39th Chaos Communication Congress · Germany · 2025

39C3 Critical Decentralization Cluster Badge

Open-hardware ESP32-S3 / TROPIC01 assembly badge and devboard

The Critical Decentralization Cluster's CDC Badge was presented as an electronic conference badge and development board at the completed 39th Chaos Communication Congress. The source-backed open-hardware platform combines an ESP32-S3, TROPIC01 secure element, front-lit e-paper display, twelve-button keypad, LiPo power path, and expansion ports, while public sources do not establish a conference-wide or admission-badge allocation.

Event39th Chaos Communication Congress
SeriesChaos Communication Congress
LocationHamburg
CountryGermany

People

Authors & Credits

39C3 assembly and CDC Badge presenter

Critical Decentralization Cluster

The cluster's own 39C3 page identifies the CDC Badge repository within its completed Congress assembly context. This does not allocate individual board-design, production, or distribution roles.

Source

CDC Badge open-hardware source publisher and copyright holder

RIAT Institute

The public CDC Badge repository attributes project source material to RIAT Institute and publishes it under CERN-OHL-P-2.0. This is a source-project credit, not a claim to every event media or third-party component asset.

Source

later public CDC Badge OS firmware publisher

krim404

The public krim404 repository publishes CDC Badge OS for v1.0/v1.1 hardware. This credit is limited to the later public firmware source and does not claim it was deployed at 39C3.

Source

named 39C3 CDC Badge presenter

Pavel Polach

The official 39C3 event page lists Pavel Polach among the CDC Badge presenters; it does not assign an individual hardware, firmware, production, or distribution role.

Source

named 39C3 CDC Badge presenter

bobotronic

The official 39C3 event page lists bobotronic among the CDC Badge presenters; it does not assign an individual hardware, firmware, production, or distribution role.

Source

named 39C3 CDC Badge presenter

dllud

The official 39C3 event page lists dllud among the CDC Badge presenters; it does not assign an individual hardware, firmware, production, or distribution role.

Source

Why It Mattered

It adds a substantial 39C3 assembly-level badge alongside the Congress Hub's digital badges and the separate Cyberwatch project. The documented hardware, fabrication outputs, and later public firmware make it a durable hackable artifact, while the catalogue keeps its exact event role and distribution scope distinct from the official CCC credential.

Hardware

The official 39C3 assembly event and the CDC Badge open-hardware repository identify an ESP32-S3 and TROPIC01 secure element, a front-lit e-paper display, a twelve-button keypad, a JST connector for a single-cell LiPo battery, BQ25895 charging/power control, and Raspberry Pi GPIO, SAO, and Grove expansion surfaces. The hardware repository publishes KiCad schematics/layout, printable cases, documentation, fabrication generation, and v1.0/v1.1 releases, but these sources do not prove the exact board revision, component population, battery, or configuration of every 39C3 unit.

Software & Apps

The hardware repository links public CDC Badge OS work built with PlatformIO and ESP-IDF. Its later CDC Badge OS source supports a secure-element-oriented application surface including FIDO2/WebAuthn, GPG/SSH, TOTP, a password vault, plugins, and Bluetooth LE features, but its own README labels the firmware pre-1.0 beta and warns that flashing can erase stored data. The catalogue records this as a post-event public software trail, not proof that it was deployed on every 39C3 device or safe for security-critical use.

Lore

The Critical Decentralization Cluster took physical form as a 39C3 assembly around privacy, open hardware, and decentralized systems, and its official Congress schedule included a dedicated CDC Badge presentation. That puts the board in the Congress's assembly badgelife rather than making it a substitute for the event's Human or Hub credential systems.

Source-backed hardware metadata

Technical Profile

Structured technical signals seeded from public badge documentation, repositories, schematics, firmware notes, or event evidence. These fields are designed for filtering, API use, repair planning, preservation, and future Companion Gear matching.

Artifact type

  • Electronic badge documented

    The official 39C3 assembly event identifies the CDC Badge as an electronic conference badge and devboard.

    Signal source

MCU / compute

  • ESP32-S3 documented

    RIAT's public CDC Badge hardware repository identifies an ESP32-S3 microcontroller.

    Signal source

Connectors

  • Grove documented

    The CDC Badge repository documents a Grove-compatible expansion connector.

    Signal source
  • SAO documented

    The CDC Badge repository documents a SAO expansion port.

