The following is transcript of the Youtube video in this link: https://youtu.be/ftEuor1asBM?si=6HUBJWEQWEzj6SDv
The bulk of the text has been obtained with YouTube's built-in transcript feature, with the formatting fixed to look nice, and some grammer mistakes fixed that YouTube's transcript feature made. It is recommended to also view the video yourself, to have a full picture of the softmod video, especially to see stuff like the boot time comparison in the 4:54 mark.
There may be additional comments made by me, and will be indicated with the quote feature, like in this section. However, I have made sure that none of the original content from the video has been removed. The only additional things added are some headers, so that it's easier to link to certain sections.

Grimdoomer's Intro

All right, it's time to talk about the Xbox 360 soft mod. Fair warning, this video is going to be pretty low quality because I'm completely exhausted from getting this soft mod ready for release. So, just bear with my crappy editing on this one.

As many people already know, I've been working on a persistent soft mod for the Xbox 360 for about a year now. And in this video, I'm going to try and answer some of the questions people have and give you an idea of what to expect from it on release. This video isn't meant to be a step-by-step tutorial; it's only an overview of the soft mod and the features it includes.

With that out of the way, let's get into it. The name of the soft mod is Peer Pressure, and it's a persistent software-only exploit for the Xbox 360 that triggers during startup.

It's based on the previously released bad update exploit, but uses a new vulnerability I found to run during startup before the boot animation loads. This means once it's installed, your console will automatically boot right into a hack state every single time you turn it on, allowing you to have custom boot animations and boot straight to a homebrew dashboard of your choosing.

In order to use this exploit, you'll need an Xbox 360 console on the 17559 system software and a hard drive.

Unfortunately, due to some changes in the southbridge chip used in the Corona and Winchester models, the exploit does not work on those revisions. So, if you have one of those console revisions, you're out of luck. Other than the Corona and Winchester consoles, all other console revisions do work with this exploit.

By the way, what the community normally calls the "Winchester" motherboard is actually called the Barracuda motherboard, as shown by XenonLibrary.

Grimdoomer's brief exploit overview

Now, before I go any further, I'm going to give a very brief and very highle overview of how the peer pressure exploit works. For all the nitty-gritty technical details, you'll have to wait until part three of my hacking the Xbox 360 hypervisor blog series comes out.

There are two main components to this exploit, which are the SMC and the Southbridge. The NAND chip and hard drive are also involved, but they're more so just along for the ride and not doing anything inherently malicious. When the console boots up, it'll try and read a security sector off of the hard drive to validate it's a genuine Xbox hard drive.

When this happens, the SMC, which is running modified code I installed to the NAND, will perform witchcraft and get the Southbridge to copy a bunch of data from the NAND and hard drive into system memory, which ultimately allows me to corrupt a bunch of data and execute a ROP chain. This ROP chain bootstraps the rest of the bad update exploit, and once that finishes, your console is now in a hacked state and ready to run homebrew.

The name "Peer Pressure" comes from using the SMC Southbridge NAND and hard drive to "pressure" the CPU into executing malicious code. For those of you that know your Xbox exploits, you might be thinking this sounds similar to the old SMC JTAG hack, and that's because it is. This is basically the same concept, only instead of having to solder wires to the JTAG port on the motherboard, you need a hard drive with some bullshit I put on it.

Earlier, I mentioned that the Corona and Winchester models don't work with this exploit. And that's because the revision of the Southbridge chip they used actually has a hardware fix for these rogue DMA attacks using both the old SMC JTAG hack and the Peer Pressure exploit. Unfortunately, I didn't realize this until later in the development process. Otherwise, I probably would have canned this whole thing and just
released it as a POC. I know a lot of people are thinking the community will find a way around this, and unfortunately, unless you can find another boot time exploit, you're out of luck.

Boot Times

All right, let's talk about boot times. As you already know, bad update 1.3 is nearly instantaneous and nearly 100% reliable. This, however, is only half the exploit. The peer pressure part of the exploit, which involves the SMC, southbridge, and flash chip doing hackery while the security sectors read up the hard drive, is also a race condition attack. So, if the race timing is missed, the exploit won't trigger and the CPU will need to be reset. However, thanks to some clever SMC modifications, it can detect if the exploit fails at any stage and automatically reset the CPU for you.

This means, at best, your console will boot in a single attempt without needing to reset the CPU and at worst the SMC will reset it for you, adding a few seconds to the boot time. The last factor in how fast the console boots is the hard drive. The two things that will increase the boot time are how long the hard drive takes to spin up and how large it is. The hard drive has to be fully spun up before you can read data off it. The longer it takes to spin up, the longer the boot times will be.

By making a small modification to the hard drive SATA adapter, you can force the hard drive to spin up as soon as power is applied instead of waiting until the Xbox communicates with it. But the modification is difficult to make by hand, so unless you really want to speedrun the boot times, it's probably not worth making, especially if you're not comfortable with performing precision soldering.

