Skip to content
gtxaspec edited this page Jul 25, 2026 · 1 revision

Every Ingenic SoC has a permanent recovery mode built into the chip itself, called USB boot mode. In this mode the camera shows up as a USB device on your computer, and flashing tools like the Web Flasher and thingino-dfu can read and write the camera's flash chip directly. No disassembly of the flash chip, no soldering, no serial adapter.

Because it lives in the chip's boot ROM, USB boot mode always works, even on a completely "bricked" camera with corrupted or erased firmware. It is the standard way to install thingino and to recover a device.

Note

Older guides call this "Cloner mode" or "USB Cloner mode". It is the exact same mode; only the tools have changed. Cloner is the legacy method and is no longer officially supported.

What you need

  • A USB cable that fits your camera's port (or a soldered connection, see tips below)
  • A computer with a free USB port

Important

Some cameras have power-only USB ports with no data lines connected. If your device is never detected no matter what you try, see the tips section.

Entering USB boot mode

There are three ways to get a camera into USB boot mode. Start with the first one that applies to your device.

Method 1: Blank flash (automatic)

If the flash chip is blank, erased, or the bootloader is corrupted, the SoC finds nothing to boot and drops into USB boot mode by itself. Just connect the camera to your computer via USB.

This is why a "bricked" camera is usually easy to recover: it is already waiting for you in USB boot mode.

Method 2: OTG adapter (no disassembly, some devices)

Some cameras with a Micro-USB port enter USB boot mode when powered through an OTG adapter. No opening of the case required.

You need a Micro-USB OTG adapter and a USB-A to USB-A cable:

Micro-USB OTG Adapter USB-A to USB-A Cable

Important

A standard USB to Micro-USB cable will NOT work for this method.

  1. Attach the OTG adapter to the camera's Micro-USB port
  2. Connect the USB-A to USB-A cable between the OTG adapter and your computer
  3. The camera powers on and enters USB boot mode automatically

Video of the process: https://www.youtube.com/shorts/sRiBUtaGxl4

Devices confirmed to work with the OTG method:

  • Eufy Outdoor E210, Indoor E220, Indoor C120
  • Wyze Pan v2
  • Wyze Doorbell V1

Devices where the OTG method does not work (use Method 3 instead):

  • Wyze Cam V2 / NEOS SmartCam
  • Wyze Cam V3

Method 3: Shorting the flash chip (works on any NOR device)

The universal method: briefly short two pins of the flash chip while plugging the camera in. This makes the first boot attempt fail, so the SoC falls back to USB boot mode.

Locate the flash memory chip on the camera circuit board. Typically this is a square chip with 8 pins labeled 25Q64 or 25Q128, rarely 25L64 or 25L128. If you have trouble locating the chip, take some pictures of both sides of your board and reach out to our community for assistance.

Pins 5 and 6 of the SOIC8 chip are on the opposite corner of pin 1, which is indicated by the embossed or drawn dot next to it.

  1. Make sure the camera is completely unplugged
  2. Connect the USB cable to the camera, but leave the computer end disconnected
  3. Short-circuit pins 5 and 6 of the flash chip with a small metal object, such as a screwdriver or tweezers

  1. While maintaining the short, connect the USB cable to the computer
  2. Wait about 1-2 seconds, then release the short

Caution

Short pins 5 and 6 on the flash chip only, not on the SoC or any other chip. Do not try to short-circuit any random chip! It will most likely burn your camera circuit.

Checking the connection

A camera in USB boot mode identifies itself as an Ingenic USB Boot Device (USB ID a108:c309).

On Linux, run sudo dmesg | tail after plugging in. You should see something like:

usb 3-3.1: New USB device found, idVendor=a108, idProduct=c309, bcdDevice= 1.00
usb 3-3.1: Product: USB Boot Device
usb 3-3.1: Manufacturer: Ingenic

On Windows, check Device Manager for a new device. Note that Windows needs a one-time driver install before flashing tools can use the device: run Zadig and install the WinUSB driver. See the Windows Setup guide for details. If the old Ingenic vendor driver (libusb0) is installed, remove it first; it is not compatible with the current tools.

In the Web Flasher, the camera simply appears in the device list after you click Connect.

If nothing shows up, unplug, and repeat the method. With Method 3, the timing of the short takes a couple of tries for most people.

Next step: flash your firmware

Once the camera is in USB boot mode, you are ready to install thingino:

  • Web Flasher: flash straight from your browser (Chrome or Edge), no software to install
  • thingino-dfu: command line tool for Linux, Windows, macOS, and Android

Both tools detect the SoC automatically, and both can make a full backup of your stock firmware before you write anything. Make a backup first.

Tips

Borrow a USB port from the WiFi module

If your camera has a USB wireless module, the camera's own USB port is most likely power-only and cannot be used. You can make a makeshift connection by borrowing the USB data wires from the wireless module. Locate the DP/D+ and DN/D- pads on the USB wireless module and solder the data wires from a stripped USB cable to them, like shown below.

