[GUIDE] UNBRICK/DOWNGRADE YOUR REALME 6/6I(INDIA)/6S USING SPFLASH TOOL FOR FREE!

Search This thread

midzan21

Senior Member
Holy smokes, thank you, you just saved my butt from getting my Realme 6s (RMX2002 EU) to service center in walk of shame because I ****ed up something while trying to install Recovery (OrangeFox) and it stuck in bootloop without entering recovery at all. Now one question - what is best custom recovery for my Realme 6s RMX2002 EU based on Android 11 C.19 firmware (bootloader unlocked) so i can install¨finally some Custom ROM based on Android 12. Thanks in advance and cheers
 

trigz974

Member
Nov 27, 2007
21
3
Saint-Denis
Many thank's for this tutorial that clearly saved my phone !!
I had the Flashing Error "Verified Boot Enable" and follow the link below to solved it.


Maybe can help.

Regards.
 

Crazy_xcx

Member
Mar 13, 2021
13
0
Hello everyone! So after the new mediatek DAA and SLA protection bypasses you can find github repo of here , using the bypass we are able to use SPFlash Tool, here is a guide how you can do it! This guide is for RMX2001, RMX2002 and RMX2003 ONLY. DON'T DO ANY OF THESE IF YOU HAVE SOMETHING ELSE!

PLEASE SEE "TROUBLESHOOTING" AT THE END OF THE GUIDE FIRST IF YOU HAVE PROBLEMS IN THE PROCESS BEFORE ASKING!


ALWAYS USE DOWNLOAD ONLY MODE OF SP FLASH TOOL.
DON'T TOUCH ANYTHING RELATED TO FORMAT ON SP FLASH TOOL! (IT'S WRITTEN EVERYWHERE, YOU WILL LOSE YOUR IMEIS IF YOU USE FORMAT ALL + DOWNLOAD. YOU ARE SAFE IF YOU USE DOWNLOAD ONLY.)


VIDEO GUIDES



FOR LINUX METHOD CLICK HERE - Credits to @bx2_nero

Windows Method

Requirements:
Bypass Tools Pack - (SPFLASH TOOL, DRIVER AND BYPASS FILES)

Decrypted OFP (OPPO FIRMWARE PACKAGE) Files:

FULL FIRMWARE - INCLUDES THE "USERDATA" PARTITION, HENCE LARGER.
B.53 - Mega - Google Drive - Mirror3
B.37 - Mega - Google Drive 2
B.23 (First RUI Update for the device) - Mega - Google Drive - Mirror3
A.50[EU] - Mega - Google Drive
A.42[EU] - Google Drive - Mirror2


NOU (NO USERDATA) FIRMWARE - FOR PEOPLE WITH LIMITED DATA PLAN.
B.53 - Google Drive - Mirror 2
B.37 - Google Drive - Mirror 2
B.23 - Google Drive - Mirror 2
A.50[EU] - Mega - Google Drive
A.42[EU] - Google Drive - Mirror2

Please read an explanation of what is userdata partition and how different is this from other firmware here.
Note: All files with available links above are tested.

Python (Must add to PATH during installation, see screenshot if you don't understand)
libusb-win32 - Having Issues? Use this.

aaf0ca5590e6884c234b1.png

Make sure to choose the last option.
1)Open command prompt by running cmd,
enter
python -m pip install pyusb pyserial json5
View attachment 5195739
After the installation, you can re-run the command. If it looks like the screenshot above you're ready to go to next step.

after the installation leave CMD.
2) Go to driver folder, find the .inf file right click and press install.
View attachment 5195737
3)Download this file and install it, after installing plug your phone to PC by connecting your phone to PC while doing Vol+- . You might need this driver as well if it's not detected.

3a6d351fec8ab9961a5e3.png

Press next, connect your device to PC while holding Vol+- buttons (your device needs to be powered off) and you will see the mtkdriver down below. Install it.
310b8508659201f6729f7.png

Choose MediaTek USB Port and install it.
4)Turn off your phone and again connect to PC while holding Vol+- buttons then run the brom.bat under Bypass folder. If it says "Protection Disabled" in the end you're ready to go on. (If it's like the screenshot below go on.)
View attachment 5196231
If you had a problem here, please check the end of the guide for it's fix.

5)Go into Flash Tool folder and open the SPFlash tool, after that choose scatter file and also if not set, set your download -agent. You don't need to select auth file as authorization is disabled. Once you do it, it should look like this. ALWAYS MAKE SURE DOWNLOAD ONLY MODE IS SELECTED! DON'T SELECT OTHER MODES!

View attachment 5202549
Click choose DA Agent. (I uploaded an updated bypass tools pack, if you're using older download new one) Go into Bypass Tools Pack > Verified Boot Fix > Choose the "DA_6765_6785_6768_6873_6885_6853.bin" file.

If its giving error go into Options menu and disable option shown below. You will be able to choose a DA file.
View attachment 5202533

73cff8e3aa78249f2d298.png

Make SURE "Download Only" is selected. Don't select ANYTHING ELSE! You will lose your IMEIs, Serial Numbers, Capability of Hardware Attestation etc. if you choose "Format data + Download" make SURE you selected "Download Only".
1f97e3897519622afb94d.png


After flashing it should look like this. Download has been complete. Enjoy!

Now, you can start downloading with the button and after that a checkmark will appear. You can reboot your phone and use it like before now! All your userdata will (inevitably) be cleared!

POSSIBLE ERROR: "Verified boot enabled."
View attachment 5197259

There are 2 fixes to this.
1st Method (DIRECT FIX):
View attachment 5202549
Click choose DA Agent. (I uploaded an updated bypass tools pack, if you're using older download new one) Go into Bypass Tools Pack > Verified Boot Fix > Choose the "DA_6765_6785_6768_6873_6885_6853.bin" file.

