Creative Hardware

Someone Turned the Wi-Fi Chip in an ESP32 Into a Software Defined Radio

ESP-SDR captures raw I/Q samples through an undocumented debug path that bypasses the chip's fixed-function modem. No SDR hardware required.

Every Wi-Fi chip contains a radio receiver. It samples a chunk of the 2.4GHz band, digitises it, and hands the result to a fixed-function modem that looks for Wi-Fi packets and throws away everything else.

That “everything else” is the entire radio spectrum, and the chip was never going to let you have it. ESP-SDR, by ESPARGOS’ Florian Euchner, takes it anyway.

What it does

Firmware that turns the ESP32’s built-in 2.4GHz Wi-Fi radio into a software defined radio. It captures raw I/Q samples from the receiver, so you can view the spectrum and study signals that aren’t Wi-Fi packets at all. No separate SDR hardware is required. The ESP32-C5 can also receive in the 5GHz band.

The firmware captures short bursts and sends them to a computer over native USB or UART.

What “raw I/Q” means and why it is the whole story

A radio receiver mixes the incoming signal down to baseband and produces two streams: I (in-phase) and Q (quadrature) — the same signal sampled 90° apart in phase. Together they describe the signal’s amplitude and phase, which is everything there is to know about it.

Every digital radio has I/Q internally. What distinguishes an SDR is that it gives you the samples instead of a decoded result. Once you have I/Q you can demodulate anything in software: FM, AM, FSK, LoRa, Bluetooth, a garage door remote, a weather station, a tyre pressure sensor.

A Wi-Fi chip normally hides this behind a hardwired modem, because the modem is the product. Exposing I/Q turns a $2 part into something whose nearest commercial equivalent costs considerably more.

How it was found, which is the genuinely modern part

Per the project: an undocumented debug path was found, with help from LLMs, that bypasses the chip’s fixed-function Wi-Fi modem and exposes raw samples. And: parts of the firmware are AI-generated.

Worth dwelling on, because it describes a reverse-engineering workflow that did not exist three years ago. Finding an undocumented register path in an undocumented peripheral traditionally means reading a leaked datasheet, disassembling a vendor binary blob, and a great deal of guessing — a task gated almost entirely on patience rather than insight.

Language models are unusually well suited to parts of that: pattern-matching across register layouts, recognising conventions reused between chip families, generating and triaging hypotheses about what an unlabelled field does. They are not doing the engineering; they are compressing the search.

The context makes it more credible than it would otherwise be: ESPARGOS already understands the sampling path on the ESP32-C61 used in its ESPARGOS One antenna array, and used LLMs to extend that understanding across eight chips in the family. That is the right shape for this kind of assistance — a human with deep knowledge of one instance, using a model to generalise it across siblings, then verifying on hardware. Not a model discovering something from nothing.

The constraints, stated honestly

Short bursts. This is not a continuous-capture SDR. The ESP32 has no path to stream multi-megasample-per-second I/Q anywhere — there isn’t the RAM to buffer it or the bandwidth to ship it. You get a snapshot, then a gap.

2.4GHz (and 5GHz on the C5). You cannot tune it to shortwave, FM broadcast, or the 433MHz band where most consumer remotes live. The receiver’s front end is built for Wi-Fi bands and that is where it stays. For those bands you still want an RTL-SDR.

Native USB or UART for transport, which bounds your sample depth per burst.

So the comparison isn’t ESP-SDR versus an RTL-SDR or a HackRF. It is ESP-SDR versus nothing — in the specific case where you want 2.4GHz spectrum awareness inside a device that already has an ESP32 in it, and adding SDR hardware was never going to happen.

What you would build with it

  • Spectrum-aware installations. A piece that responds to the actual RF activity in a room — how many devices, how busy the band, what’s transmitting — using the microcontroller already running the work. RF as a sensor rather than a transport.
  • Teaching. An SDR on a board a student already owns, for under five dollars, is a very different proposition from asking a class to buy dongles. I/Q, mixing, FFTs and modulation are much easier to teach when everyone can capture real samples.
  • Debugging your own radios. If you build BLE or Wi-Fi devices, being able to look at the band rather than infer from packet loss is a serious diagnostic upgrade.
  • Bluetooth, BLE and 2.4GHz proprietary protocol work — everything in that band becomes inspectable.
  • Sonification. Raw I/Q is a complex-valued audio-rate signal. Feeding the 2.4GHz noise floor into a synthesis chain is the kind of thing the RF-art tradition — Christina Kubisch’s electrical walks, Joyce Hinterding’s antennas — has been doing with analogue means for decades.

The broader point about the ESP32 family stands: it keeps turning out to contain more hardware than its documentation admits. The I²S peripheral became a logic analyser and a camera interface, the RMT peripheral became an addressable-LED driver and an IR transceiver, and now the Wi-Fi front end is an SDR. The documented feature set of a cheap SoC is a floor, not a ceiling.