USB wifi module pins

Force USB boot mode from a running system (advanced)

If you have shell access to a running system, you can erase the bootloader so the SoC drops into USB boot mode on the next power-up (see Method 1).

Caution

This is irreversible until you flash new firmware. Only do this if you intend to reflash the device immediately, and know how to recover it.

From a U-Boot shell:

sf probe; sf erase 0 +1; reset

From a Linux shell:

flash_eraseall /dev/mtd0 && restart -f

Legacy: cloner

The old flashing method, Ingenic USB Cloner, used this same USB boot mode with Ingenic's proprietary PC utility. Cloner is no longer officially supported; use the Web Flasher or thingino-dfu instead.

  1. Wiki Home
  2. About the Project
    1. Contributions
    2. Features
    3. Project Philosophy
    4. Releases
  3. Getting Started
    1. FAQ
    2. Glossary
    3. Hardware Identification
    4. Image Builder
    5. USB Boot Mode
    6. Ingenic USB Cloner
      1. OTG Booting
    7. PPSTRONG
    8. Installation: General
    9. Installation: No Tools Methods
    10. Resources and Links
    11. Support Community
    12. Troubleshooting
    13. UART Connection
    14. Updating Firmware
    15. Unbricking
    16. Web UI
  4. Supported Cameras
    1. Cameras
    2. 360 AP1PA3
    3. AliExpress LTIA‐37FJZ (Vanhua Z55 module)
    4. AOQEE C1
    5. Aosu C5L
    6. Cinnado
      1. Cinnado D1 2K
      2. Cinnado D1 3K
    7. Dekco DC5L
    8. Eufy
      1. Eufy E210 Outdoor Cam
      2. Eufy E220
    9. Galayou/Wansview
      1. Galayou G2
      2. Galayou G7
      3. Wansview W6
      4. Wansview W7/Galayou Y4
    10. Hualai (Wyze/Atom/Neos/Personal)
      1. Dafang Upgrading for Wyze v2
      2. NEOS conversion
      3. Personal Cam Pan and Cam 2
      4. Wyze Cam Pan V1
      5. Wyze Doorbell (V1)
        1. Chime Reverse Engineering
        2. Flashing VDB1 over UART (YMODEM)
        3. MQTT Control and Monitoring
      6. Wyze v2/Neos SmartCam/ATOM Cam 1
      7. Wyze v3
      8. Wyze Accessories
    11. iFlytek XFP301‐M
    12. Jienuo JN-107-AR-E-WIFI
    13. Jooan A6M
    14. LaView L2
    15. LongPlus X07
    16. LSC 3215672
    17. Sannce I21AG
    18. Sonoff Cam‐S2 and B1P
    19. TP-Link Tapo C100/C110/C111
    20. Wuuk Y0510
    21. Xiaomi
      1. Xiaomi Mijia1080p (SXJ02ZM)
      2. Xiaomi MJSXJ03HL
      3. Xiaomi Outdoor Camera AW200 (MJSXJ05HL)
  5. Configuration
    1. Administration
    2. Automation
      1. Configuring camera using runonce.sh script
    3. Cron jobs
    4. General
    5. LED Indicators
    6. Lighting
    7. Media Streaming Endpoints
    8. Network Storage
    9. Networking
      1. DHCP: Timezone
      2. Wireless Networking
      3. USB Direct w CDC (NCM)
      4. USB Ethernet Networking
      5. Remote Access
      6. VPN
        1. Tailscale
        2. Wireguard
        3. Zerotier
      7. Wi-Fi
        1. Self Hosted AP
        2. Tips and Tricks
      8. WWAN (Cellular)
    10. Night Mode
    11. ONVIF
    12. OSD (On-screen Display)
    13. Plugins
      1. Motion Guard
      2. Yandex Disk
    14. SSH Access Keys
    15. Wi-Fi Access
    16. Provisioning
    17. Streamer Bitrate Control
    18. Video Rotation
  6. Integration
    1. Home Assistant
    2. Frigate
    3. Ingenic A1/$15 NVR
    4. LightNVR
    5. Mobile Apps
    6. MQTT Integration
    7. Virtual Webcam on Linux
    8. Mainsail (Klipper)
  7. Development
    1. Booting
      1. Boot: MMC SD
      2. Boot: NFS
    2. CH341A Programmer
    3. RTSP Players
    4. Flash Chips
    5. go2rtc
    6. Porting Guide
    7. Ingenic Platform Capability Matrix
    8. Ingenic Image Processor
    9. ISP Reserved Memory (RMEM)
    10. Debugging
    11. Software
      1. Building From Sources
      2. Buildroot
      3. Toolchain
      4. Choice of JSON library
    12. SSL and TLS Web UI in thingino
    13. Tech Info
      1. Hardware
      2. PWM Info
      3. Supported Hardware
      4. T23 GPIOs
      5. T31 GPIOs
    14. U-Boot Cheatsheet
    15. Zeratul/Atlas/Tassadar
    16. Resources

Clone this wiki locally