I currently have two Wyze Cam v4 units. While looking into the manual flashing process, I noticed that the standard firmware updates available for SD card flashing do not seem to include or overwrite the bootloader. They typically only rewrite the primary system and kernel partitions.
For security auditing and complete peace of mind against deep persistence malware, I am looking for a way to perform a 100% clean, true factory restore.
Is there a specific recovery file or full flash image—perhaps obtainable directly from the developers or higher-tier support—that completely wipes and rewrites all partitions from scratch?
Ideally, I am looking for something that:
Completely overwrites the bootloader and all system partitions.
Wipes any potential modified or malicious code residing anywhere on the chip.
Preserves only the absolute essential factory-locked data (like the MAC address and unique device IDs).
Basically, I want to make the cameras perform exactly as they did the day they rolled off the assembly line. Has anyone successfully requested or received such a file from Wyze support, or is there a known method to achieve this level of clean flash?
As far as I know you have to have backed up your factory bootloader in order to be able to reinstall it. People used to flash Thingino on the v3 and if they lost the backup of their original files, they were stuck with it basically.
I’m sure there is someone somewhere at Wyze that can provide it, not sure who or how you’d get to them though. There is also moderately high risk of bricking the cam when trying to replace the bootloader.
I suspect the v4 may have a totally locked and secure bootloader (which is what prevents a lot of cams from being able to use some 3rd party firmware or software running on the SD card). Someone would need to confirm that, but if it is the case, then there shouldn’t be any need to ever overwrite it.
Thanks for the insight! Yes, I am fully aware that the bootloader is locked/secure and would typically require physical hardware modification (like desoldering the flash chip) to actually tamper with or modify.
The reason I’m being extra cautious is that I purchased these cameras on Amazon, and it’s a well-known fact that they frequently repackage and resell returned devices.
Because of this, I am specifically hoping to find an official solution that can be deployed via a standard SD card update—something that deeply cleans and rewrites all system partitions, flushing out any potentially modified code to ensure a 100% sterile, infection-free device.
Does anyone know if such a “deep-wipe” factory recovery image actually exists for the v4, or has anyone managed to get one from support?
Those cases are either a mistake (if it is sold as new, the person processing the return just didn’t check it thoroughly), or are listed as amazon resale or refurbished etc.
Yes at the very least disassembling the camera and soldering wires onto the serial header. Which you’d clearly be able to see if someone had done to your cam. It is also the reason why most of the modern models, they wouldn’t be able to just provide you a file, you’d need to tear apart the cam and know how to load that binary serially, they’re obviously not going to condone doing that.
I’d say just use your judgement, the power cord is virtually impossible to get wrapped back up the way it comes from the factory, same with the foam wrapping etc. You can tell if it was a returned item pretty easily. Even if someone carefully put it back in the packing, you’d see signs that the cam has been taken apart. I suspect the app might have issues with it if it was running an insecure firmware too, but I don’t know that for a fact.
As previously mentioned, that should not theoretically be possible on the secured/locked bootloader devices, which I believe the v4 is one. Maybe @carverofchoice has more insight into that though.
You are completely right about the security aspect, but just to clarify: I don’t want to modify or custom-patch the existing bootloader with third-party code. Since a locked bootloader’s primary function is to verify cryptographic signatures, it theoretically should accept and execute a full, official, factory-signed recovery image if Wyze provided one.
For comparison, I also have a Xiaomi C700 camera. I managed to download the full official firmware for it, which actually includes the stock bootloader and completely reinstalls (through u-boot) both the A and B system partitions from scratch. This works flawlessly despite the C700 having a dedicated MJA1 hardware security chip for cryptographic keys, simply because the image is officially signed by the manufacturer.
That is exactly what I’m hoping to find for the Wyze Cam v4—an official, signed full-flash file that the secure bootloader will happily accept to completely wipe and restore everything to a true zero-state.
@carverofchoice, do you happen to know if Wyze has ever released or provided a full partition recovery image like this for the v4?
This makes me think about also checking Settings ➜ Device Info ➜ Activation Date, which I believe should let someone know if a Cam has previously been setup, as I think that information comes from Wyze’s servers. Discussion in Wyze v4 camera activation date is wrong may or may not be helpful but might provide additional context.