If its giving error go into Options menu and disable option shown below. You will be able to choose a DA file.
View attachment 5202533

2nd Method (WORKAROUND):
If you're getting this error, and you are SURE you used "Download Only" mode, there's a way to get rid of this. First, load the scatter then untick/deselect partitions listed below.

opporeserve2,
cdt_engineering,
my_custom,
special_preload,
userdata,
super,

After running brom.bat and flashing all partitions except the ones listed above, your phone will be able to reboot to stock recovery. Now select " Power Off" option then go run brom.bat, bypass authorization and then flash partitions listed below from SPFlash Tool.

super,
dtbo,
userdata

Your device will be able to boot into system after this if you have followed steps correctly.

POSSIBLE ERROR: Issues while disabling protection;


View attachment 5196241
Power off your device Restart the process from 2nd step.

POSSIBLE ERROR: Issues while flashing;
View attachment 5196249

Power off your device, you will need to do the bypass again. Check your USB Cable, there might be a disconnection. If not, start from 3rd step and make sure you did everything right.

So, welcome to hell(!).

For people who want to downgrade:
If you want to downgrade to any version you would like, just use the B23 file as it is the oldest ofp file i could find for extracting process. If you were on EU version before (Any version starting with A) download ozip from here(for EU) , here(for Global) and manually flash from Realme UI recovery and format your data. Your device will be back at A.XY firmware with EU features (No heytap, no ads, no theme store, no bloatware) you had before.

For people on EU who want to unbrick:
So, you can use any version starting with B and it should work. It works in my case, i was on A.48, i flashed B53 and over that flashed B23. No probs at all. If you want to return to EU rom (starting with A) download ozip from here and manually flash from Realme UI recovery and format your data. Your device will be back at A.XY firmware with EU features (No heytap, no ads, no theme store, no bloatware) you had before.

Thanks --
https://github.com/bkerler/oppo_decrypt for decryptor.
https://github.com/MTK-bypass for creating the tool.
Hello sir i have downloaded all the files and tried to flash and it gave me and error that verified boot is enabled
 

Crazy_xcx

Member
Mar 13, 2021
13
0
Hello everyone! So after the new mediatek DAA and SLA protection bypasses you can find github repo of here , using the bypass we are able to use SPFlash Tool, here is a guide how you can do it! This guide is for RMX2001, RMX2002 and RMX2003 ONLY. DON'T DO ANY OF THESE IF YOU HAVE SOMETHING ELSE!

PLEASE SEE "TROUBLESHOOTING" AT THE END OF THE GUIDE FIRST IF YOU HAVE PROBLEMS IN THE PROCESS BEFORE ASKING!


ALWAYS USE DOWNLOAD ONLY MODE OF SP FLASH TOOL.
DON'T TOUCH ANYTHING RELATED TO FORMAT ON SP FLASH TOOL! (IT'S WRITTEN EVERYWHERE, YOU WILL LOSE YOUR IMEIS IF YOU USE FORMAT ALL + DOWNLOAD. YOU ARE SAFE IF YOU USE DOWNLOAD ONLY.)


VIDEO GUIDES



FOR LINUX METHOD CLICK HERE - Credits to @bx2_nero

Windows Method

Requirements:
Bypass Tools Pack - (SPFLASH TOOL, DRIVER AND BYPASS FILES)

Decrypted OFP (OPPO FIRMWARE PACKAGE) Files:

FULL FIRMWARE - INCLUDES THE "USERDATA" PARTITION, HENCE LARGER.
B.53 - Mega - Google Drive - Mirror3
B.37 - Mega - Google Drive 2
B.23 (First RUI Update for the device) - Mega - Google Drive - Mirror3
A.50[EU] - Mega - Google Drive
A.42[EU] - Google Drive - Mirror2


NOU (NO USERDATA) FIRMWARE - FOR PEOPLE WITH LIMITED DATA PLAN.
B.53 - Google Drive - Mirror 2
B.37 - Google Drive - Mirror 2
B.23 - Google Drive - Mirror 2
A.50[EU] - Mega - Google Drive
A.42[EU] - Google Drive - Mirror2

Please read an explanation of what is userdata partition and how different is this from other firmware here.
Note: All files with available links above are tested.

Python (Must add to PATH during installation, see screenshot if you don't understand)
libusb-win32 - Having Issues? Use this.

aaf0ca5590e6884c234b1.png

Make sure to choose the last option.
1)Open command prompt by running cmd,
enter
python -m pip install pyusb pyserial json5
View attachment 5195739
After the installation, you can re-run the command. If it looks like the screenshot above you're ready to go to next step.

after the installation leave CMD.
2) Go to driver folder, find the .inf file right click and press install.
View attachment 5195737
3)Download this file and install it, after installing plug your phone to PC by connecting your phone to PC while doing Vol+- . You might need this driver as well if it's not detected.

3a6d351fec8ab9961a5e3.png

Press next, connect your device to PC while holding Vol+- buttons (your device needs to be powered off) and you will see the mtkdriver down below. Install it.
310b8508659201f6729f7.png

Choose MediaTek USB Port and install it.
4)Turn off your phone and again connect to PC while holding Vol+- buttons then run the brom.bat under Bypass folder. If it says "Protection Disabled" in the end you're ready to go on. (If it's like the screenshot below go on.)
View attachment 5196231
If you had a problem here, please check the end of the guide for it's fix.

5)Go into Flash Tool folder and open the SPFlash tool, after that choose scatter file and also if not set, set your download -agent. You don't need to select auth file as authorization is disabled. Once you do it, it should look like this. ALWAYS MAKE SURE DOWNLOAD ONLY MODE IS SELECTED! DON'T SELECT OTHER MODES!

