, a fuller notification within 72 hours, and a final report within 14 days. The essential requirements, including the software bill of materials, follow on 11 December 2027.
Read those two dates together and the asymmetry is obvious. Europe is building a legal regime that will eventually tell you what software is inside a product, with a deadline and a named regulator. There is no counterpart for what silicon is inside it. If a vulnerability in a hardware root of trust is exploited in a product you manufacture, your 24-hour clock starts against a component you were never able to examine and whose supplier owes you no equivalent disclosure.
For a European manufacturer, that gap is a scheduling risk rather than an abstraction, because the reporting duty is yours and the opacity belongs to somebody else. For a business that only buys, the exposure is milder but the remedy is the same: whatever you cannot verify, you should at least have named in a contract.
The question to send this week
Do not rebuild anything around a conference badge. Baochip-1x is made by a one-person Delaware company that is bootstrapped with no outside investors, fabricated through a partner that handles the TSMC relationship, and targeting general availability late this year. That is a serious engineering effort and a thin commercial base, and treating it as a procurement option today would be the wrong lesson.
The right one costs an email. Ask each supplier of a security key, hardware module or secure element what independent evidence they can provide that the die inside a delivered unit matches the published design, and file whatever comes back. Most answers will point to a certification scheme, which is worth knowing precisely because it is not the same claim. When a team eventually prices this in, the number is small and knowable: a fleet of 200 security keys at roughly 50 euros each is a 10,000 euro line item, and the decision it informs is worth more than that.
Read next: The Door Left Open Was the Package Registry | 16,000 Firms Pooled Their Supplier Risk. You Didn't



