CLI tool
geo-tp/ESP32-Bit-Pirate avatar
geo-tp/ESP32-Bit-Pirate

ESP32 Bit Pirate: a multi-protocol hardware hacking tool with a web-based CLI

A Hardware Hacking Tool with Web-Based CLI That Speaks Every Protocol

5,930 stars497 forksC++MIT

At a glance

What is it?
ESP32 Bit Pirate is MIT-licensed ESP32 firmware that puts Bus Pirate-style protocol work behind a serial or browser CLI. It is broad by design, and the breadth is also where its limits start.
Who is it for?
Adopt ESP32 Bit Pirate if you already own one of the supported boards and want one firmware that covers I2C, SPI, UART, JTAG, radio and more from a single CLI. Skip it if you need one narrow protocol done precisely, or if your hardware is not on the supported list, because the README names specific devices only.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 1 day ago.
What is it written in?
Mainly C++, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 30, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The gap ESP32 Bit Pirate fills between a Bus Pirate and a pile of adapters

Hardware work usually starts with a drawer of single-purpose adapters: a USB-UART bridge, an SPI programmer, a logic analyzer, an IR blaster, a Sub-GHz dongle. ESP32 Bit Pirate collapses that into one ESP32-S3 board running firmware that presents each capability as a mode in a command-line interface. The README describes it as "open-source firmware that turns your device into a multi-protocol development and analysis tool, inspired by the legendary Bus Pirate."

The intended user is someone doing bench-level protocol work: reading an EEPROM over I2C, sniffing a UART line, dumping SPI flash, scanning a JTAG chain, or replaying a Sub-GHz signal. It is not a consumer gadget. You get a CLI, a set of modes, and the expectation that you know what SDA, SCL, MOSI and CS mean. The project also targets people who want scripting, since it supports Bus Pirate-style bytecode instructions and Python.

How modes, the CLI and LittleFS fit together

The architecture is mode-based. A session starts in HiZ, the default high-impedance state, and you switch into a protocol mode such as I2C, SPI, UART, 1WIRE, JTAG, CAN, SUBGHZ or RFID. Each mode exposes its own commands: I2C has scan, glitch, slave mode, dump and eeprom; SPI has eeprom, flash, sdcard and slave mode; DIO handles digital I/O with read, pullup, set and pwm. The mode is the unit of configuration, which keeps pin assignments and timing tied to the protocol you selected rather than to global settings.

The interface is reachable two ways. Over USB serial, or over Wi-Fi through a web-based CLI. The README also points to web serial tools that let a browser talk to the USB serial port, so you do not need a local terminal emulator. Data moves in and out through LittleFS, the on-device filesystem, which the README says can be imported and exported over HTTP. Sniffers exist for I2C, UART, SPI, 1Wire, 2wire, CAN, Wi-Fi, Bluetooth and SubGhz, so capture is a first-class part of the design rather than an add-on. A helper called Pirate assistant is documented as assisting with the firmware itself.

Installing ESP32 Bit Pirate from the web flasher

The project does not ask you to build from source first. The README directs users to the official website, where an install page flashes the firmware to a supported board. This is the shortest path and the one the documentation leads with.

Open the web flasher in a browser that supports Web Serial:

bash
https://geo-tp.github.io/ESP32-Bit-Pirate/webflasher/

Connect the board over USB, select the port when the browser prompts, and flash. After the board reboots, open the serial terminal or the web CLI. The first thing you should see is the CLI prompt in HiZ mode, which is the default state described in the README.

From there, switching into a mode is the first real action. The README lists the modes with their wiki pages, so the sequence is: pick the mode, wire the pins for that protocol, then run the mode's commands. For a first pass on an unknown I2C bus, the I2C mode offers a scan command alongside glitch, slave mode, dump and eeprom operations. If you prefer to build the firmware yourself, the repository carries a platformio.ini at the top level and the default branch is named pioarduino, which tells you the build system without the README spelling it out.

Where the breadth becomes a liability

Supporting I2C, SPI, UART, 1-Wire, 2-Wire, 3-Wire, JTAG, CAN, Sub-GHz, RFID, RF24, FM, LoRa, cellular, infrared, USB, Bluetooth and Wi-Fi on one microcontroller is an enormous surface area. The practical consequence is that any single mode gets less depth than a dedicated instrument. A standalone logic analyzer samples faster and buffers more; a dedicated SPI programmer has mature flash database support; a purpose-built Sub-GHz tool has better receive sensitivity. ESP32 Bit Pirate is the tool you reach for when you want one device that does many things adequately, not the tool you reach for when one measurement must be exact.