View attachment 5202549
Click choose DA Agent. (I uploaded an updated bypass tools pack, if you're using older download new one) Go into Bypass Tools Pack > Verified Boot Fix > Choose the "DA_6765_6785_6768_6873_6885_6853.bin" file.

If its giving error go into Options menu and disable option shown below. You will be able to choose a DA file.
View attachment 5202533

73cff8e3aa78249f2d298.png

Make SURE "Download Only" is selected. Don't select ANYTHING ELSE! You will lose your IMEIs, Serial Numbers, Capability of Hardware Attestation etc. if you choose "Format data + Download" make SURE you selected "Download Only".
1f97e3897519622afb94d.png


After flashing it should look like this. Download has been complete. Enjoy!

Now, you can start downloading with the button and after that a checkmark will appear. You can reboot your phone and use it like before now! All your userdata will (inevitably) be cleared!

POSSIBLE ERROR: "Verified boot enabled."
View attachment 5197259

There are 2 fixes to this.
1st Method (DIRECT FIX):
View attachment 5202549
Click choose DA Agent. (I uploaded an updated bypass tools pack, if you're using older download new one) Go into Bypass Tools Pack > Verified Boot Fix > Choose the "DA_6765_6785_6768_6873_6885_6853.bin" file.

If its giving error go into Options menu and disable option shown below. You will be able to choose a DA file.
View attachment 5202533

2nd Method (WORKAROUND):
If you're getting this error, and you are SURE you used "Download Only" mode, there's a way to get rid of this. First, load the scatter then untick/deselect partitions listed below.

opporeserve2,
cdt_engineering,
my_custom,
special_preload,
userdata,
super,

After running brom.bat and flashing all partitions except the ones listed above, your phone will be able to reboot to stock recovery. Now select " Power Off" option then go run brom.bat, bypass authorization and then flash partitions listed below from SPFlash Tool.

super,
dtbo,
userdata

Your device will be able to boot into system after this if you have followed steps correctly.

POSSIBLE ERROR: Issues while disabling protection;


View attachment 5196241
Power off your device Restart the process from 2nd step.

POSSIBLE ERROR: Issues while flashing;
View attachment 5196249

Power off your device, you will need to do the bypass again. Check your USB Cable, there might be a disconnection. If not, start from 3rd step and make sure you did everything right.

So, welcome to hell(!).

For people who want to downgrade:
If you want to downgrade to any version you would like, just use the B23 file as it is the oldest ofp file i could find for extracting process. If you were on EU version before (Any version starting with A) download ozip from here(for EU) , here(for Global) and manually flash from Realme UI recovery and format your data. Your device will be back at A.XY firmware with EU features (No heytap, no ads, no theme store, no bloatware) you had before.

For people on EU who want to unbrick:
So, you can use any version starting with B and it should work. It works in my case, i was on A.48, i flashed B53 and over that flashed B23. No probs at all. If you want to return to EU rom (starting with A) download ozip from here and manually flash from Realme UI recovery and format your data. Your device will be back at A.XY firmware with EU features (No heytap, no ads, no theme store, no bloatware) you had before.

Thanks --
https://github.com/bkerler/oppo_decrypt for decryptor.
https://github.com/MTK-bypass for creating the tool.

Hello everyone! So after the new mediatek DAA and SLA protection bypasses you can find github repo of here , using the bypass we are able to use SPFlash Tool, here is a guide how you can do it! This guide is for RMX2001, RMX2002 and RMX2003 ONLY. DON'T DO ANY OF THESE IF YOU HAVE SOMETHING ELSE!

PLEASE SEE "TROUBLESHOOTING" AT THE END OF THE GUIDE FIRST IF YOU HAVE PROBLEMS IN THE PROCESS BEFORE ASKING!


ALWAYS USE DOWNLOAD ONLY MODE OF SP FLASH TOOL.
DON'T TOUCH ANYTHING RELATED TO FORMAT ON SP FLASH TOOL! (IT'S WRITTEN EVERYWHERE, YOU WILL LOSE YOUR IMEIS IF YOU USE FORMAT ALL + DOWNLOAD. YOU ARE SAFE IF YOU USE DOWNLOAD ONLY.)


VIDEO GUIDES



FOR LINUX METHOD CLICK HERE - Credits to @bx2_nero

Windows Method

Requirements:
Bypass Tools Pack - (SPFLASH TOOL, DRIVER AND BYPASS FILES)

Decrypted OFP (OPPO FIRMWARE PACKAGE) Files:

FULL FIRMWARE - INCLUDES THE "USERDATA" PARTITION, HENCE LARGER.
B.53 - Mega - Google Drive - Mirror3
B.37 - Mega - Google Drive 2
B.23 (First RUI Update for the device) - Mega - Google Drive - Mirror3
A.50[EU] - Mega - Google Drive
A.42[EU] - Google Drive - Mirror2


NOU (NO USERDATA) FIRMWARE - FOR PEOPLE WITH LIMITED DATA PLAN.
B.53 - Google Drive - Mirror 2
B.37 - Google Drive - Mirror 2
B.23 - Google Drive - Mirror 2
A.50[EU] - Mega - Google Drive
A.42[EU] - Google Drive - Mirror2

Please read an explanation of what is userdata partition and how different is this from other firmware here.
Note: All files with available links above are tested.

Python (Must add to PATH during installation, see screenshot if you don't understand)
libusb-win32 - Having Issues? Use this.

aaf0ca5590e6884c234b1.png

Make sure to choose the last option.
1)Open command prompt by running cmd,
enter
python -m pip install pyusb pyserial json5
View attachment 5195739
After the installation, you can re-run the command. If it looks like the screenshot above you're ready to go to next step.

after the installation leave CMD.
2) Go to driver folder, find the .inf file right click and press install.
View attachment 5195737
3)Download this file and install it, after installing plug your phone to PC by connecting your phone to PC while doing Vol+- . You might need this driver as well if it's not detected.

