ipwndfu
ByMichael Warner 11th September 202513th November 2025
What is ipwndfu?
ipwndfu is an open-source tool created by axi0mX that helps put compatible iOS devices into pwned DFU (Device Firmware Update) mode using bootrom exploits.

Features of ipwndfu
- Pwned DFU Mode: Bypasses signature checks, enables custom boot chains.’, ‘Exploits included: Supports alloc8, steaks4uce, limera1n, SHAtter, and the famous checkm8 exploit.’, ‘Capabilities: Dump SecureROM, decrypt keybags, demote devices to enable JTAG, and facilitate jailbreaking or untethered downgrades on older hardware.’
- Include a dedicated ‘Common Commands’ section with direct commands: ‘./ipwndfu -p’, ‘./ipwndfu –dump-rom’, ‘./ipwndfu –demote’.
- Add a ‘Requirements’ section clearly stating: ‘Requires libusb installed on your system (macOS or Linux).’, ‘Requires a compatible legacy or checkm8-vulnerable iOS device.’
ipwndfu has unique features, including enabling custom boot chains, bypassing signature checks, and supporting multiple exploits.
- Pwned DFU Mode: Bypass signature checks, enable custom boot chains, and exploit included: Support alloc8, steaks4uce, limera1n, SHAtter, and the famous checkm8 exploit. With these exploits and Pwned DFU mode, users can dump SecureROM, decrypt Keybags, demote the device to enable JTAG, and facilitate jailbreaking or untethered downgrades on older hardware.
- Also, it includes a dedicated ‘Common Commands’ section with direct commands such as:
- ./ipwndfu -p’, ‘./ipwndfu –dump-rom’, ‘./ipwndfu –demote’.
- Encrypt or decrypt hex data on a connected device in pwned DFU Mode using its GID or UID key.
Requirements:
- Requires libusb installed on your system (macOS or Linux).
- Compatible legacy or checkm8-vulnerable iOS device.
Warning /Disclaimer : Please use this tool for your security research purpose and dont use your primery device our strong advice is use your testing device for experiments.
Download ipwndfu
You can download the latest version of ipwndfu from the official GitHub repository and the direct download links below.
ipwndfu Compatible Devices(checkm8)
Supported Processors (A5 – A11)
A5 / A5X
A6 / A6X
A7
A8 / A8X
A9 / A9X
A10 / A10X
A11
Compatible Devices List
iPhones:
iPhone 4s
iPhone 5 / 5c
iPhone 5s
iPhone 6 / 6 Plus
iPhone 6s / 6s Plus
iPhone SE (1st Gen – 2016)
iPhone 7 / 7 Plus
iPhone 8 / 8 Plus
iPhone X
iPads:
iPad 2, iPad (3rd Gen), iPad (4th Gen)
iPad (5th Gen), iPad (6th Gen), iPad (7th Gen)
iPad mini 1, mini 2, mini 3, mini 4
iPad Air 1, Air 2
iPad Pro 9.7″, 10.5″, 12.9″ (1st & 2nd Gen)
iPod Touch & Apple TV / Watches:
iPod touch (5th, 6th, and 7th Gen)
Apple TV 3rd Gen (A1459/A1427) & Apple TV 4K / HD
Apple Watch Series 1, 2, and 3
Note: A12 and later chipset devices are not supported for checkm8/ipwndfu
(iPhone XS, XR, 11, 12, 13, 14, 15, 16, 17, 18, like the latest devices)
How to install ipwndfu
Here is the clear, step-by-step instructions for common commands to demonstrate practical experience
It is a Python-based script that interacts directly with your device over USB.
Prerequisites & Installation
Step 1: Install Dependencies
ipwndfu requires libusb to manipulate USB communication.
- On macOS: Install Homebrew if you haven’t already, then run:
bash
brew install libusb
Use code with caution.
- On Linux (Ubuntu/Debian): Run:
bash
sudo apt update sudo apt install git python3 libusb-1.0-0-dev
Use code with caution.
Step 2: Download ipwndfu
Clone the official repository from the axi0mX GitHub page: [1]
bash
git clone https://github.com/axi0mX/ipwndfu.git cd ipwndfu
Use code with caution.
