-
Notifications
You must be signed in to change notification settings - Fork 0
ATK FIERCE X Protocol Notes
This page tracks the current reverse-engineering state for the ATK FIERCE X using ATK V HUB Web at https://hub.atk.pro/.
These notes are based on WebHID captures from the local sniffer in tools/webhid-sniffer-extension.
| Field | Value |
|---|---|
| Product string | ATK Mouse 8K Dongle |
| Vendor ID | 0x373B |
| Product ID | 0x101B |
| WebHID report ID | 8 |
| Frame size | 16 bytes |
| Config usage page | 0xFF02 |
| Config usage | 0x0002 |
ATK uses the same 16-byte payload shape and global checksum rule as the IPI FLY PRO:
byte[0] = (0x4D - sum(byte[2..=15])) & 0xFFMost ATK settings are not IPI-compatible commands. They are block writes where values are stored as value/check pairs:
check = 0x55 - valueThe active DPI stage is stored in the 0x00 block. Bytes 9/10 carry the stage index and check byte.
stage 1: 07 00 00 00 08 20 35 04 51 00 55 00 00 00 00 3f
stage 2: 07 00 00 00 08 20 35 04 51 01 54 00 00 00 00 3f
stage 3: 07 00 00 00 08 20 35 04 51 02 53 00 00 00 00 3f
stage 4: 07 00 00 00 08 20 35 04 51 03 52 00 00 00 00 3fPolling is stored in the same 0x00 block. Bytes 5/6 carry the polling value and check byte.
125 Hz -> 08 4d
250 Hz -> 04 51
500 Hz -> 02 53
1000 Hz -> 01 54
2000 Hz -> 10 45
4000 Hz -> 20 35
8000 Hz -> 40 15Captured with active stage 4:
125 Hz: 07 00 00 00 08 08 4d 04 51 03 52 00 00 00 00 3f
250 Hz: 07 00 00 00 08 04 51 04 51 03 52 00 00 00 00 3f
500 Hz: 07 00 00 00 08 02 53 04 51 03 52 00 00 00 00 3f
1000 Hz: 07 00 00 00 08 01 54 04 51 03 52 00 00 00 00 3f
2000 Hz: 07 00 00 00 08 10 45 04 51 03 52 00 00 00 00 3f
4000 Hz: 07 00 00 00 08 20 35 04 51 03 52 00 00 00 00 3f
8000 Hz: 07 00 00 00 08 40 15 04 51 03 52 00 00 00 00 3fChanging DPI writes four 8-byte blocks. A DPI value group appears to use:
[raw, raw, flags_or_hi, group_check]
group_check = (0x255 - raw - raw - flags_or_hi) & 0xFFLikely encoding:
dpi = (raw + 1) * 10
raw = (dpi / 10) - 1Examples:
0x4f -> 800 DPI
0x59 -> 900 DPI
0x9f -> 1600 DPIMore fixed-value captures are still needed before implementing DPI writes.
off: 07 00 00 4c 08 00 00 80 d5 03 52 00 55 00 00 f3
solid: 07 00 00 4c 08 01 54 80 d5 03 52 01 54 00 00 9e
breathing: 07 00 00 4c 08 02 53 80 d5 03 52 01 54 00 00 9eDebounce is stored in the 0xA9 block. Bytes 5/6 are the debounce value in milliseconds and its check byte.
0 ms -> 00 55
1 ms -> 01 54
2 ms -> 02 53
4 ms -> 04 51
8 ms -> 08 4d
15 ms -> 0f 46
20 ms -> 14 41Sleep is also stored in the 0xA9 block. Bytes 9/10 are the raw timer and check byte.
raw = seconds / 10Confirmed:
30 s -> 03 52
1 min -> 06 4f
2 min -> 0c 49
3 min -> 12 43
5 min -> 1e 37
20 min -> 78 dd
25 min -> 96 bf
30 min -> b4 a1Changing sleep also emits a 0xB5 write with the same timer raw value. Treat this as part of the sleep write sequence until proven otherwise.
All three are in the 0xA9 block and use 00 55 for off, 01 54 for on.
byte[7..8] Motion Sync
byte[11..12] Linear Correction
byte[13..14] Ripple CorrectionExamples:
Motion Sync on: 07 00 00 a9 0a 08 4d 01 54 03 52 00 55 00 55 ea
Linear on: 07 00 00 a9 0a 08 4d 00 55 03 52 01 54 00 55 ea
Ripple on: 07 00 00 a9 0a 08 4d 00 55 03 52 00 55 01 54 eaon: 16 00 00 00 0a 01 00 00 00 00 00 00 00 00 00 2c
off: 16 00 00 00 0a 00 00 00 00 00 00 00 00 00 00 2dOnly the mode byte is mapped so far. Other bytes likely encode color, brightness and speed.
off: 18 00 00 00 0a 00 ff 00 08 05 09 01 00 00 00 15
color stream: 18 00 00 00 0a 01 ff 00 08 05 09 01 00 00 00 14
single-color breathing: 18 00 00 00 0a 02 ff 00 08 05 09 01 00 00 00 13
single-color solid: 18 00 00 00 0a 03 ff 00 08 05 09 01 00 00 00 12
neon: 18 00 00 00 0a 04 ff 00 08 05 09 01 00 00 00 11
mixed-color breathing: 18 00 00 00 0a 05 ff 00 08 05 09 01 00 00 00 10
colorful solid: 18 00 00 00 0a 06 ff 00 08 05 09 01 00 00 00 0f- Confirm fixed DPI values for
800,900,1600and1800. - Capture all visible lift-off distance options with exact UI labels.
- Capture RGB color, brightness and speed one field at a time.
- Identify firmware/version reads.
- Capture one simple button remap.