Midterms 2026See who we think should earn your vote, based on our standardsThe guide →
WRITTEN IN PLAIN AMERICAN ENGLISH.
CLAY TRIBUNE.
Advertisement

Hijacking the PS5’s RTMP stream: How one hacker redirected the console’s broadcast to his Mac

A hacker hijacks the PS5's RTMP stream, redirecting it to his Mac to stream to Discord without a costly capture card.

By mitch·5 min read
A PS5 console connected to a Mac laptop with wires, suggesting a hacked streaming setup.

Sony has locked down the PS5’s hardware, and one hacker found a way around it. He redirected the console’s RTMP stream to his Mac, so he could stream to Discord without buying a capture card. The trick works by tricking the PS5 into thinking his Mac is Twitch.

The Problem With Streaming

The PS5 has a Broadcast button that lets you stream to YouTube and Twitch. It’s convenient, but it’s limited. If you want to stream to Discord or OBS, you’re out of luck. The obvious fix is a capture card, which plugs the HDMI output into your computer and feeds it into OBS.

Streaming games with friends can run well over $100, which is a steep price for a capture card alone. To avoid paying that much, the hacker hunted for a more affordable path.

Advertisement

Remote Play Failed

Remote Play is another route. You connect the PS5 to your MacBook, share the Mac’s screen to Discord, and play from there. The problem is that you need to connect everything to the Remote Play device: controller, earphones, and so on. There’s also input lag, and the stream quality is entirely controlled by the PS5. You can’t configure anything.

What the hacker wanted was a way to avoid altering his physical setup whenever he streamed.

How RTMP Works

RTMP, which stands for Real-Time Messaging Protocol, is what lets the PS5 stream to YouTube and Twitch. It’s a standard used for sending live audio and video. Before any content reaches its destination, the PS5 first resolves the address through DNS when a broadcast begins.

Here’s the rough sequence:

  1. The PS5 resolves the hostname for the destination service.
  2. It makes an HTTPS call asking which regional server to use.
  3. The server responds with an address like ap-southeast-1.prod.fi.contribute.live-video.net.
  4. The PS5 pushes the actual stream there.

The key insight is that the PS5 doesn’t hardcode Twitch’s IP. It looks it up every time.

Spoofing DNS

The hacker’s plan was simple: control what DNS returns. If he could redirect Twitch’s hostname to his Mac’s IP, the PS5 would send the stream there instead.

Spoofing ingest.twitch.tv failed entirely. It functions as a discovery endpoint, not an RTMP server in its own right. What actually happens is that the PS5 queries it for the correct server address, after which the console sends the stream to that destination.

As a temporary fix, he attempted YouTube. Its RTMP intake relies on ordinary RTMP on port 1935, without any TLS certificate involved. This time, the PS5 managed to send the stream to his Mac. However, YouTube periodically verifies whether the stream is truly active. Because YouTube never got the stream, that verification failed, causing broadcasting to cease after roughly 60 seconds.

The Real Endpoint

While broadcasting, the answer arrived from studying DNS logs. The PS5 resolved ingest.global-contribute.live-video.net, which led down to aps30.contribute.live-video.net. That last address is the actual RTMP server.

The spoof targeting contribute.live-video.net captures every subdomain, routing the genuine stream to the Mac while sidestepping any certificate problems.

The Setup

A small macOS menu bar app was put together by the hacker, bundling dnsmasq and nginx-rtmp. The hacker runs dnsmasq on his Mac and sets it up to resolve the LAN address of Twitch’s ingest domains to his Mac’.

plaintext
server=1.1.1.1
server=8.8.8.8
address=/contribute.live-video.net/192.168.8.175
address=/ingest.global-contribute.live-video.net/192.168.8.175
address=/live.twitch.tv/192.168.8.175
...
log-queries
log-facility=/tmp/dnsmasq.log
no-hosts
listen-address=0.0.0.0

IP redirection is what these address lines do for Twitch’s ingest domains to his Mac’, directing its traffic through 192.168.8.175.

Next he aimed the PS5 at the DNS server. With a GL.iNet router running OpenWRT, he set it up to give his Mac’s IP as the DNS server specifically for the PS5′ a DHCP lease.

plaintext
uci add_list dhcp.lan.dhcp_option="tag:PS5,6,192.168.8.175"
uci commit dhcp
/etc/init.d/dnsmasq restart

The tag:PS5 feature operates due to the PS5’s static lease carrying that tag in /etc/config/dhcp. When the PS5 requests a new lease, it receives Option 6, the DHCP setting for DNS server, automatically. No console setup is needed on the PS5 side.

Receiving the Stream

The receiving end uses nginx-rtmp:

The configuration specifies an RTMP server listening at port 1935, with a chunk size set to 4096. Inside it, an application named ps5 runs live streams without recording, keeping a sync delay of 10 milliseconds. When a stream is published, the server makes an HTTP request to http://127.0.0.1:9988/on_publish.

When the PS5 begins broadcasting, the on_publish callback informs the menu bar app of the event. The app then displays the complete RTMP URL for copying, after Nginx sends a POST request to localhost:9988 carrying the stream name.

What We Learned

What makes the trick work is that it targets the system’s weakest part. Capture cards cost a fortune. Remote Play is a pain to set up. But DNS records are just plain text. Alter that text, and the PS5 gets confused.

The hacker’s method shows that sometimes the lock isn’t as strong as it seems.

Key facts:
– Capture cards can run well over $100
– YouTube stream check fails after roughly 60 seconds
– RTMP output is 1080p60, H.264 video, AAC stereo audio
– Sync delay kept at 10 milliseconds

Comparison Table

Feature Capture Card PS5 Hack
Cost Upwards of $100 Free
Setup Plug HDMI into OBS Configure DNS and nginx
Complexity Simple Requires router configuration
Quality Full PC encoding PS5 stream routed through the hack

The technique demonstrates that the PS5’s RTMP setup can be rerouted, with the researcher cautioning that the success of this approach hinges on how the PS5 handles DNS requests. When a company secures its devices by managing where a request lands, the usual solution is to point that request toward a different destination.

Readers who enjoy ingenious tricks will find this a pleasing form of experimentation. The PS5’s hardware is secured against such changes, yet the DNS remains open for manipulation.

See the video the story is built around at yashgarg.dev.

The Notebook

Get the Notebook.

The day's best stories and every fresh verdict, in plain English, in your inbox by seven. One email a day, no more.

We send one note to confirm. Every issue has a one-click way out.

Advertisement

Leave a Reply

Your email address will not be published. Required fields are marked *

As an Amazon Associate, Clay Tribune earns from qualifying purchases.