# Hackbat ESP32 (The Hackbat)

> An open-hardware pentest board you order from the fab yourself: ESP32-C6 with Wi-Fi 6 and BLE, a CC1101 sub-GHz radio, OLED and SD card.

- **Category:** Multitools
- **Availability:** In development
- **Good for:** Build your own sub-GHz and Wi-Fi pentest board from open files.
- **You'll need:** A JLCPCB order with the published BOM and centroid files, and your own firmware.
- **Trade-off:** Not sold assembled; the C6 version is still under test and has no NFC.
- **Page:** https://gadgets.sh/devices/hackbat/

## Where to buy

| Shop | Status | Link |
|---|---|---|
| The Hackbat | Source repository | https://github.com/thehackbat/hackbat_esp32?utm_source=gadgets.sh&utm_medium=referral&utm_campaign=hackbat&utm_content=api |

## Blueprint

**Open hardware.** Both the current ESP32-C6 'Hackbat ESP32' and its RP2040-based predecessor are open hardware: KiCad schematic/PCB, Gerbers and BOM are published on GitHub by the same maker.

### Design files

- schematic: [Hackbat ESP32 schematic (KiCad)](https://github.com/thehackbat/hackbat_esp32/blob/main/kicad/hackbat.kicad_sch) (KiCad)
- pcb: [Hackbat ESP32 PCB (KiCad)](https://github.com/thehackbat/hackbat_esp32/blob/main/kicad/hackbat.kicad_pcb) (KiCad)
- gerbers: [Hackbat ESP32 Gerbers (folder)](https://github.com/thehackbat/hackbat_esp32/tree/main/kicad/production_files/gerber) (Gerber)
- bom: [Hackbat ESP32 BOM (CSV)](https://github.com/thehackbat/hackbat_esp32/blob/main/kicad/production_files/bom.csv) (CSV)
- schematic: [Original RP2040 HackBat schematic (KiCad)](https://github.com/controlpaths/hackbat/blob/main/kicad/hackbat/hackbat.kicad_sch) (KiCad)
- pcb: [Original RP2040 HackBat PCB + Gerbers (folder)](https://github.com/controlpaths/hackbat/tree/main/kicad/hackbat/output_files) (Gerber)

### Source repositories

- [thehackbat/hackbat_esp32](https://github.com/thehackbat/hackbat_esp32) — hardware, ★12
- [controlpaths/hackbat](https://github.com/controlpaths/hackbat) — hardware, CC0-1.0, ★1001

### Key parts

| Part | Role | Datasheet |
|---|---|---|
| TI CC1101 | sub-GHz radio (315/433/868/915 MHz) | https://www.ti.com/product/CC1101 |
| Espressif ESP32-C6-WROOM-1 | MCU (current ESP32 version) | https://www.espressif.com/sites/default/files/documentation/esp32-c6_datasheet_en.pdf |
| Raspberry Pi RP2040 | MCU (original version) | https://datasheets.raspberrypi.com/rp2040/rp2040-datasheet.pdf |
| NXP/ams PN532 | 13.56 MHz NFC (original RP2040 version only) |  |

_Notes:_ thehackbat/hackbat_esp32 README states it is the 'new version...based on the ESP32 C6', superseding controlpaths/hackbat's RP2040 design; both list the same JLCPCB affiliate link ('?from=controlpath'), indicating the same maker/lineage. Both repos' KiCad/Gerber/BOM links curl-verified 200; thehackbat_esp32 carries no LICENSE file despite being described as open-source, controlpaths/hackbat is CC0-1.0.

### Raw source files

Direct links an agent or KiCad can open (the viewer on the page reads the same files).

