NorthSec

NorthSec 2026

The May 9-17, 2026 Montreal NorthSec edition whose official registration page offered a new social electronic badge while supplies lasted and whose villages material documented badge soldering, badge-enhancement activity, and a badge museum. Post-event first-hand and third-party firmware sources document an observed ESP32-S3/NFC/NeoPixel badge configuration, while NorthSec's public archive still lacks an official 2026 hardware or firmware release.

Bonsecours Market, Montreal · Canada · 2026

NorthSec 2026 Badge badge image

NorthSec 2026 Badge

NorthSec 2026's official registration page lists a new social electronic badge as an included item for conference, CTF, combo, and training ticket holders while supplies lasted. The official competition page's retained 2026 Solarpunk section says the hackable electronic badge was fully integrated into the CTF, with badge challenges worth points and on-site badge-firmware tampering among the physical tracks. Official villages pages document badge pickup through attendees' nSec order QR codes, soldering-village activity where attendees could enhance their badge with blinking electronic parts, and a badge museum. On August 3, after the May event, NorthSec published the separate Apache-2.0 `nsec/badge-2026` repository. Its commit-pinned hardware and source tree documents an ESP32-S3 badge design with an ST25R3916 NFC front end, six buttons, eighteen WS2812/NeoPixel LEDs, a 200×200 GDEH0154D67 / SSD1681 e-paper path, KiCad design files, production BOM/CPL/Gerbers, PlatformIO firmware, conference/CTF partitions, CTF assets, and dock/SAO directories.

Lifecycle

Add-ons & Upgrades

NorthSec 2026 Badge official event-page backed

badge distribution

New social electronic badge entitlement

The registration page lists a new social electronic badge as an included item for multiple NorthSec 2026 ticket classes while supplies lasted.

Compatibility: NorthSec 2026 conference, CTF, combo, and training attendance

NorthSec 2026 Badge official schedule backed

badge pickup workflow

Order QR badge pickup

The villages schedule told attendees to retrieve goodies such as their t-shirt and badge using the QR code in their nSec order email.

Compatibility: NorthSec 2026 Badge

NorthSec 2026 Badge official commit-pinned public source

hardware source

Official 2026 KiCad and production archive

The official hardware tree supplies KiCad board/schematic files plus JLCPCB BOM, CPL, and Gerber material, with dock and SAO design directories. It documents the released project design without proving that every recipient board was populated or flashed identically.

Compatibility: NorthSec 2026 badge design; physical production variance and allocation scope unconfirmed

NorthSec 2026 Badge official village backed

lineage exhibit

NorthSec Badge Museum

The official villages page describes a Badge Museum documenting NorthSec's long-running electronic-badge history and open-hardware culture.

Compatibility: NorthSec badge lineage

NorthSec 2026 Badge official 2026 competition page backed

official CTF challenge surface

CTF-integrated badge challenges

The official competition page's retained 2026 Solarpunk section says the hackable electronic badge was fully integrated into the CTF and that solving badge challenges earned points; it separately names badge-firmware tampering among on-site physical tracks.

Compatibility: NorthSec 2026 CTF and electronic badge

NorthSec 2026 Badge public source; no tagged binary release

official firmware source

Official conference/CTF firmware source

NorthSec's C++/Arduino PlatformIO tree includes shared NFC, e-paper, LED, and button modules alongside conference/CTF partition material. The public snapshot does not identify a tagged release, factory binary, or event-unit deployment revision.

Compatibility: NorthSec 2026 badge source tree; exact deployed firmware unconfirmed

NorthSec 2026 Badge first-hand source-backed; official map corroborates core peripherals

post-event hardware observation

First-hand ESP32-S3, NFC, and NeoPixel hardware observation

Marx314's post-event attendee account identifies an observed NorthSec 2026 badge with ESP32-S3-WROOM-1, 16 MB flash, ST25R3916 NFC, a six-button D-pad, an 18-pixel NeoPixel ring, and an e-ink display path. NorthSec's later official map corroborates the common controller/peripheral shape but not the reported module capacity or every production variant.

Compatibility: Observed NorthSec 2026 attendee badge; production-variant scope unconfirmed

NorthSec 2026 Badge official commit-pinned publication

post-event official source release

Official 2026 Apache-2.0 source release

NorthSec publicly released the separate nsec/badge-2026 source tree after the event, including hardware, firmware, animations, CTF content, dock material, and source artwork. Its historical commit timestamps are retained project chronology, not proof of public availability before the event.

Compatibility: NorthSec 2026 badge project; no physical-unit or deployed-firmware revision mapping published

NorthSec 2026 Badge public source; license unspecified

third-party firmware

Custom NFC webhook and e-ink firmware

Marx314's public post-event source implements custom NFC-to-webhook behavior with Wi-Fi setup and display/no-display builds. It is replacement firmware for an observed badge configuration, not NorthSec's factory firmware or Apache-2.0 source release.

Compatibility: NorthSec 2026 badge as configured by the third-party project; not an official NorthSec release

Operational history

Issues & Camp Impact

hardware-source caveat · official post-event source plus first-hand observation · official design source documented; event-unit deployment scope remains open

NorthSec's separate Apache-2.0 nsec/badge-2026 repository now publishes KiCad, BOM/CPL/Gerbers, a pin map, and C++/PlatformIO source for the ESP32-S3/NFC/e-paper/NeoPixel design. It does not identify a source commit, binary, display state, component revision, or assembly/flash configuration for each distributed badge. Marx314's write-up remains useful first-hand context, including its observed 16 MB module report, but it is not an official production ledger.

The catalogue can document the official technical surface and CTF integration without presenting the published design snapshot or any third-party observation as a universal recipient-unit configuration.

official-source publication and deployment boundary · commit-pinned official GitHub publication · documented; public source release is post-event

The official nsec/badge-2026 repository appeared publicly after NorthSec 2026. Its March-to-May authored commit history documents development chronology but does not establish public availability during the May event. The reviewed repository has no tag, GitHub release, or published binary, and no source maps a specific commit to a physical attendee unit or deployed CTF state.

Readers can inspect a real official source release while the catalogue avoids backdating its publication, claiming a particular factory image, or treating one source revision as proof for every badge handed out.

third-party firmware license caveat · repository metadata audit · source visible; license unspecified

The public marx314/nsec-badge-2026-nfc-webhook project has no GitLab license metadata, root LICENSE or LICENSE.md file, tag, or release that declares reuse terms. Its visible source must therefore not be represented as Apache-2.0, officially released by NorthSec, or otherwise reusable by default.

Readers can inspect the custom firmware trail, but the catalogue does not imply permission to redistribute, modify, or reuse it and keeps it distinct from NorthSec's separately published Apache-2.0 source archive.

Resources

Sources