3a6d351fec8ab9961a5e3.png

Press next, connect your device to PC while holding Vol+- buttons (your device needs to be powered off) and you will see the mtkdriver down below. Install it.
310b8508659201f6729f7.png

Choose MediaTek USB Port and install it.
4)Turn off your phone and again connect to PC while holding Vol+- buttons then run the brom.bat under Bypass folder. If it says "Protection Disabled" in the end you're ready to go on. (If it's like the screenshot below go on.)
View attachment 5196231
If you had a problem here, please check the end of the guide for it's fix.

5)Go into Flash Tool folder and open the SPFlash tool, after that choose scatter file and also if not set, set your download -agent. You don't need to select auth file as authorization is disabled. Once you do it, it should look like this. ALWAYS MAKE SURE DOWNLOAD ONLY MODE IS SELECTED! DON'T SELECT OTHER MODES!

View attachment 5202549
Click choose DA Agent. (I uploaded an updated bypass tools pack, if you're using older download new one) Go into Bypass Tools Pack > Verified Boot Fix > Choose the "DA_6765_6785_6768_6873_6885_6853.bin" file.

If its giving error go into Options menu and disable option shown below. You will be able to choose a DA file.
View attachment 5202533

73cff8e3aa78249f2d298.png

Make SURE "Download Only" is selected. Don't select ANYTHING ELSE! You will lose your IMEIs, Serial Numbers, Capability of Hardware Attestation etc. if you choose "Format data + Download" make SURE you selected "Download Only".
1f97e3897519622afb94d.png


After flashing it should look like this. Download has been complete. Enjoy!

Now, you can start downloading with the button and after that a checkmark will appear. You can reboot your phone and use it like before now! All your userdata will (inevitably) be cleared!

POSSIBLE ERROR: "Verified boot enabled."
View attachment 5197259

There are 2 fixes to this.
1st Method (DIRECT FIX):
View attachment 5202549
Click choose DA Agent. (I uploaded an updated bypass tools pack, if you're using older download new one) Go into Bypass Tools Pack > Verified Boot Fix > Choose the "DA_6765_6785_6768_6873_6885_6853.bin" file.

If its giving error go into Options menu and disable option shown below. You will be able to choose a DA file.
View attachment 5202533

2nd Method (WORKAROUND):
If you're getting this error, and you are SURE you used "Download Only" mode, there's a way to get rid of this. First, load the scatter then untick/deselect partitions listed below.

opporeserve2,
cdt_engineering,
my_custom,
special_preload,
userdata,
super,

After running brom.bat and flashing all partitions except the ones listed above, your phone will be able to reboot to stock recovery. Now select " Power Off" option then go run brom.bat, bypass authorization and then flash partitions listed below from SPFlash Tool.

super,
dtbo,
userdata

Your device will be able to boot into system after this if you have followed steps correctly.

POSSIBLE ERROR: Issues while disabling protection;


View attachment 5196241
Power off your device Restart the process from 2nd step.

POSSIBLE ERROR: Issues while flashing;
View attachment 5196249

Power off your device, you will need to do the bypass again. Check your USB Cable, there might be a disconnection. If not, start from 3rd step and make sure you did everything right.

So, welcome to hell(!).

For people who want to downgrade:
If you want to downgrade to any version you would like, just use the B23 file as it is the oldest ofp file i could find for extracting process. If you were on EU version before (Any version starting with A) download ozip from here(for EU) , here(for Global) and manually flash from Realme UI recovery and format your data. Your device will be back at A.XY firmware with EU features (No heytap, no ads, no theme store, no bloatware) you had before.

For people on EU who want to unbrick:
So, you can use any version starting with B and it should work. It works in my case, i was on A.48, i flashed B53 and over that flashed B23. No probs at all. If you want to return to EU rom (starting with A) download ozip from here and manually flash from Realme UI recovery and format your data. Your device will be back at A.XY firmware with EU features (No heytap, no ads, no theme store, no bloatware) you had before.

Thanks --
https://github.com/bkerler/oppo_decrypt for decryptor.
https://github.com/MTK-bypass for creating the tool.
What can i do to solve the problem after i have done all the steps shown it throws back an error download not completed
 

Crazy_xcx

Member
Mar 13, 2021
13
0
Hello today I Have Flashed B.53 full firmware on my realme 6 and now it start rebooting in recovery again and again .I have Tried wipe data after flashing and than reboot my device but still having the same problem. One more thing when I wiped data and againg rebooted into the recovery it shows this code (r_traits<char>,std::_allocator<char>>const&,std::_1::ba) if someone have any solution please reply waiting for a solution .Thank You
i am having the same issue please reply someone
 

aniketjjp66

New member
Dec 15, 2022
1
0
I just bricked my realme 6i (rmx2002) . Will this method work on realme 6i. I tried but it keep failing.
 

tr3ty

New member
Mar 4, 2023
1
0
Hello everyone! So after the new mediatek DAA and SLA protection bypasses you can find github repo of here , using the bypass we are able to use SPFlash Tool, here is a guide how you can do it! This guide is for RMX2001, RMX2002 and RMX2003 ONLY. DON'T DO ANY OF THESE IF YOU HAVE SOMETHING ELSE!

PLEASE SEE "TROUBLESHOOTING" AT THE END OF THE GUIDE FIRST IF YOU HAVE PROBLEMS IN THE PROCESS BEFORE ASKING!


