Some time ago I bought an unbranded Tuya 2 gang switch from aliexpress and recently got around to playing with it.
It's a T34 (BK7231N ) based device with RF capabilities, the PCB has 3 touch/proximity sensors but only 2 are populated (the middle one might still be readable with a custom firmware?)
I am yet to flash OBkn to it but I got a firmware backup from it.
The flashing pads on the back were easy to reach no soldering/desoldering needed.

Seems to be an upgraded version of -Link
Also seen here -Link
My current issue is that it could not auto fetch the json from 0x1D1000 (all are 0xff values ), but looking at the firmware file the config might be at 0x1D4000



AI: What tool or method did you use to try and auto-fetch the JSON from 0x1D1000?
The BK7231GUIFlashTool from the github.
AI: Have you already tried extracting or reading the config from 0x1D4000, and if so, what were the results?
I am not familiar with the exact format the json should be in just by reading the HEX from the firmware.
Eddit: corrected link.
It's a T34 (BK7231N ) based device with RF capabilities, the PCB has 3 touch/proximity sensors but only 2 are populated (the middle one might still be readable with a custom firmware?)
I am yet to flash OBkn to it but I got a firmware backup from it.
The flashing pads on the back were easy to reach no soldering/desoldering needed.


Seems to be an upgraded version of -Link
Also seen here -Link
My current issue is that it could not auto fetch the json from 0x1D1000 (all are 0xff values ), but looking at the firmware file the config might be at 0x1D4000




AI: What tool or method did you use to try and auto-fetch the JSON from 0x1D1000?
The BK7231GUIFlashTool from the github.
AI: Have you already tried extracting or reading the config from 0x1D4000, and if so, what were the results?
I am not familiar with the exact format the json should be in just by reading the HEX from the firmware.
Eddit: corrected link.