The second constraint is hardware. The README lists supported devices explicitly: ESP32 S3 Dev Kit, M5 AtomS3 Lite, M5 Cardputer, M5 Cardputer ADV, M5 StampS3, M5 Stick S3, LILYGO T-Display, LILYGO T-Embed, LILYGO T-Embed CC1101, and the list continues. GPIO counts differ sharply across them, from 8 on the AtomS3 Lite to more than 20 on the S3 Dev Kit. A mode that needs several pins may simply not fit on a smaller board. The README does not document rollback to a previous firmware version, so treat flashing as a one-way step until you confirm otherwise.

ESP32 Bit Pirate against a Bus Pirate and against Flipper Zero

The Bus Pirate is the obvious reference point, and the project says so itself. A Bus Pirate is dedicated hardware with a USB interface and a long-established command set. ESP32 Bit Pirate runs on commodity ESP32-S3 boards, costs whatever the board costs, and adds Wi-Fi and Bluetooth that a classic Bus Pirate does not have. The trade is that you supply the board, the wiring and the pin mapping, and you depend on the project's device support rather than on a fixed hardware design.

Flipper Zero is the other comparison the topics list invites, since flipperzero appears among them. Flipper is a self-contained handheld with its own screen and controls. ESP32 Bit Pirate on an M5 Cardputer, which the README describes as having a screen, keyboard, mic, speaker, IR TX, SD card and battery, moves in that direction, and the README documents a standalone mode for the Cardputer. But the primary interface remains a serial or web CLI, so the workflow is closer to a bench instrument tethered to a laptop than to a pocket device. Choose the Bus Pirate if you want fixed, predictable hardware; choose Flipper if you want a handheld; choose this if you already have a supported ESP32-S3 board and want protocol coverage without buying another instrument.

Licence, releases and what upgrading costs you

The repository is MIT licensed, which is permissive and places few conditions on reuse. The practical implication for anyone embedding this firmware in a product is that MIT still requires the copyright notice and permission notice to be preserved, and it offers no warranty. That is a statement about the licence text, not legal advice; check the LICENSE file in the repository root for the exact wording.

Releases are tagged and dated: v1.5 on 2026-03-12, v1.6 on 2026-06-05, v1.7 on 2026-08-06. The last push to the default branch was on 2026-09-16, so the project is not archived and development has continued past the most recent release. The upgrade cost is the same as the install cost: reflash the board. Because the README does not document a downgrade path or a settings-migration story, treat each version bump as a full replacement and keep your own copy of any scripts or captured data you store on LittleFS. The repository also carries a test directory and a webui directory alongside src and lib, which suggests the web interface is maintained in-tree rather than as a separate project.

Editorial conclusion

Adopt ESP32 Bit Pirate if you already own one of the supported boards and want one firmware that covers I2C, SPI, UART, JTAG, radio and more from a single CLI. Skip it if you need one narrow protocol done precisely, or if your hardware is not on the supported list, because the README names specific devices only. Before flashing, verify your exact board variant appears in the supported devices table and confirm the wiring for the mode you intend to use on the project wiki page for that mode.

Frequently asked questions

What is ESP32 Bit Pirate?

It is open-source firmware that turns a supported ESP32 board into a multi-protocol development and analysis tool, inspired by the Bus Pirate. It exposes digital protocols such as I2C, SPI, UART and JTAG, plus radio work including Bluetooth, Wi-Fi, Sub-GHz and RFID, through a serial terminal or web-based CLI.

Is ESP32 a 32-bit processor?

The firmware targets ESP32-S3 boards, which the README lists by name as supported devices, including the ESP32 S3 Dev Kit, M5 AtomS3 Lite, M5 Cardputer, M5 StampS3 and M5 Stick S3. The README does not otherwise discuss the processor architecture.

What is a bus pirate?

The README states that ESP32 Bit Pirate is inspired by the Bus Pirate and that its scripting uses Bus Pirate-style bytecode instructions. The project presents itself as an open-source firmware alternative to that class of tool, running on commodity ESP32 boards.

What is the ESP32 microcontroller used for?

In this project the ESP32-S3 is used to run firmware that sniffs, sends and scripts digital protocols such as I2C, SPI, UART, 1-Wire, JTAG and CAN, and radio protocols including Bluetooth, Wi-Fi, Sub-GHz and RFID. The README lists the supported boards and the modes each session can switch into.

Which ESP32 is most powerful?

The README does not rank ESP32 variants by capability. It lists supported boards with their GPIO counts, from 8 GPIO on the M5 AtomS3 Lite to more than 20 on the ESP32 S3 Dev Kit, which is the comparison the documentation actually provides.

Official sources

  1. geo-tp/ESP32-Bit-Pirate on GitHub
  2. License: MIT
  3. Project website
  4. README
  5. Releases
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/geo-tp-esp32-bit-pirate.svg)](https://hysenlabs.com/projects/geo-tp-esp32-bit-pirate)