Yukong¶
Yukong is a private research project that produces patched MediaTek bootloader (LK) images for vivo devices, enabling bootloader unlock on Dimensity 9400/9400+/9500 (8400 WIP) devices.
Private project
Yukong is not open source. lkpatcher is.
Patched images are provided as-is for research purposes. Do not pay for bootloader unlocks — everything here is free.
Credits¶
Supported devices¶
| Device | Model | SoC | Status |
|---|---|---|---|
| vivo X200 Pro | PD2405 | Dimensity 9400 (MT6991) | ✅ A15 + A16 |
| vivo X200 | PD2415 | Dimensity 9400 (MT6991) | ✅ A16 |
| vivo X200s | PD2458 | Dimensity 9400 (MT6991) | ✅ A16 |
| vivo X200 Pro mini | PD2419 | Dimensity 9400 (MT6991) | ✅ A16 |
| iQOO Z10 Turbo+ | PD2507 | Dimensity 9400+ (MT6991) | ✅ A16 |
| vivo X300 (Global, ARB 1) | PD2509 | Dimensity 9500 (MT6993) | ✅ A16 |
| vivo X300 Pro (Global, ARB 1) | PD2502 | Dimensity 9500 (MT6993) | ✅ A16 |
| vivo X300 (CN, ARB 2) | PD2509 | Dimensity 9500 (MT6993) | ✅ A16 |
| vivo X300 Pro (CN, ARB 2) | PD2502 | Dimensity 9500 (MT6993) | ✅ A16 |
How it works¶
The LK (little kernel) bootloader contains the oem_getinfo handler,
which reads the lock state from the SEC_CFG partition and reports it to
fastboot. On stock firmware, unlocking requires vivo's proprietary
challenge-response scheme (plctrl / hedgehog): the device sends an
HMAC-SHA256 challenge bound to your eMMC CID, the host forwards it to
vivo's server for signing with an OEM private key, and the signed
response is RSA-verified on-device before the lock state changes.
The patch completely evades this routine. The oem_getinfo handler
is modified so that:
fastboot continue— unlocks the bootloader directly, no server interaction, no signed response, no HMAC, no RSAfastboot oem getinfo— relocks the bootloader- X300 Specific: to relock, run
fastboot oem lock.
The patched LK binary is re-wrapped in the MTK secure container with updated hashes and passes the preloader's own verification chain (whitelist signature + container magic). No OEM private keys are used or required.
OTA updates
Do not update via OTA while having an unlocked bootloader.
Since the bootloader unlock is achieved by evading vivo's verification routines, OTA updates would replace the patched lk with a stock one, rendering device completely unbootable. To update, flash full OTA via fastboot, with patched lk and known-good preloader.
Flashing tutorial¶
Read everything first
You need root access via GhostLock and a working ADB/fastboot environment. This modifies your bootloader partition — an error can hard-brick your device.
Prerequisites¶
- Root access via GhostLock
adbandfastbootbinaries on your host machine- The correct patched
lkimage for your device and firmware version - Battery above 50%
Steps¶
1. Back up your stock misc partition
Keep this file — you need it to restore your original boot slot configuration.
2. Flash misc to boot the opposite slot
Determine your current slot:
Flash the misc partition to force boot from the opposite slot (giving you a recovery path on the original slot):
3. Flash the patched LK to the opposite slot
If your current active slot is _a, flash to lk_b:
If your current active slot is _b, flash to lk_a:
4. Reboot to bootloader
The device reboots using the patched LK on the opposite slot.
5. Unlock the bootloader
This unlocks the bootloader directly — no confirmation prompt, no server interaction, no signed response needed.
6. Verify
Relocking¶
To relock the bootloader (e.g. before an OTA update):
This reverts the lock state to locked.
Before relocking
Make sure your boot and system partitions are stock. Relocking with modified images will trigger secure boot failure and may hard-brick the device.