ALWAYS USE DOWNLOAD ONLY MODE OF SP FLASH TOOL.
DON'T TOUCH ANYTHING RELATED TO FORMAT ON SP FLASH TOOL! (IT'S WRITTEN EVERYWHERE, YOU WILL LOSE YOUR IMEIS IF YOU USE FORMAT ALL + DOWNLOAD. YOU ARE SAFE IF YOU USE DOWNLOAD ONLY.)


VIDEO GUIDES



FOR LINUX METHOD CLICK HERE - Credits to @bx2_nero

Windows Method

Requirements:
Bypass Tools Pack - (SPFLASH TOOL, DRIVER AND BYPASS FILES)

Decrypted OFP (OPPO FIRMWARE PACKAGE) Files:

FULL FIRMWARE - INCLUDES THE "USERDATA" PARTITION, HENCE LARGER.
B.53 - Mega - Google Drive - Mirror3
B.37 - Mega - Google Drive 2
B.23 (First RUI Update for the device) - Mega - Google Drive - Mirror3
A.50[EU] - Mega - Google Drive
A.42[EU] - Google Drive - Mirror2


NOU (NO USERDATA) FIRMWARE - FOR PEOPLE WITH LIMITED DATA PLAN.
B.53 - Google Drive - Mirror 2
B.37 - Google Drive - Mirror 2
B.23 - Google Drive - Mirror 2
A.50[EU] - Mega - Google Drive
A.42[EU] - Google Drive - Mirror2

Please read an explanation of what is userdata partition and how different is this from other firmware here.
Note: All files with available links above are tested.

Python (Must add to PATH during installation, see screenshot if you don't understand)
libusb-win32 - Having Issues? Use this.

aaf0ca5590e6884c234b1.png

Make sure to choose the last option.
1)Open command prompt by running cmd,
enter
python -m pip install pyusb pyserial json5
View attachment 5195739
After the installation, you can re-run the command. If it looks like the screenshot above you're ready to go to next step.

after the installation leave CMD.
2) Go to driver folder, find the .inf file right click and press install.
View attachment 5195737
3)Download this file and install it, after installing plug your phone to PC by connecting your phone to PC while doing Vol+- . You might need this driver as well if it's not detected.

3a6d351fec8ab9961a5e3.png

Press next, connect your device to PC while holding Vol+- buttons (your device needs to be powered off) and you will see the mtkdriver down below. Install it.
310b8508659201f6729f7.png

Choose MediaTek USB Port and install it.
4)Turn off your phone and again connect to PC while holding Vol+- buttons then run the brom.bat under Bypass folder. If it says "Protection Disabled" in the end you're ready to go on. (If it's like the screenshot below go on.)
View attachment 5196231
If you had a problem here, please check the end of the guide for it's fix.

5)Go into Flash Tool folder and open the SPFlash tool, after that choose scatter file and also if not set, set your download -agent. You don't need to select auth file as authorization is disabled. Once you do it, it should look like this. ALWAYS MAKE SURE DOWNLOAD ONLY MODE IS SELECTED! DON'T SELECT OTHER MODES!

View attachment 5202549
Click choose DA Agent. (I uploaded an updated bypass tools pack, if you're using older download new one) Go into Bypass Tools Pack > Verified Boot Fix > Choose the "DA_6765_6785_6768_6873_6885_6853.bin" file.

If its giving error go into Options menu and disable option shown below. You will be able to choose a DA file.
View attachment 5202533

73cff8e3aa78249f2d298.png

Make SURE "Download Only" is selected. Don't select ANYTHING ELSE! You will lose your IMEIs, Serial Numbers, Capability of Hardware Attestation etc. if you choose "Format data + Download" make SURE you selected "Download Only".
1f97e3897519622afb94d.png


After flashing it should look like this. Download has been complete. Enjoy!

Now, you can start downloading with the button and after that a checkmark will appear. You can reboot your phone and use it like before now! All your userdata will (inevitably) be cleared!

POSSIBLE ERROR: "Verified boot enabled."
View attachment 5197259

There are 2 fixes to this.
1st Method (DIRECT FIX):
View attachment 5202549
Click choose DA Agent. (I uploaded an updated bypass tools pack, if you're using older download new one) Go into Bypass Tools Pack > Verified Boot Fix > Choose the "DA_6765_6785_6768_6873_6885_6853.bin" file.

If its giving error go into Options menu and disable option shown below. You will be able to choose a DA file.
View attachment 5202533

2nd Method (WORKAROUND):
If you're getting this error, and you are SURE you used "Download Only" mode, there's a way to get rid of this. First, load the scatter then untick/deselect partitions listed below.

opporeserve2,
cdt_engineering,
my_custom,
special_preload,
userdata,
super,

After running brom.bat and flashing all partitions except the ones listed above, your phone will be able to reboot to stock recovery. Now select " Power Off" option then go run brom.bat, bypass authorization and then flash partitions listed below from SPFlash Tool.

super,
dtbo,
userdata

Your device will be able to boot into system after this if you have followed steps correctly.

POSSIBLE ERROR: Issues while disabling protection;


View attachment 5196241
Power off your device Restart the process from 2nd step.

POSSIBLE ERROR: Issues while flashing;
View attachment 5196249

Power off your device, you will need to do the bypass again. Check your USB Cable, there might be a disconnection. If not, start from 3rd step and make sure you did everything right.

So, welcome to hell(!).

For people who want to downgrade:
If you want to downgrade to any version you would like, just use the B23 file as it is the oldest ofp file i could find for extracting process. If you were on EU version before (Any version starting with A) download ozip from here(for EU) , here(for Global) and manually flash from Realme UI recovery and format your data. Your device will be back at A.XY firmware with EU features (No heytap, no ads, no theme store, no bloatware) you had before.