Understood that you want the original one, but depending how they secure the bootloader, SD card may not have any sort of writable path to it. That’s why so many devices, especially IOT ones, require soldering or otherwise connecting to an internal header to actually write to the chip, even if it is a stock genuine image you want to load.
A truly secure device should not have the bootloader writable from any “user mode” path.
Based on the activation date, it looks like I was theoretically the first one to boot them up—so that’s definitely a good sign! Hopefully, everything came straight from the factory pristine and untouched.
I wouldn’t say I’m inherently paranoid, but I always prefer to flash my devices completely clean whenever the option is available, just for that extra peace of mind.
I dig. I don’t think Activation Date alone is a guarantee of purity, as discussed in the topic I linked, but I do think it’s a reasonable data point to consider for peace of mind.
By the way, I actually really love these cameras. They’re small, look sleek, and the black finish makes them barely noticeable. I just really hope that for the v5, Wyze decides to include an MJA1-like chip or a dedicated secure element.
To be honest no matter what they (or any other brand) were to incorporate or provide assurances of, I would never trust an internet connected cam in private spaces or on my main network. If I had a need for that I’d have a closed circuit system accessible only via my VPN.
As with any Wishlist topic, you can visit that one to click or tap the Vote button above the initial post and share your ideas and use cases in the comments to show your support for the product and feature request/suggestions that are important to you.
Can I ask you honestly? Is the Wyze v4 really that weak in terms of security, or is it mostly just suitable for casual monitoring?
I completely get your point about isolation. I actually have a Eufy camera as well that is completely blocked from the internet; it runs strictly on the local LAN through the factory app.
While discussing the limitations of locked bootloaders and firmware flashing, another critical security concern came up that I really hope the developers address in the upcoming Wyze Cam v5.
Currently, if a camera is deeply compromised (e.g., someone gains physical access and extracts the long-term device identity keys or root certificates directly from the flash memory), a standard Factory Reset or re-pairing via the app does absolutely nothing to secure the device.
A hard reset only wipes the user partition (Wi-Fi credentials and current session tokens). It does not rotate or regenerate the hardcoded factory device identity. Once that root key is extracted, the device is permanently compromised, as the attacker can impersonate the camera to the cloud indefinitely.
For the v5, it would be a huge step forward if Wyze could implement one of the following:
1. A dedicated Secure Element (like the MJA1 chip found in the Xiaomi C700): This hardware-level protection would make extracting the private cryptographic keys physically impossible.
2. Dynamic Key Regeneration: A true low-level factory reset mechanism that cryptographically rotates the device’s root identity and securely negotiates a brand-new certificate with the AWS cloud.
Adding hardware-backed key storage would finally elevate these cameras from casual monitoring devices to genuinely secure smart home equipment. Would love to hear if others agree!
Nothing specific to the v4 or even Wyze, just seems like common sense to me with inexpensive cameras that rely on a cloud server to operate and access. Pretty much every company making this style has suffered one or more breaches at some point, the potential is always there. Heck even the most secure “cloud cam” - a current or former employee could potentially access them.
If someone were to gain that sort of access and have those sort of intentions, I would not trust that camera ever again regardless of whether the key can be replaced.
Personally, I still would not consider it truly secure, nor would I consider anything connected via wifi and that relies on the internet to be anything more than “casual”. These are not security cameras, regardless of what Wyze (or any other company) wants you to think.
Wyze, secure? Haha I used these cameras up till V3, where the OEM Chinese bootloader and MAC address were left in tact. The MAC changes to the “wyze” MAC upon full boot. I actually had to block a few cameras native Chinese MAC address from communicating, as it caused issues with my static IP assignemnts. Then after Wyze bricked a brand new camera with their firmware update and refused to take responsibility, I said I’m done. I still have a few Wyze around but moved to an actual usable Lorex system. I can even hear the audio clear as day, and all my events always playback, but Still miss the Wyze tracking feature, that sometimes actually worked well.
That is completely understandable, especially after dealing with those bootloader and MAC address headaches.
However, it is worth noting that the Wyze Cam v4 actually works differently than the v3. In theory, the v4 uses TLS 1.3 and features Secure Boot, which is exactly why third-party firmware like Thingino cannot be installed on it.