CipherFuse v4.1 · free · GPL-3.0

Encrypt the flash.
Keep the key.

CipherFuse burns a flash-encryption key into an ESP32 and writes your Arduino or ESP-IDF firmware so the chip is the only thing that can read it.

ESP32S2S3C2C3C6H2P4
This can lock a board. Burning the key cannot be undone. Back the key file up, flash plaintext first, and confirm the firmware runs before you encrypt.

Windows 10 and 11

64-bit. Python, Qt, and esptool are inside the download.

Download Windows zip

Unzip and run CipherFuse.exe. Read PREREQUISITES.txt in the folder.

Ubuntu

22.04 and 24.04. The installer adds Python, PyQt6, and the esptool libraries.

Download Ubuntu package

tar -xzf CipherFuse-4.1-ubuntu.tar.gz
cd CipherFuse-4.1-ubuntu && ./install.sh

What you do not have to install yourself

Windows package
  • Python
  • PyQt6
  • pyserial
  • esptool, espefuse, espsecure
Ubuntu installer
  • python3, pip, and venv
  • PyQt6 and pyserial from Ubuntu
  • cryptography, bitstring, reedsolo, PyYAML, intelhex, click

A CP2102 or CH340 USB-UART board may still need that chip vendor’s driver. Native-USB ESP32 boards usually appear with no extra driver.

Order of work

  1. Pick the chip and the serial port.
  2. Flash plaintext and confirm the board runs.
  3. Generate a key and copy it somewhere safe.
  4. Flash and encrypt.