For people on EU who want to unbrick:
So, you can use any version starting with B and it should work. It works in my case, i was on A.48, i flashed B53 and over that flashed B23. No probs at all. If you want to return to EU rom (starting with A) download ozip from here and manually flash from Realme UI recovery and format your data. Your device will be back at A.XY firmware with EU features (No heytap, no ads, no theme store, no bloatware) you had before.

Thanks --
https://github.com/bkerler/oppo_decrypt for decryptor.
https://github.com/MTK-bypass for creating the tool.
bro can you to communicate on discord(bana discorddan ulaşabilirmisin) Recep#8274
 
Apr 8, 2023
5
0
Hi everone,
I need help as I stuck in the orange state, tried to Flash B53 and B37 but still it is at the same state and my relame ui recovery is opne some time but unable to detect SD card and for the online update it s not connecting with the WIFI please help.
 

Crazy_xcx

Member
Mar 13, 2021
13
0
Hi everone,
I need help as I stuck in the orange state, tried to Flash B53 and B37 but still it is at the same state and my relame ui recovery is opne some time but unable to detect SD card and for the online update it s not connecting with the WIFI please help.
Is your phone stuck in bootloop not able to boot you should try b.65 it will boot the recovery will not work use a PC using bypass tools to bypass mtk auth and flash tool to flash the stock rom b.65
 

bx2nero

Senior Member
Apr 22, 2015
297
89
Can you please share the b.65 decrypted file. Also need help in recovering IMEI number as I have formated my device with Sp tool 🥵
B65 decrypted file has working link in the Linux guide, check out
Unfortunately IMEI cannot be restored
visit SC to change mobo.
Thats why it has been clearly written in the guide to never use that.
 

labu kundur

New member
Aug 1, 2023
2
0
Hello everyone! So after the new mediatek DAA and SLA protection bypasses you can find github repo of here , using the bypass we are able to use SPFlash Tool, here is a guide how you can do it! This guide is for RMX2001, RMX2002 and RMX2003 ONLY. DON'T DO ANY OF THESE IF YOU HAVE SOMETHING ELSE!

PLEASE SEE "TROUBLESHOOTING" AT THE END OF THE GUIDE FIRST IF YOU HAVE PROBLEMS IN THE PROCESS BEFORE ASKING!


ALWAYS USE DOWNLOAD ONLY MODE OF SP FLASH TOOL.
DON'T TOUCH ANYTHING RELATED TO FORMAT ON SP FLASH TOOL! (IT'S WRITTEN EVERYWHERE, YOU WILL LOSE YOUR IMEIS IF YOU USE FORMAT ALL + DOWNLOAD. YOU ARE SAFE IF YOU USE DOWNLOAD ONLY.)


VIDEO GUIDES



FOR LINUX METHOD CLICK HERE - Credits to @bx2_nero

Windows Method

Requirements:
Bypass Tools Pack - (SPFLASH TOOL, DRIVER AND BYPASS FILES)

Decrypted OFP (OPPO FIRMWARE PACKAGE) Files:

FULL FIRMWARE - INCLUDES THE "USERDATA" PARTITION, HENCE LARGER.
B.53 - Mega - Google Drive - Mirror3
B.37 - Mega - Google Drive 2
B.23 (First RUI Update for the device) - Mega - Google Drive - Mirror3
A.50[EU] - Mega - Google Drive
A.42[EU] - Google Drive - Mirror2


NOU (NO USERDATA) FIRMWARE - FOR PEOPLE WITH LIMITED DATA PLAN.
B.53 - Google Drive - Mirror 2
B.37 - Google Drive - Mirror 2
B.23 - Google Drive - Mirror 2
A.50[EU] - Mega - Google Drive
A.42[EU] - Google Drive - Mirror2

Please read an explanation of what is userdata partition and how different is this from other firmware here.
Note: All files with available links above are tested.

Python (Must add to PATH during installation, see screenshot if you don't understand)
libusb-win32 - Having Issues? Use this.

aaf0ca5590e6884c234b1.png

Make sure to choose the last option.
1)Open command prompt by running cmd,
enter
python -m pip install pyusb pyserial json5
View attachment 5195739
After the installation, you can re-run the command. If it looks like the screenshot above you're ready to go to next step.

after the installation leave CMD.
2) Go to driver folder, find the .inf file right click and press install.
View attachment 5195737
3)Download this file and install it, after installing plug your phone to PC by connecting your phone to PC while doing Vol+- . You might need this driver as well if it's not detected.

3a6d351fec8ab9961a5e3.png

Press next, connect your device to PC while holding Vol+- buttons (your device needs to be powered off) and you will see the mtkdriver down below. Install it.
310b8508659201f6729f7.png

Choose MediaTek USB Port and install it.
4)Turn off your phone and again connect to PC while holding Vol+- buttons then run the brom.bat under Bypass folder. If it says "Protection Disabled" in the end you're ready to go on. (If it's like the screenshot below go on.)
View attachment 5196231
If you had a problem here, please check the end of the guide for it's fix.

5)Go into Flash Tool folder and open the SPFlash tool, after that choose scatter file and also if not set, set your download -agent. You don't need to select auth file as authorization is disabled. Once you do it, it should look like this. ALWAYS MAKE SURE DOWNLOAD ONLY MODE IS SELECTED! DON'T SELECT OTHER MODES!

View attachment 5202549
Click choose DA Agent. (I uploaded an updated bypass tools pack, if you're using older download new one) Go into Bypass Tools Pack > Verified Boot Fix > Choose the "DA_6765_6785_6768_6873_6885_6853.bin" file.

If its giving error go into Options menu and disable option shown below. You will be able to choose a DA file.
View attachment 5202533

73cff8e3aa78249f2d298.png

Make SURE "Download Only" is selected. Don't select ANYTHING ELSE! You will lose your IMEIs, Serial Numbers, Capability of Hardware Attestation etc. if you choose "Format data + Download" make SURE you selected "Download Only".
1f97e3897519622afb94d.png


After flashing it should look like this. Download has been complete. Enjoy!