2. How to Use ipwndfu
Step 1: Put your Apple device into DFU Mode
Connect your compatible device (iPhone 4S through iPhone X) to your computer using a USB-A to Lightning cable (USB-C to Lightning cables often do not work reliably for this exploit).
Follow the standard button combination for your specific device to enter DFU mode:
- For iPhone 6s and older: Hold the Power and Home buttons for 10 seconds. Release Power but continue holding Home until your computer detects a DFU device. The screen must remain completely black.
- For iPhone 7 / 7 Plus: Hold the Power and Volume Down buttons for 10 seconds. Release Power but keep holding Volume Down.
- For iPhone 8 / X: Press Volume Up, then Volume Down, then hold the Side button until the screen goes black. Quickly hold both the Side button and Volume Down for 5 seconds, then release the Side button while keeping Volume Down held.
Step 2: Trigger the Exploit (Pwned DFU Mode)
Once your device is in standard DFU mode, execute the exploit script in your terminal:
bash ./ipwndfu -p
Use code with caution.
(Note: On Linux, you may need to run this command with sudo if you haven’t configured your udev rules).
⚠️ Important: The checkm8 bootrom exploit relies on precise USB timing. It is highly unstable and will likely fail on the first few attempts. If it fails or errors out, hard-reboot your phone back into standard DFU mode and run the command again until you see a success message stating the device is in “pwned DFU mode”.
Step 3: Run Advanced Commands
Once the device is successfully exploited (the screen will still be black), you can execute other utility actions:
- Dump the SecureROM (Bootrom Data):
bash ./ipwndfu –dump-rom
Use code with caution.
- Decrypt a Firmware Keybag (for research/decryption):
bash
./ipwndfu –decrypt-gid <KEYBAG_HEX_STRING>
Use code with caution.
- Demote the device (to allow hardware JTAG debugging):
bash
./ipwndfu –demote
Use code with caution.
To exit pwned DFU mode at any time, simply force-restart your device using its physical buttons.
- Define all technical terms (DFU mode, bootrom exploit, SecureROM) clearly or link to authoritative sources.
- Provide clear, step-by-step instructions for common commands to demonstrate practical experience.
checkm8
- Permanent, unpatchable bootrom exploit for hundreds of millions of iOS devices
- Meant for researchers, this is not a jailbreak with Cydia yet
- Allows dumping SecureROM, decrypting keybags for iOS firmware, and demoting device for JTAG
- current SoC support: s5l8947x, s5l8950x, s5l8955x, s5l8960x, t8002, t8004, t8010, t8011, t8015
- future SoC support: s5l8940x, s5l8942x, s5l8945x, s5l8747x, t7000, t7001, s7002, s8000, s8001, s8003, t8012
- full jailbreak with Cydia on the latest iOS version is possible, but requires additional work
Quick start guide for checkm8
- Use a cable to connect the device to your Mac. Hold buttons as needed to enter DFU Mode.
- First run ./ipwndfu -p to exploit the device. Repeat the process if it fails; it is not reliable.
- Run ./ipwndfu –dump-rom to get a dump of SecureROM.
- Run ./ipwndfu –decrypt-gid KEYBAG to decrypt a keybag.
- Run ./ipwndfu –demote to demote device and enable JTAG.
Features
- Jailbreak and downgrade iPhone 3GS (new bootrom) with alloc8 untethered bootrom exploit. 🙂
Dependencies
This tool should be compatible with Mac and Linux. It won’t work in a virtual machine.
- libusb, If you are using Linux: install libusb using your package manager.
- ailbreak guide for iPhone 3GS (new bootrom)
Steps
Backup your data. Everything will be removed from your phone as it is a full restore.
Generate a custom 24Kpwn IPSW for iPhone 3GS (old bootrom).
Restore to this custom IPSW on your iPhone 3GS (new bootrom).
After restore is complete, your phone will connect back to your computer in DFU Mode. The screen will be black. This is expected. 24Kpwn exploit does not work on iPhone 3GS (new bootrom).
Use ipwndfu to put your device into pwned DFU Mode:
$ ./ipwndfu -p *** based on limera1n exploit (heap overflow) by geohot *** Found: CPID:8920 CPRV:15 CPFM:03 SCEP:03 BDID:00 ECID:XXXXXXXXXXXXXXXX SRTG:[iBoot-359.3.2] Device is now in pwned DFU Mode.
