
Reverse engineering the BYD Dolphin head unit — CAN bus, AVAS, NFC keys, OTA, and more. DiLink 3 / Android 10.
Reverse engineering, documentation, and tooling for the BYD Dolphin 25/26 infotainment system (DiLink 3, Android 10).
Everything here was discovered through ADB exploration, APK decompilation, and CAN bus probing — no proprietary documentation was used.
⚠️ Disclaimer: Unofficial, community-driven project — no affiliation with BYD. Reverse engineering of BYD's internal Android services for educational and interoperability purposes only. Use at your own risk — modifying vehicle software may void your warranty or violate BYD's terms of service. The authors assume no liability for any damage to your vehicle, software, or data.
| Property | Value |
|---|---|
| Platform | DiLink 3.0 |
| Android | 10 (API 29) |
| SoC | Qualcomm QCM6125 (SM6125 Trinket) |
| Architecture | ARM64, 8 cores |
| RAM | ~3.5 GB |
| Kernel | 4.14.117-perf |
| ADB | WiFi, port 5555 |
| Head Unit IP | 192.168.10.10 (car WiFi) |
| Firmware | 13.1.32.2507250.1 (Jul 25 2025) |
| MCU | 13.5.2.2312260.1 |
| DSP | 13.5.5.2505300.2 |
| Bootloader | Unlocked (ro.boot.flash.locked=0) |
| Verified boot | Orange (unlocked) |
| Instrument Cluster | Separate Qt/QML system (Qt 5.15.10 / 6.5.5) |
Tested on firmware
13.1.32.2507250.1. Older versions likely work. Newer firmware updates from BYD may change or break things — no guarantees.
New here? Start with the Sideloading Guide to install apps on your BYD — no root needed.
For custom apps built on this research, see byd-apps.
adb connect 192.168.10.10:5555
Third Party Apps XX folder (country code suffix), plug into carBYD6125F (universal across DiLink 3)targetSdk ≤ 33, minSdk ≤ 29Inject CAN frames from ADB — no root, no OBD2 dongle:
# 1. Start the ClusterDebug app + service (acts as privileged proxy)
adb shell "am start -n com.byd.clusterdebug/.MainActivity"
adb shell "am startservice -n com.byd.clusterdebug/.ClusterDebugService"
# 2. Inject CAN frames
adb shell "am broadcast -a com.byd.cluster.spi --es normal 'FF,FF,FF,FF,FF,FF,FF,FF'"
# 3. Capture cluster screenshot
adb shell "fission_screencap -d 1 -p /data/local/tmp/cluster.png"
adb pull /data/local/tmp/cluster.png
See Driver Display for the full UDS diagnostic protocol, CAN frame format, and ECU network topology.
| Feature | Details |
|---|---|
| AC temperature reading | getTemprature(zone) — zone 1/2 = set temp, zone 4 = outside/ambient |
| Full AC control | 40+ getter + SET methods (start/stop, temp, fan, wind mode) via permission bypass |
| AC remote control | hasFeature("ACRemoteControl") = 1, supports 10–30min timer |
| Permission bypass | BydPermissionContext (ContextWrapper) auto-grants BYDAUTO_* permissions client-side |
| CAN bus read/write | Via ADB using app_process + reflection |
| 75+ BYD packages | With CAN bus access, 100+ custom BYDAUTO_* permissions |
| Engine simulator sound | Simulator present and switchable (HAS_SIMULATOR=2), preset selected via 0x3E300038. The MCU stores and echoes back any source type — verified to 200; only 0 is rejected — so acceptance does not imply a distinct sound and the number of real presets is not discoverable through this API. 0x48F00013 returns 1 meaning "a source exists", not a count. — Engine Sound app |
| AVAS preset selection | CAN-writable — UI shows 2 but MCU accepts 0–5+ |
| setBuffer PCM streaming | 128-byte PCM frames accepted by MCU (ret=0) for 8+ feature IDs. Max buffer: 128 bytes. Whether MCU interprets as audio unconfirmed. |
| AVAH test tones | Play on AVAS external speaker using factory diagnostic signals (0x6E970010) |
| AVAS melody patterns | 8 working patterns (doorbell, shop chime, alarm, fanfare, etc.) via TEST_AUDIO_AVAS_SET pitch control — Door Sound app |
| CAN bus injection | VCDS-style feature coding possible — inject CAN frames via com.byd.cluster.spi broadcast, no root needed |
| Cluster screenshot | Capture driver display via fission_screencap -d 1 -p <file> |
| Instrument cluster reads | PowerUnit, TempUnit, BacklightCtlType, InsThemeValue via BYDAutoManager |
| DRL toggle | setInt(1004, 0x43100046, 1/2) — DRL auto mode ON/OFF, confirmed by readback |
| YUN device (1034) | ALL 0xAA feature IDs accepted by MCU — setBuffer(1034, fid, data) and setInt(1034, fid, val) return 0 (OK). Cloudmanager's private MCU channel. Needs AES encryption for actuation. |
| Content providers | Expose vehicle data (battery, tyre pressure, maintenance, trip consumption) |
| Sideloading | USB drive or ADB — see guide |
| 360 camera frames | Live 1280×960 from all four surround cameras, no root. bmmcamera.jar is world-readable — load it yourself and drive JNIBMMCamera directly from a shell-uid app_process. An installed app can never do this (SELinux denies untrusted_app_* the bmmcameraserver binder); a process launched over ADB can — details |
| Feature | Status |
|---|---|
| Door lock status | Main doors return INVALID (0), child lock readable. No dedicated setDoorLockStatus() — needs generic set() with unknown feature IDs |
| 360 camera display control | BYDAutoPanoramaDevice (mode, rotation, transparency) is enforced server-side and the BydPermissionContext bypass fails. Frame capture works — see above |