- KiCad project **Original RP2040 HackBat schematic (KiCad)** (controlpaths/hackbat): [hackbat.kicad_pro](https://raw.githubusercontent.com/controlpaths/hackbat/main/kicad/hackbat/hackbat.kicad_pro), [dio.kicad_sch](https://raw.githubusercontent.com/controlpaths/hackbat/main/kicad/hackbat/dio.kicad_sch), [dio_oled.kicad_sch](https://raw.githubusercontent.com/controlpaths/hackbat/main/kicad/hackbat/dio_oled.kicad_sch), [hackbat.kicad_sch](https://raw.githubusercontent.com/controlpaths/hackbat/main/kicad/hackbat/hackbat.kicad_sch), [nfc.kicad_sch](https://raw.githubusercontent.com/controlpaths/hackbat/main/kicad/hackbat/nfc.kicad_sch), [rf.kicad_sch](https://raw.githubusercontent.com/controlpaths/hackbat/main/kicad/hackbat/rf.kicad_sch), [rp2040.kicad_sch](https://raw.githubusercontent.com/controlpaths/hackbat/main/kicad/hackbat/rp2040.kicad_sch), [supply.kicad_sch](https://raw.githubusercontent.com/controlpaths/hackbat/main/kicad/hackbat/supply.kicad_sch), [wifi.kicad_sch](https://raw.githubusercontent.com/controlpaths/hackbat/main/kicad/hackbat/wifi.kicad_sch), [hackbat.kicad_pcb](https://raw.githubusercontent.com/controlpaths/hackbat/main/kicad/hackbat/hackbat.kicad_pcb)
- KiCad project **Hackbat ESP32 schematic (KiCad)** (thehackbat/hackbat_esp32): [hackbat.kicad_pro](https://raw.githubusercontent.com/thehackbat/hackbat_esp32/main/kicad/hackbat.kicad_pro), [RF.kicad_sch](https://raw.githubusercontent.com/thehackbat/hackbat_esp32/main/kicad/RF.kicad_sch), [esp32c6.kicad_sch](https://raw.githubusercontent.com/thehackbat/hackbat_esp32/main/kicad/esp32c6.kicad_sch), [hackbat.kicad_sch](https://raw.githubusercontent.com/thehackbat/hackbat_esp32/main/kicad/hackbat.kicad_sch), [io.kicad_sch](https://raw.githubusercontent.com/thehackbat/hackbat_esp32/main/kicad/io.kicad_sch), [oled.kicad_sch](https://raw.githubusercontent.com/thehackbat/hackbat_esp32/main/kicad/oled.kicad_sch), [power.kicad_sch](https://raw.githubusercontent.com/thehackbat/hackbat_esp32/main/kicad/power.kicad_sch), [sd_card.kicad_sch](https://raw.githubusercontent.com/thehackbat/hackbat_esp32/main/kicad/sd_card.kicad_sch), [hackbat.kicad_pcb](https://raw.githubusercontent.com/thehackbat/hackbat_esp32/main/kicad/hackbat.kicad_pcb)

## Specifications

### Hackbat ESP32 (current version)

| | |
|---|---|
| Microcontroller | ESP32-C6 WROOM-1; compatible with the 1U variant for an external antenna |
| Sub-GHz radio | TI CC1101 for 315, 433, 868 and 915 MHz ISM/SRD bands; on-board antenna, J2 for SMA |
| Display | Monochrome OLED, SH1106 or SSD1306 drivers in ESP-IDF |
| Storage | microSD over SDIO |
| Board | Two-layer PCB with parts on both sides; black solder mask on the original |
| Files | KiCad schematics and PCB, production files for JLCPCB assembly |

### Original Hackbat (RP2040)

| | |
|---|---|
| Microcontroller | Raspberry Pi RP2040, dual Cortex-M0+ at 133 MHz, USB host and device |
| Radios | CC1101 sub-GHz · ESP-12F (ESP8266) Wi-Fi |
| NFC | PN532 at 13.56 MHz over I²C |
| Display | 128 × 64 OLED, SH110X (SSD1306 with resistor change) |
| Licence | CC0-1.0 |

### Getting one

| | |
|---|---|
| How | Zip the production files, upload to JLCPCB, add assembly with the BOM and centroid files; choose lead-free HASL |
| Related | A DEF CON 32 badge on the ESP32-C3 with the same order-it-yourself approach |

## Documentation

- [Hackbat ESP32 repository](https://github.com/thehackbat/hackbat_esp32)
- [README at the reviewed commit](https://github.com/thehackbat/hackbat_esp32/blob/6596eb40c666e6807d89d7880e599a52a3ac7c4c/README.md)
- [KiCad and production files](https://github.com/thehackbat/hackbat_esp32/tree/6596eb40c666e6807d89d7880e599a52a3ac7c4c/kicad)
- [Original RP2040 Hackbat repository](https://github.com/controlpaths/hackbat)
- [Original README at the reviewed commit](https://github.com/controlpaths/hackbat/blob/816d0acb7881e823c6b60f0ee02bc06544d12f2e/README.md)
- [DEF CON 32 badge repository](https://github.com/thehackbat/defcon32_badge)
- [Maker website](https://thehackbat.com/)

---
Source: gadgets.sh · https://gadgets.sh/devices/hackbat/ · JSON: https://gadgets.sh/api/v1/devices/hackbat.json