Now, you can start downloading with the button and after that a checkmark will appear. You can reboot your phone and use it like before now! All your userdata will (inevitably) be cleared!

POSSIBLE ERROR: "Verified boot enabled."
View attachment 5197259

There are 2 fixes to this.
1st Method (DIRECT FIX):
View attachment 5202549
Click choose DA Agent. (I uploaded an updated bypass tools pack, if you're using older download new one) Go into Bypass Tools Pack > Verified Boot Fix > Choose the "DA_6765_6785_6768_6873_6885_6853.bin" file.

If its giving error go into Options menu and disable option shown below. You will be able to choose a DA file.
View attachment 5202533

2nd Method (WORKAROUND):
If you're getting this error, and you are SURE you used "Download Only" mode, there's a way to get rid of this. First, load the scatter then untick/deselect partitions listed below.

opporeserve2,
cdt_engineering,
my_custom,
special_preload,
userdata,
super,

After running brom.bat and flashing all partitions except the ones listed above, your phone will be able to reboot to stock recovery. Now select " Power Off" option then go run brom.bat, bypass authorization and then flash partitions listed below from SPFlash Tool.

super,
dtbo,
userdata

Your device will be able to boot into system after this if you have followed steps correctly.

POSSIBLE ERROR: Issues while disabling protection;


View attachment 5196241
Power off your device Restart the process from 2nd step.

POSSIBLE ERROR: Issues while flashing;
View attachment 5196249

Power off your device, you will need to do the bypass again. Check your USB Cable, there might be a disconnection. If not, start from 3rd step and make sure you did everything right.

So, welcome to hell(!).

For people who want to downgrade:
If you want to downgrade to any version you would like, just use the B23 file as it is the oldest ofp file i could find for extracting process. If you were on EU version before (Any version starting with A) download ozip from here(for EU) , here(for Global) and manually flash from Realme UI recovery and format your data. Your device will be back at A.XY firmware with EU features (No heytap, no ads, no theme store, no bloatware) you had before.

For people on EU who want to unbrick:
So, you can use any version starting with B and it should work. It works in my case, i was on A.48, i flashed B53 and over that flashed B23. No probs at all. If you want to return to EU rom (starting with A) download ozip from here and manually flash from Realme UI recovery and format your data. Your device will be back at A.XY firmware with EU features (No heytap, no ads, no theme store, no bloatware) you had before.

Thanks --
https://github.com/bkerler/oppo_decrypt for decryptor.
https://github.com/MTK-bypass for creating the tool.
i have Realme 6i G85 MTK 6787 with 3gb ram. which firmware should i use. i already tried many firmware but not working..
 
Last edited:

phantom5985

New member
Aug 14, 2023
1
0
i did try all the lnks above but non og it works can you provide me with some new kinks so i can recover my phone
 

Top Liked Posts

  • There are no posts matching your filters.
  • 17
    Hello everyone! So after the new mediatek DAA and SLA protection bypasses you can find github repo of here , using the bypass we are able to use SPFlash Tool, here is a guide how you can do it! This guide is for RMX2001, RMX2002 and RMX2003 ONLY. DON'T DO ANY OF THESE IF YOU HAVE SOMETHING ELSE!

    PLEASE SEE "TROUBLESHOOTING" AT THE END OF THE GUIDE FIRST IF YOU HAVE PROBLEMS IN THE PROCESS BEFORE ASKING!


    ALWAYS USE DOWNLOAD ONLY MODE OF SP FLASH TOOL.
    DON'T TOUCH ANYTHING RELATED TO FORMAT ON SP FLASH TOOL! (IT'S WRITTEN EVERYWHERE, YOU WILL LOSE YOUR IMEIS IF YOU USE FORMAT ALL + DOWNLOAD. YOU ARE SAFE IF YOU USE DOWNLOAD ONLY.)


    VIDEO GUIDES



    FOR LINUX METHOD CLICK HERE - Credits to @bx2_nero

    Windows Method

    Requirements:
    Bypass Tools Pack - (SPFLASH TOOL, DRIVER AND BYPASS FILES)

    Decrypted OFP (OPPO FIRMWARE PACKAGE) Files:

    FULL FIRMWARE - INCLUDES THE "USERDATA" PARTITION, HENCE LARGER.
    B.53 - Mega - Google Drive - Mirror3
    B.37 - Mega - Google Drive 2
    B.23 (First RUI Update for the device) - Mega - Google Drive - Mirror3
    A.50[EU] - Mega - Google Drive
    A.42[EU] - Google Drive - Mirror2


    NOU (NO USERDATA) FIRMWARE - FOR PEOPLE WITH LIMITED DATA PLAN.
    B.53 - Google Drive - Mirror 2
    B.37 - Google Drive - Mirror 2
    B.23 - Google Drive - Mirror 2
    A.50[EU] - Mega - Google Drive
    A.42[EU] - Google Drive - Mirror2

    Please read an explanation of what is userdata partition and how different is this from other firmware here.
    Note: All files with available links above are tested.

    Python (Must add to PATH during installation, see screenshot if you don't understand)
    libusb-win32 - Having Issues? Use this.

    aaf0ca5590e6884c234b1.png

    Make sure to choose the last option.
    1)Open command prompt by running cmd,
    enter
    python -m pip install pyusb pyserial json5
    1611352854113.png

    After the installation, you can re-run the command. If it looks like the screenshot above you're ready to go to next step.

    after the installation leave CMD.
    2) Go to driver folder, find the .inf file right click and press install.
    1611352830350.png

    3)Download this file and install it, after installing plug your phone to PC by connecting your phone to PC while doing Vol+- . You might need this driver as well if it's not detected.