Once in pwned DFU Mode, use the -x flag to install the alloc8 exploit. This step will replace 24Kpwn exploit with alloc8.
$ ./ipwndfu -x Installing alloc8 exploit to NOR. Dumping NOR, part 1/8. Dumping NOR, part 2/8. Dumping NOR, part 3/8. Dumping NOR, part 4/8. Dumping NOR, part 5/8. Dumping NOR, part 6/8. Dumping NOR, part 7/8. Dumping NOR, part 8/8. NOR backed up to file: nor-backups/nor-XXXXXXXXXXXXXXXX-20170409-224258.dump Sending iBSS. Waiting for iBSS to enter Recovery Mode. Sending iBSS payload to flash NOR. Sending run command. If screen is not red, NOR was flashed successfully and device will reboot.
Notes:
Installation takes about 30 seconds. Once NOR is being flashed, the screen will be green for about 10 seconds, and then your phone will reboot.
If there are any errors before the screen turned green, it is safe to try again.
If the screen turns red, something went wrong while your phone was being flashed. Trying again probably won’t help.
If there are no issues, the phone will reboot and automatically boot into iOS.
3 second delay during boot when using a phone jailbroken with alloc8
alloc8 exploit takes about 3 seconds to run.
When your phone is off, to turn it on you will need to keep holding the Power button for at least 3 seconds, or your phone will not turn on. This might be because LLB protects against accidental presses of the Power button by shutting down the phone if the power button is not being held anymore. Without an exploit it takes less than a second before this check happens, but with alloc8 exploit it will happen after about 3 seconds. It might be possible to change this behavior by patching LLB.
If your phone enters deep sleep, there will be a 3 second delay before it wakes up. This can be fixed if you disable deep sleep with a tweak from Cydia, but your phone’s battery life will decrease.
Where to download older IPSWs
Always download IPSWs directly from Apple, because IPSWs from other sites could be infected with malware.
There is a trusted site where you can find legitimate Apple download links for older IPSW files:
https://ipsw.me/
How to create a 24Kpwn IPSW
iOS version
Tool
iOS 3.1
PwnageTool 3.1.3
iOS 3.1.2
PwnageTool 3.1.5
iOS 3.1.3
PwnageTool 3.1.5
iOS 4.0
PwnageTool 4.01
iOS 4.3.3
redsn0w 0.9.15 beta 3
iOS 5.0
redsn0w 0.9.15 beta 3
iOS 5.0.1
redsn0w 0.9.15 beta 3
iOS 5.1
redsn0w 0.9.15 beta 3
iOS 5.1.1
redsn0w 0.9.15 beta 3
Notes on using redsn0w 0.9.15b3
Q: Will this custom IPSW be used on a newer (fixed) version of the iPhone3GS? A: No
You must answer No to create a 24Kpwn IPSW using redsn0w. If you did this correctly, the name of the custom IPSW from redsn0w will start with NO_BB_OLDROM_iPhone2,1.
Compatibility with older iOS versions
Newer phones might not support some older versions of iOS. You cannot brick your phone by attempting to restore an older version of iOS, so it might be worth it to try anyway. If iTunes restore fails with Error 28, the hardware of your phone is not compatible with that version of iOS.
Manufactured
Error 28
Success
Week 38 2010
N/A
3.1+
Week 48 2010
N/A
3.1+
Week 3 2011
3.x
4.3.3+
Week 14 2011
3.x
4.0+
Week 23 2011
N/A
3.1.2+
Week 29 2011
3.x
4.0+
Week 36 2011
3.x
4.0+
Week 26 2012
3.x, 4.x
5.0+
You can find the week and year of manufacture by looking at the serial number of your phone. If your phone is from 2011 or 2012, help me expand this list and let me what versions worked or didn’t work.
Decoding iPhone 3GS serial number
Serial number: AABCCDDDEE AA = Device ID B = 2009=9, 2010=0, 2011=1, 2012=2 CC = Week of production DDD = Unique ID EE = Color
How to restore to a custom IPSW
Enter DFU Mode: https://www.theiphonewiki.com/wiki/DFU_Mode
Run exploit to put your phone into pwned DFU Mode. You can use ./ipwndfu -p.
Any version of iTunes should work. In iTunes, hold Option (or SHIFT if using Windows) and click Restore. You should be prompted to choose a file. Choose your custom IPSW.