Skip to content

Yukong

Yukong is a private research project that produces patched MediaTek bootloader (LK) images for vivo devices, enabling bootloader unlock on Dimensity 9400/9400+/9500 (8400 WIP) devices.

Private project

Yukong is not open source. lkpatcher is.

Patched images are provided as-is for research purposes. Do not pay for bootloader unlocks — everything here is free.

Download patched images

Credits

  • @R0rt1z2 — original LK research & initial patch for X200 Pro
  • @thegwchr — tooling, porting

Supported devices

Device Model SoC Status
vivo X200 Pro PD2405 Dimensity 9400 (MT6991) ✅ A15 + A16
vivo X200 PD2415 Dimensity 9400 (MT6991) ✅ A16
vivo X200s PD2458 Dimensity 9400 (MT6991) ✅ A16
vivo X200 Pro mini PD2419 Dimensity 9400 (MT6991) ✅ A16
iQOO Z10 Turbo+ PD2507 Dimensity 9400+ (MT6991) ✅ A16
vivo X300 (Global, ARB 1) PD2509 Dimensity 9500 (MT6993) ✅ A16
vivo X300 Pro (Global, ARB 1) PD2502 Dimensity 9500 (MT6993) ✅ A16
vivo X300 (CN, ARB 2) PD2509 Dimensity 9500 (MT6993) ✅ A16
vivo X300 Pro (CN, ARB 2) PD2502 Dimensity 9500 (MT6993) ✅ A16

How it works

The LK (little kernel) bootloader contains the oem_getinfo handler, which reads the lock state from the SEC_CFG partition and reports it to fastboot. On stock firmware, unlocking requires vivo's proprietary challenge-response scheme (plctrl / hedgehog): the device sends an HMAC-SHA256 challenge bound to your eMMC CID, the host forwards it to vivo's server for signing with an OEM private key, and the signed response is RSA-verified on-device before the lock state changes.

The patch completely evades this routine. The oem_getinfo handler is modified so that:

  • fastboot continue — unlocks the bootloader directly, no server interaction, no signed response, no HMAC, no RSA
  • fastboot oem getinfo — relocks the bootloader
  • X300 Specific: to relock, run fastboot oem lock.

The patched LK binary is re-wrapped in the MTK secure container with updated hashes and passes the preloader's own verification chain (whitelist signature + container magic). No OEM private keys are used or required.

OTA updates

Do not update via OTA while having an unlocked bootloader. Since the bootloader unlock is achieved by evading vivo's verification routines, OTA updates would replace the patched lk with a stock one, rendering device completely unbootable. To update, flash full OTA via fastboot, with patched lk and known-good preloader.

Flashing tutorial

Read everything first

You need root access via GhostLock and a working ADB/fastboot environment. This modifies your bootloader partition — an error can hard-brick your device.

Prerequisites

  • Root access via GhostLock
  • adb and fastboot binaries on your host machine
  • The correct patched lk image for your device and firmware version
  • Battery above 50%

Steps

1. Back up your stock misc partition

adb shell dd if=/dev/block/by-name/misc of=/sdcard/misc_stock.img
adb pull /sdcard/misc_stock.img .

Keep this file — you need it to restore your original boot slot configuration.

2. Flash misc to boot the opposite slot

Determine your current slot:

adb shell getprop ro.boot.slot_suffix
# e.g. _a or _b

Flash the misc partition to force boot from the opposite slot (giving you a recovery path on the original slot):

adb shell dd if=/data/local/tmp/misc_force_slot_{a/b} of=/dev/block/by-name/misc    

3. Flash the patched LK to the opposite slot

If your current active slot is _a, flash to lk_b:

adb shell dd if=/data/local/tmp/lk_xxxxxx.img of=/dev/block/by-name/lk_b

If your current active slot is _b, flash to lk_a:

adb shell dd if=/data/local/tmp/lk_xxxxxx.img of=/dev/block/by-name/lk_a

4. Reboot to bootloader

fastboot reboot bootloader

The device reboots using the patched LK on the opposite slot.

5. Unlock the bootloader

fastboot continue

This unlocks the bootloader directly — no confirmation prompt, no server interaction, no signed response needed.

6. Verify

fastboot getvar unlocked
# unlocked: yes

Relocking

To relock the bootloader (e.g. before an OTA update):

fastboot oem getinfo

This reverts the lock state to locked.

Before relocking

Make sure your boot and system partitions are stock. Relocking with modified images will trigger secure boot failure and may hard-brick the device.