    3a6d351fec8ab9961a5e3.png

    Press next, connect your device to PC while holding Vol+- buttons (your device needs to be powered off) and you will see the mtkdriver down below. Install it.
    310b8508659201f6729f7.png

    Choose MediaTek USB Port and install it.
    4)Turn off your phone and again connect to PC while holding Vol+- buttons then run the brom.bat under Bypass folder. If it says "Protection Disabled" in the end you're ready to go on. (If it's like the screenshot below go on.)
    1611391901952.png

    If you had a problem here, please check the end of the guide for it's fix.

    5)Go into Flash Tool folder and open the SPFlash tool, after that choose scatter file and also if not set, set your download -agent. You don't need to select auth file as authorization is disabled. Once you do it, it should look like this. ALWAYS MAKE SURE DOWNLOAD ONLY MODE IS SELECTED! DON'T SELECT OTHER MODES!

    1611929163628.png

    Click choose DA Agent. (I uploaded an updated bypass tools pack, if you're using older download new one) Go into Bypass Tools Pack > Verified Boot Fix > Choose the "DA_6765_6785_6768_6873_6885_6853.bin" file.

    If its giving error go into Options menu and disable option shown below. You will be able to choose a DA file.
    1611928718706.png


    73cff8e3aa78249f2d298.png

    Make SURE "Download Only" is selected. Don't select ANYTHING ELSE! You will lose your IMEIs, Serial Numbers, Capability of Hardware Attestation etc. if you choose "Format data + Download" make SURE you selected "Download Only".
    1f97e3897519622afb94d.png


    After flashing it should look like this. Download has been complete. Enjoy!

    Now, you can start downloading with the button and after that a checkmark will appear. You can reboot your phone and use it like before now! All your userdata will (inevitably) be cleared!

    POSSIBLE ERROR: "Verified boot enabled."
    1611478791612.png


    There are 2 fixes to this.
    1st Method (DIRECT FIX):
    1611929163628.png

    Click choose DA Agent. (I uploaded an updated bypass tools pack, if you're using older download new one) Go into Bypass Tools Pack > Verified Boot Fix > Choose the "DA_6765_6785_6768_6873_6885_6853.bin" file.

    If its giving error go into Options menu and disable option shown below. You will be able to choose a DA file.
    1611928718706.png


    2nd Method (WORKAROUND):
    If you're getting this error, and you are SURE you used "Download Only" mode, there's a way to get rid of this. First, load the scatter then untick/deselect partitions listed below.

    opporeserve2,
    cdt_engineering,
    my_custom,
    special_preload,
    userdata,
    super,

    After running brom.bat and flashing all partitions except the ones listed above, your phone will be able to reboot to stock recovery. Now select " Power Off" option then go run brom.bat, bypass authorization and then flash partitions listed below from SPFlash Tool.

    super,
    dtbo,
    userdata

    Your device will be able to boot into system after this if you have followed steps correctly.

    POSSIBLE ERROR: Issues while disabling protection;


    1611392223180.png

    Power off your device Restart the process from 2nd step.

    POSSIBLE ERROR: Issues while flashing;
    1611392834527.png


    Power off your device, you will need to do the bypass again. Check your USB Cable, there might be a disconnection. If not, start from 3rd step and make sure you did everything right.

    So, welcome to hell(!).

    For people who want to downgrade:
    If you want to downgrade to any version you would like, just use the B23 file as it is the oldest ofp file i could find for extracting process. If you were on EU version before (Any version starting with A) download ozip from here(for EU) , here(for Global) and manually flash from Realme UI recovery and format your data. Your device will be back at A.XY firmware with EU features (No heytap, no ads, no theme store, no bloatware) you had before.

    For people on EU who want to unbrick:
    So, you can use any version starting with B and it should work. It works in my case, i was on A.48, i flashed B53 and over that flashed B23. No probs at all. If you want to return to EU rom (starting with A) download ozip from here and manually flash from Realme UI recovery and format your data. Your device will be back at A.XY firmware with EU features (No heytap, no ads, no theme store, no bloatware) you had before.

    Thanks --
    https://github.com/bkerler/oppo_decrypt for decryptor.
    https://github.com/MTK-bypass for creating the tool.
    2
    I just unbricked mine (realme 6) with a Red State warning error.

    •Download Mediatek Bypass Tool by MCT TEAM.
    • set Target SOC to [AUTO] then tap BYPASS.
    •while device is in bootloop (press Vol+ and Vol- then Power at the same time.) if screen is off just press and hold Vol+ and Vol- until you see the protection is off.
    ———
    •Open SPFTool.
    •load this = “DA_6765_6785_6768_6873_6885_6853.bin” and the usual scatter_file.txt.
    •now Press “Download”.
    If done correctly the program should continue until done without any error like verified boot etc.
    Files are included.
    I hope this helps. :D
    716F78B2-B03B-421C-9881-C6FDEECC1E11.jpeg
    2
    It is firmware for the device you mentioned, RMX2040, hence, yes.
    OMG, thank you very much. without your help and tutorial I can't bring my phone back from the dead. God bless Mabuhay
    2
    bro can we use this method to revert back from latest b59 firmware in realme 6
    Yes obviously !
    1
    Thank you for your efforts. Can you add the decrypted A34 file?
    Hello! I wasn't able to find factory package (ofp) files for any version that makes sense for versions starting with A. (EU). There are A11 and A08 which according to update trackers, did never exist and the A.11 package is %50 larger than all the other files weirdly. I have contacted owner of some sites that do upload files like these and they asked for money. If it's a resonable price i will get it, decrypt it and upload here! If you were able to find any versions starting with A, feel free to message me on telegram (@ctivity) or email me!