• Hello ES! We could use some help to get us past the finish line on building the new knowledgebase for the forum.
    Can you donate? Please see our fundraising page. Thank you!

Luna M600 Ludicrous V2 reverse engineering and firmware making

Those are TVS diodes so it is protection from voltage spikes in those circuits.

According to this discussion it looks like this controller uses only analogue signal torque sensor output and it does not use cadence sensor data. I do not know how it affects M560 or M600 motors

 
Usually is another one also against Vcc.

Then is fine if Luna is taking analogue. I can imagine Bafang removed CAN chip from new torque sensors to save some cents.
 
Last edited:
This is how for Innotrace controller the torque sensor is connected. This is for UART torque sensor but I guess it uses the same torque sensor analogue output (and also crank arms direction/speed sensor output). I noticed the pin LJ on the torque sensor is marked the same for M620 UART and M600, I guess this is the same signal on both UART and CAN sensors.

1752081941358.png

1752081984083.png
 
Last edited:
Maybe it's designed this way to 'save' the electronics in case of too high controller temperature. The solder would melt breaking the connection?
Or to simplify manufacturing process.
Yo phobos, do you still want to test the VESC for Bafang m620 UART controller? I designed a cheap version of the power stage so making the controller should not be expensive now


We still need to figure out the VESC firmware for this controller though. It looks like the folks from VESC discord know something about it or may be able to help. But be careful out there, there is mxleming guy and it looks like he has some power on that server and he is really mad lol
 
What does that "Front light load switch" do? For some reason the brake signal (SL pin on the Bafang controller) is shortened on the Front Light Load Switch (QD pin on the Bafang controller) on the Luna controller. Is this how it is on the original Bafang M600 controller?

1752120563387.png

1752120976812.png
 
Just turning on 6V (or 12V with new controllers) for front light (and rear). Then going to first and 3rd connector on the body.
Maybe Luna has not integrated a light. But why would they shorten SL with QD can not explain.
 
Yo phobos, do you still want to test the VESC for Bafang m620 UART controller? I designed a cheap version of the power stage so making the controller should not be expensive now
I looked into it but currently I prefer riding than tinkering, so I'll continue sometime in autumn.
Great work on both controllers so far though, especially this one, pairing it with m560 should be sweet without the bafang firmware BS.
 
Started reverse engineering the main wiring harness connector. It turned out all 3 receptacles on the Bafang M600 motor case have CANL, CANH, 5V and GNG pins and all those pins are connected to the Luna controller. That means we can connect VESC Express dongle outside of the motor using any of those receptacles and use USB or Bluetooth to calibrate the rotary encoder and do another stuff with the controller using the VESC Tool application. That means we might not need that Bluetooth module on the PCB (that part is obsolete and hard to find).

Innotrace controller does not have 5V output and for the VESC for Bafang m620 UART controller I implemented an additional circuitry for 5V and it also requires the motor harness modification to make the VESC Express works with that controller but it looks like the Luna controller should work with VESC Express out of the box (You still need to make a cable for VESC Express though).


1752174165856.png
 
Last edited:
The brakes circuit has been reverse engineered. Some other circuits are also updated

1752200947899.png

1752201004150.png

1752201052876.png

1752201090324.png
 
Good job. Would go higher with R163 and R164. I noticed the throttle halls have soft output. Little better resolution then I guess.
 
Could be just a mistake in Benjamin scheme. Should have been named PC11_TX and PC12_RX. In 300A scheme version it is OK.

What caught my eyes is SWCLK and SWDIO. Does it mean STM32 in VESC can update firmware of the BT module?
I guess we need only Tx and Rx for BT communication.

Also check 300A VESC scheme. I guess this was the source for Luna as they have also 16S, no?
It looks like this motor controller is not capable to update the Bluetooth module firmware. This Bluetooth module should use pins P0.17 and P0.19 for this operation but it looks like those pins are not connected on the Luna controller (I can see no vias under those pins on the opposite side of the board and no extra tracks going around). It looks like it uses the same pins as VESC MK5 except the one dedicated for LED and the one dedicated for the integrated antenna.

1752256505155.png

1752257501591.png


1752257491252.png
 
Last edited:
Reverse engineering of the main harness connector is almost complete and another weird circuit has been found

There is an unmarked pin on the connectors PCB (also unmarked on green Bafang controller PCB and marked IO on blue bafang controller PCB) which is not connected to anything on the connectors PCB. But that pin is connected to this weird circuit with transistors controlled by STM32. There is something should be connected to that pin on the connectors PCB to make it functional. It will not work with the stock Bafang connectors PCB.

1752374516607.png

1752374811581.png

1752374856117.png

1752374906937.png

1752375142051.png
 
And the main harness connector has been reverse engineered. So all the connectors circuits are complete.

There is another not connected to anything on the connectors PCB pin (not marked on the connectors PCB and on the green Bafang controller, and marked "IO" on blue Bafang controller). That pin is connected to STM32 through another weird circuit.

Those circuits might be something Luna used for the controller development or maybe those circuits have a purpose for actual use (which requires the connectors PCB modification and probably the wiring harness modification)

1752379695897.png

1752379930905.png

1752379986821.png

1752380043871.png
 
Last edited:
Yo phobos, do you still want to test the VESC for Bafang m620 UART controller? I designed a cheap version of the power stage so making the controller should not be expensive now


We still need to figure out the VESC firmware for this controller though. It looks like the folks from VESC discord know something about it or may be able to help. But be careful out there, there is mxleming guy and it looks like he has some power on that server and he is really mad lol
Why is this mxleming guy so mad anyway?
You should give the MESC firmware a try — it runs way better on that controller than VESC.
 
