On the nRF51, once the RBPCONF protection is enabled, using the debugger to access directly the Flash or RAM return nothing but zeros. However, it is still possible to control the code execution and read and write to registers (even to Program Counter). So finding a “gadget” in the ...
The PCB design matches perfectly the nRF52840 reference design (found in the Nordic Datasheet). It’s like a copy-paste design. Decoupling capacitors C5 and C15 are removed and the glitch output is connected to VDD_CPU (DEC1) : C5 and C15 are removed (black frame). VDD_CPU_DEC1 (red...