As for the size of the hard drive, the time it takes to mount a FATX partition increases the larger the partition is. This is normally hidden by the console mounting the hard drive while the boot animation is playing. However, since the files needed to complete the exploit process are stored on the hard drive, I have to mount it before I can start playing the boot animation.

In this section, Grimdoomer shows a speed comparison between a retail console, a standard softmodded console, and one with the aformentioned SATA adapter modification. There's no boot time numbers mentioned in the original transcript, so this was the only section of the video I cut out of this transcript.

Hard Drives

Now, let's talk about what types of hard drives work with the exploit.

In all tests run thus far, every single 2.5" mechanical hard drive has worked with the exploit. The only drives that do not work are solid state drives or SSDs.

To make this explicitly clear, as long as you have a mechanical hard drive, it doesn't matter what brand, what size, if it's a genuine Microsoft Xbox 360 hard drive or not, if it's formatted to FATX or not, so long as it is a mechanical SATA hard drive, it will work with the exploit.

There's a lot of propaganda floating around about the hard drive needing to be a specific brand or model, and it's all bullshit. Find any 2.5" mechanical SATA hard drive, and it'll work just fine.

As for SSDs, the fastest rate at which I can attempt to exploit this race condition is on the order of milliseconds. The rate at which an SSD responds to a read request is around 100 microsconds, or around 10 times faster than how fast I can exploit the race condition.

While I have some ideas on how I can make them work with the exploit, it's a lot of effort for little benefit. Once I finish support for replacing the disc drive with a second hard drive, you'll be able to use your SSD in place of the disc drive, and you'll only need a mechanical drive to keep the exploit files on.

Installation

So, what do you actually need to install the soft mod?

You'll need any Xbox 360 console that's not a Corona or Winchester model, any mechanical 2 and 1/2 in SATA hard drive, and a USB stick.

Once you copy the soft installer files to the USB stick, plug it into your console and run Rock Band Blitz. Press A at the start menu and it'll boot into the softmod installer.

From here, you can back up your console CPU key, NAND image, and hard drive security sectors. Once that's done, you can install the soft mod, which will make necessary modifications to your console's NAND image, and copy the exploit files to the hard drive. Finally, the installer will perform a special reboot operation on your console to reset the SMC so the modifications take effect the next time you turn it on.

And that's it! Your console is now softmoded. When running the soft installer, you can provide additional homebrew apps to be installed at the same time. Things like Aurora, Freestyle Dash, XeLL, or updated versions of the original Xbox backwards compatibility emulator. This will set up your soft configuration file so you can boot straight into your homebrew dashboard the next time you turn your console on without any additional configuration required.

Boot Modes

Once the soft is installed, you'll have a few different modes you can boot your console in.

The default mode is softmod mode, which will boot your console with the soft mod enabled in full homebrew features.

The next is safe mode. By holding the sync button and pressing the eject button, your console will boot with the soft enabled but ignore your softmod configuration file. This mode can be used if you mess something up with your config file, homebrew dashboard, etc., and your console encounters issues getting to the dashboard.

The last mode is retail mode. By holding down the sync button and pressing the power button, your console will boot with the soft mod disabled in a completely stock state. No homebrew, no unsigned code, just completely stock Xbox 360. No matter what happens with the soft files, whether they get corrupted or deleted, you'll always be able to boot into retail mode and repair the softmod installation.

From the softmod configuration app, you can also change the behavior powering on the console via the eject button. You can choose between the default eject button behavior and booting XeLL.

One thing you'll need to keep in mind is that the soft install has two parts, the console part and the hard drive part. Both are required for the soft mod to work. If you remove your hard drive or connect one that doesn't have Peer Pressure installed, the console will only be able to boot in retail mode.

Similarly, putting a hard drive with Peer Pressure installed on an unmoded console will not allow you to use the softmod. Once peer pressure is installed on a hard drive, it can be used on any console that also has Peer Pressure installed, allowing you to share one hard drive between multiple soft modded consoles.

Additionally, if your hard drive is a genuine Xbox hard drive or has been modded to act like a genuine Xbox hard drive, you'll still be able to use it on an unmoded retail console even after installing the soft mod.

Homebrew Compatibility

So, you got the soft mod installed, your console's booted, let's talk about running homebrew.

When I decided to turn this exploit into a feature complete thing, I wanted a completely blank slate to start from.

With the peer pressure soft mod, you no longer need DashLaunch, and it's actually completely incompatible with the soft mod. Most of the features DashLaunch provides have already been implemented as mainline features in peer pressure, and some of which I have improved for better functionality. The one exception to this is the so-called plugin system.