Why is this mxleming guy so mad anyway?
You should give the MESC firmware a try — it runs way better on that controller than VESC.
He believes I am Krasnodar and it looks like there is a drama between him and Krasnodar.

I do not know where to take that MESC firmware, but it looks like the guys from the VESC Discord server know how to make VESC firmware works on that controller.
 
Last edited:
Why is this mxleming guy so mad anyway?
You should give the MESC firmware a try — it runs way better on that controller than VESC.
The mad Mxlemming is also here unfortunately.

I have no idea wtf the motivation for this reverse engineering is, but tpehak managed to piss off a discord group with me, hackey from 3shul, marcos from luna, Benjamin vedder, tech from team triforce... Loads of people who actively contribute to the VESC or design commercial hardware... With completely bizarre behaviour, repeatedly refusing help with improvements and refusing to share original innotrace firmware he had attained from some mysterious source.

Deleted user is tpehak in the screenshots below. Make your own mind up if I'm mad. You can of course go and find the discord server and see the whole unredacted conversation if anyone is that excited... It doesn't vary much from the examples given.
 

Attachments

  • Screenshot_20250714-000403.png
    Screenshot_20250714-000403.png
    222.5 KB · Views: 34
  • Screenshot_20250714-000441.png
    Screenshot_20250714-000441.png
    230 KB · Views: 35
  • Screenshot_20250714-000535.png
    Screenshot_20250714-000535.png
    221.8 KB · Views: 30
  • Screenshot_20250714-000611.png
    Screenshot_20250714-000611.png
    221.4 KB · Views: 28
  • Screenshot_20250714-000627.png
    Screenshot_20250714-000627.png
    222.3 KB · Views: 34
The mad Mxlemming is also here unfortunately.

I have no idea wtf the motivation for this reverse engineering is, but tpehak managed to piss off a discord group with me, hackey from 3shul, marcos from luna, Benjamin vedder, tech from team triforce... Loads of people who actively contribute to the VESC or design commercial hardware... With completely bizarre behaviour, repeatedly refusing help with improvements and refusing to share original innotrace firmware he had attained from some mysterious source.

Deleted user is tpehak in the screenshots below. Make your own mind up if I'm mad. You can of course go and find the discord server and see the whole unredacted conversation if anyone is that excited... It doesn't vary much from the examples given.
It is good to see you are here and I hope you calmed down. I am currently focused on VESC for Bafang M600 controller so I am not able to contribute to your work with VESC for Bafang m620 controller firmware at the moment. But it looks like there are people who would like to try to build this controller and to try the VESC firmware for this controller so feel free to create a dedicated tread here about the VESC firmware for VESC for Bafang m620 controller (also known as Innotrace controller) and post the instructions about how to make it works.

I have no idea why Benjamin Vedder is pissed off, he literally makes money on donations from the VESC firmware and my work sertanly contributed to his welth. I am all about people donating him money for his work and I am sure people will gladly do this if he will make a little effort and post the instructions how to make his firmware works on this controller. Even I will gladly donate him for his work.
 
Last edited:
@TPEHAK : Personally, I don't understand why, if you are doing all this publication of reverse engineering, you would not simply publish the requested binary.

Seems a bit petty. :(
That is OK. We need to finish the VESC firmware so we do not need anything else. In regard of what the VESC team thinks about it I would think about it as a motivation factor or a challenge for the VESC team if they can bring something better than the Innotrace firmware. And I can judge them - currently the VESC firmware for the Innotrace controller is not even working (or at least I can not make it works). We need to make it simple to install in the first place - just flash the firmware with ST-Link and start working straight out of the box without dealing with all those configurations and lisp codes. Ideally also it should be able to trigger the rotary encoder calibration procedure just simply pressing some buttons combination on the display without connecting the controller to PC.
 
Last edited:
The mad Mxlemming is also here unfortunately.

I have no idea wtf the motivation for this reverse engineering is, but tpehak managed to piss off a discord group with me, hackey from 3shul, marcos from luna, Benjamin vedder, tech from team triforce... Loads of people who actively contribute to the VESC or design commercial hardware... With completely bizarre behaviour, repeatedly refusing help with improvements and refusing to share original innotrace firmware he had attained from some mysterious source.

Deleted user is tpehak in the screenshots below. Make your own mind up if I'm mad. You can of course go and find the discord server and see the whole unredacted conversation if anyone is that excited... It doesn't vary much from the examples given.
How do I find the server on Discord? Do I need a link?
 
For anyone reading this looking into the innotrace saga

By the grace of Benjamin Vedder, there is the open source firmware for the innotrace x1. Installing it won't be easy, you'll need to access the SWD and it might involve wiring and breaking seals and configuring with the included lisp script, with risk of bricking things, but it's there. I've tested it personally, it works with enough enthusiasm and effort.

Now...

Regarding this saga of "reverse engineering"... There is absolutely no way in hell anyone with the capability of the purported level of engineering is unable to get the firmware working. It's just inconceivable.

This leads to the logical conclusion, with the bizarre behaviour and mysterious firmware supply that the efforts are a ruse to dampen and delay anyone's frustration with being screwed out of a working bike.

This Luna reverse engineering appears to be nothing more than spite at a competitor... Luna have AFAIK honoured GPL requirements (hardware is not covered by GPL and the creator of the luna board is plenty capable of making his own VESC compatible design) and have their firmware pushed to the main VESC repo

So... If you're an unfortunate x1 customer with a bricked/locked out bike, your primary options seem to be significant personal effort and risk flashing open VESC firmware from the repo linked above or to persue legal action to get the situation sorted.
 
Back
Top