    Signal source

Display / visual output

  • E-paper documented

    The CDC Badge repository documents the front-lit e-paper display surface.

    Signal source

Power

  • LiPo documented

    The CDC Badge repository documents single-cell LiPo support, while its separate firmware checklist preserves configuration and safety caveats.

    Signal source

Firmware

  • ESP-IDF documented

    The later public CDC Badge OS source identifies an ESP-IDF firmware stack for CDC Badge v1.0/v1.1 hardware; exact 39C3 deployment remains unverified.

    Signal source

Repair, preservation, and legal lab context

Companion Gear

Parts, tools, and supplies that match this badge's documented hardware, protocols, or preservation needs. These are category-level recommendations, not compatibility guarantees.

SparkFun exact

SAO Headers

Headers and connector supplies for SAO repair, add-on testing, and preservation.

Why this matches

This badge has a documented SAO connector. Matched technical signals: SAO.

Matched evidence

Useful for add-on repair, testing, display, and bench documentation.

Open vendor search

Vendor link · selected for technical relevance

Seeed Studio exact

Replacement Displays

Display modules and related parts for repair and preservation planning.

Why this matches

This badge has a documented display signal. Matched technical signals: E-paper.

Matched evidence

Useful for preservation, repair planning, and careful display handling.

Open vendor search

Vendor link · selected for technical relevance

SparkFun likely

Qwiic / I2C Adapters

I2C adapter supplies for badge add-ons, sensors, and lab documentation.

Why this matches

SAO workflows often use I2C-compatible add-on testing and bench documentation. Matched technical signals: SAO.

Matched evidence

Useful for development and documentation of hardware you own or are authorized to work on.

Open vendor search

Vendor link · selected for technical relevance

SparkFun likely

SAO Extension Cables

Extension wiring and jumper supplies for testing or displaying SAO add-ons away from the main badge.

Why this matches

Extension wiring is useful for testing and displaying SAO add-ons. Matched technical signals: SAO.

Matched evidence

Useful for authorized bench testing and display setups.

Open vendor search

Vendor link · selected for technical relevance

SparkFun likely

Display Headers and Connectors

Headers, sockets, and connector supplies for display repair or replacement work.

Why this matches

Display headers and connectors are useful for repair and preservation planning. Matched technical signals: E-paper.

Matched evidence

Useful for careful repair or replacement of small display modules.

Open vendor search

Vendor link · selected for technical relevance

Lifecycle

Add-ons & Upgrades

badge expansion source-backed

Raspberry Pi, SAO, and Grove expansion surfaces

The public repository documents a Raspberry Pi GPIO header, a SAO port, and a Grove-compatible connector as three expansion paths. It does not establish that any particular add-on was distributed or supported at 39C3.

Compatibility: 39C3 Critical Decentralization Cluster Badge

Source
badge hardware source-backed

ESP32-S3 and TROPIC01 secure-element core

The official 39C3 CDC Badge presentation and RIAT hardware repository identify an ESP32-S3 development platform paired with a TROPIC01 secure element. The catalogue does not treat that hardware description as a claim about every physical event unit's exact revision or configuration.

Compatibility: 39C3 Critical Decentralization Cluster Badge

Source
open-hardware lifecycle public release

Versioned KiCad and fabrication release trail

RIAT publishes KiCad hardware, printable cases, documentation, fabrication-generation material, and v1.0/v1.1 releases under CERN-OHL-P-2.0. This preserves a reproducibility trail without proving final event production parity or a recipient inventory.

Compatibility: CDC Badge v1.0/v1.1 hardware

Source
post-event firmware pre-1.0 beta

CDC Badge OS public firmware trail

krim404's public GPL-3.0 CDC Badge OS describes an ESP-IDF/PlatformIO application stack with hardware-key, identity, plugin, and BLE capabilities, but labels itself pre-1.0 beta and warns of data loss on flashing. It is not a verified 39C3 deployment image.

Compatibility: CDC Badge v1.0/v1.1 hardware

Source
user interface source-backed

Front-lit e-paper display and twelve-button keypad

The official event page describes a front-lit e-paper display and twelve-button keypad; the public hardware repository associates the keypad with a TCA9535 I²C expander.