DashLaunch plugins on boot-up

The DashLaunch plugin model was never intended to be used as extensively as it is today, which is why most of these plugins are incompatible with each other and require specific load orders. Many of these things are competing for the same address space in memory, and even worse are competing to hook the same OS functions and make god knows what modifications to the OS. The bottom line is that any plugin that hooks into the OS can cause compatibility issues with the soft mod and prevent me from adding new features later on.

After looking at all the different plugins people are using, they basically fall into one of three categories. So-called "stealth services", game specific plugins, or "other".

Stealth services

As far as stealth services go, there's no chance I'm going to help you steal access to a paid service so you can cheat in online video games. If that's all you want to use a soft mod for, don't even bother installing it and just stick to using other methods to hack your console.

Game-specific plugins

For game-specific plugins, I have plans to implement a new trainer system with better support for these things, but in the meantime, there's a side loading feature that can be used to load a DLL anytime a specific game is launched.
The sideloading feature is not meant to be used as a trainer system, but it can be used for plugins that do things like restore dead online services for various games.

Other plugins

For things in the "other" category, such as UI skinning, device drivers, etc., I've looked at some of these and scoped them out for potential mainline features in the softmod, but have no definitive plans for if or when that'll actually happen.

Outside of DashLaunch plugins, all other homebrew apps, games, etc. should work just fine.

Additional Features

Now, let's talk about the additional features the soft mod provides. The soft mod implements most of the typical OS patches that disable security and licensing checks, meaning all the games, DLC, etc. that work on an RGH console will also work on the softmod. There's a few additional restrictions that I've removed, and you'll be able to see a complete list of these once the softmod is released.

While the soft mod is active, Xbox Live access is disabled, so you can leave your console connected to the internet with the softmod installed and don't have to worry about getting banned. While I would like to say you can sign into Xbox Live while running in retail mode, I haven't confirmed if any of the modifications made by the softmod install can be detected by Xbox Live anti-cheat.

At the time of making this video, the anti-cheat system is not actually functioning correctly, so I can't even test this out using one of my own consoles.

Until it's been confirmed whether or not using Xbox Live in retail mode is safe, you'll have the option to disable Xbox Live access using parental controls when installing the soft mod.

The softmod also has a built-in autoupdate system, which will alert you whenever there's a new update available and allow you to download and install it automatically. If your console doesn't have internet access, you can also download the latest update manually and install it offline.

By default, the soft mod has a flash protection mechanism that blocks attempts to modify the console NAND image, which could render your console unable to boot in any mode. For people who understand the risks associated with tampering with the console NAND image, this feature can be temporarily disabled until the next reboot in the softmod settings app.

The softmod will also have a boot animation editor that can be used to customize the Blades-era boot animation and create theme files that can be shared with other people. Alternatively, the boot animation can be swapped out for a custom one using the softmod settings app.

At this time, I don't have any immediate plans to support customizing other versions of the boot animation, but perhaps I'll add it in a future update.

Unfortunately, exFAT support and dual hard drive support will not be in the first release of Peer Pressure. In order to get this release faster, I decided to move both of those features to the first major update, which will most likely not happen until early 2027.

While EXFAT and dual hard drive support are mostly complete, it'll take a month or two to finish them and do all the required testing to make sure they're up to par for daily use. Rather than delay the release any longer, I decided to cut them for the first release and ship them in an update.

RGH Support

Some people might be wondering if they'll be able to use this on their RGH console, and the answer is not right now. Testing all the different configurations for this exploit is already difficult enough and trying to add proper RGH support will make this even more difficult and timeconuming.

It is possible to flash a stock NAND image to your RGH console and then install the soft mod that way.

However, be warned: depending on what wiring method you use for the RGH install, leaving the wires connected while running non-RGH SMC code could cause stability issues or potentially damage your console if left that way long term. If you're using a modchip-based install, you'll probably be fine if you disable the modchip before installing the soft mod. At this time, I don't have any definitive plans to add proper RGH support as it just complicates the testing process and makes it even more time conuming.

When it comes to modchip-based installs (RGH 1.2 and S-RGH in particular), their timing files can properly support retail NAND images just fine, so I doubt this will be an issue at all.
As for RGH3 consoles, the motherboard models compatible with Peer Pressure can also boot retail with RGH3 wiring installed as long as the SMC firmware has the NO_DBG_CHK patch, as mentioned on ConsoleMods. Weather Grimdoomer wants to implement this feature or not in his own Peer Pressure SMC firmware remains to be seen.

Release Date

I believe due to leak shenanigans, the beta tester application form has been closed to the public.

And finally, the thing everyone has been waiting for. The soft mod has been in beta testing for a few weeks now, and as long as no major issues are found, I'll most likely release it sometime between October 2nd and October 9th. If you have a supported console type and a hardware NAND flasher and would like to sign up to join the beta test, you can find the sign up link in the description of this video. That's all for this video. See you next time.

Edit

Pub: 04 Oct 2026 23:56 UTC

Edit: 05 Oct 2026 05:00 UTC

Views: 289