01

Target Board & Base Firmware

Pick your board model. If you haven't flashed the base firmware yet, hold BOOTSEL on your board, plug it in, and copy the .uf2 file to the RPI-RP2 drive.

123 KB UF2
02

Flash Boot Payload (iBSS.boot)

Provide the iBSS.boot stitched payload generated for your device (e.g. from surrealra1n). The tool compresses it in-browser with LZ4 and writes it to flash offset 0x10020000 over USB Serial.

Select or drag & drop iBSS.boot Typically 2.0 – 2.8 MB raw payload
03

LED Operating Guide

Once flashed, SurrealBoot runs standalone without a computer. Connect the RP2350 to power, plug in the iPhone, and follow the RGB LED states:

  • Solid Orange
    Idle / Listening for USB host connection.
  • Solid Magenta (Countdown)
    Recovery detected. Hold Volume Down + Power. Board injects reboot packet at tick 2.
  • Solid Cyan
    Release Power, keep holding Volume Down for 8s.
  • Blinking White
    Release all buttons. Waiting for DFU enumeration.
  • Solid Blue
    Running USBLiter8 exploit.
  • Solid Green
    Boot payload streamed to memory. iPhone boots!
04

Hardware Notes

Waveshare RP2350 USB-A

The USB-A female port is wired directly to VSYS for 5V power and GP12/13 for data. Our firmware automatically handles the board's onboard R13 resistor with active USB bus resets.

Cables & Connection

Use a standard USB-A to Lightning cable connected between the board's USB-A host port and the iPhone. Keep the board powered via USB-C or 5V pin.

Supported Hardware

View the supported devices wiki →