Compatibility: 39C3 Critical Decentralization Cluster Badge

Source

Operational history

Issues & Camp Impact

assembly scope, official-credential, and allocation boundary note

The official Congress sources call the CDC Badge an electronic conference badge and development board presented by the Critical Decentralization Cluster, but reviewed sources do not identify it as the official CCC Human badge, a general Congress admission credential, a ticket entitlement, a conference-wide handout, an event price, an allocation count, or a recipient ledger.

The record preserves the concrete 39C3 assembly artifact while not conflating a cluster badge with CCC's main credential or assuming every attendee received one.

Confidence
official 39C3 assembly and talk pages
Status
assembly artifact documented; allocation unrecovered
Timeframe
39C3, December 2025
Source note
39C3 Critical Decentralization Cluster assembly page, CDC Badge assembly event page, and Critical Decentralization Cluster 39C3 retrospective.
beta firmware, sensitive-data, and security-critical-use boundary warning

The later public CDC Badge OS README states that flashing can wipe stored FIDO2/U2F credentials, TOTP seeds, password-vault entries, GPG keys, and PIN data; it calls the project a proof of concept/demonstrator and says not to use it as-is for production or security-critical deployments.

The record may describe the public software capability surface but does not endorse the firmware, vouch for its cryptography, privacy, data durability, or safety, or imply it was the software deployed at 39C3.

Confidence
public firmware README
Status
public source explicitly pre-1.0 beta
Timeframe
2026 public firmware state
Source note
krim404/cdc-badge-os README.
firmware-release and event-deployment boundary note

The public CDC Badge OS repository was created after the December 2025 event and describes v1.0/v1.1 hardware, while the RIAT hardware repository links multiple possible firmware projects. The reviewed sources do not provide a signed 39C3 image, installed-version inventory, setup/recovery policy for event recipients, event-specific feature configuration, or a historical deployment release mapping.

Later firmware transparency is useful evidence, but the catalogue does not backdate it into a confirmed Congress software image or user-support commitment.

Confidence
repository chronology and project statements
Status
post-event public firmware trail; 39C3 deployment unknown
Timeframe
January-July 2026 public firmware history
Source note
riatlabs/cdc-badge repository, CDC Badge v1.1 release, and krim404/cdc-badge-os repository metadata and README.
missing rights-cleared image note

No 39C3 Critical Decentralization Cluster Badge image is published because the current public source trail has not been paired with a reusable original badge or artifact photo or official upstream raster render with source URL, license or permission basis, attribution, and processing notes.

The Germany record remains source-backed and image-free rather than copying source-page media, documentation screenshots, event photos, social media, placeholders, or generated approximations.

Confidence
local project policy
Status
needs licensed original replacement
Timeframe
current catalogue build
Source note
badge.gallery image policy and 39C3 official assembly and talk pages, Critical Decentralization Cluster's 39C3 page, and RIAT's public CDC Badge hardware and firmware source trail.
physical revision, production, and unit-configuration boundary note

RIAT publishes versioned v1.0 and v1.1 hardware sources, KiCad fabrication material, cases, and documentation, but the reviewed public record does not map a specific release, component substitutions, test result, PCB lot, enclosure, battery, production quantity, factory/assembly path, or final configuration to each physical 39C3 unit.

Open hardware remains a preservation and reproduction trail without becoming a claim that every 39C3 badge exactly matches a current repository release or bill of materials.

Confidence
versioned public hardware sources
Status
v1.0/v1.1 source releases public; event-unit mapping unrecovered
Timeframe
2025-2026 public source trail
Source note
riatlabs/cdc-badge repository and v1.1 release.
power, charging, and electrical-safety configuration boundary warning

RIAT's firmware checklist says the BQ25895 default fast-charge current would damage the documented 1200 mAh bundled LiPo and directs firmware developers to lower it; it also covers USB charging-port detection, system-voltage configuration, shipping-mode power-off, and TROPIC01 sleep. The public record does not establish that all 39C3 units had those settings, a matching battery, protection validation, current/thermal testing, compliance review, or safe user configuration.

The catalogue surfaces the published operational caution without presenting the badge as electrically validated, safe to charge, or safe to flash under every firmware/configuration combination.

Confidence
primary firmware checklist
Status
source-published configuration cautions; deployed settings unrecovered
Timeframe
current public source review
Source note
CDC Badge firmware checklist and open-hardware repository.

Resources

Sources