Skip to content

Feature Request: Add official support for C2000 Gen 2 and its Expansion Battery (BP2000) #51

Description

@R-a-K-i

Device Details

  • Main Station: Anker SOLIX C2000 Gen 2
  • Expansion Battery: Anker SOLIX BP2000 (2kWh)

Description

Hello! First of all, thank you for this amazing integration.

I am currently using the new Anker SOLIX C2000 Gen 2 with a BP2000 expansion battery. In the integration setup, I selected the "C1000 Gen 2" profile. The main unit works partially with this profile (telemetry like base power and AC/DC toggles are working fine).

However, since the real C1000 Gen 2 hardware does not support expansion batteries, the connected BP2000 battery is currently not detected at all, and no entities are created for it.

I have attached my decrypted debug log from the connection session with the C1000 Gen 2 profile. Hopefully, the raw data provides the necessary structures to implement proper support for the C2000 Gen 2 and its expansion loop.

Thanks a lot for your help!

Debug Log (C1000 Gen 2 Profile)

2026-09-17 07:21:44.401 DEBUG (MainThread) [SolixBLE.device] Decrypted payload: a10131a221062011415043444b4b463047313534303030373100054131373833010102010101a30e0400000101fc080064cc00580200a41b040000000008073200000000000000001e00020000000001640a00a506042100640000a60a044200000000004b0164a70704014200000000a80404000000aa0404000000ab0404000000ac0404000000ae0404000000b20404000000c02c0411415043444l34453047313136303032313101020209011e011d0001010001000a41313738335f326b5768ce2c0410000000000000000000000000000000000111000000000000000000000000000000000000000000000000d91a0400000f640a00000000664a986a6858986a0000000000000000da18048000000000000000000001e00138047f00000038046405dc06040000000000f91d0401010201070005000000000007000500020209010202090106000300fa150401010101001f0700000000000000000000000000fd0100fe0503faba0000
2026-09-17 07:21:44.401 DEBUG (MainThread) [SolixBLE.device] Telemetry parameters: {'a1': '31', 'a2': '062011415043444b4b463047313534303030373100054131373833010102010101', 'a3': '0400000101fc080064cc00580200', 'a4': '040000000008073200000000000000001e00020000000001640a00', 'a5': '042100640000', 'a6': '044200000000004b0164', 'a7': '04014200000000', 'a8': '04000000', 'aa': '04000000', 'ab': '04000000', 'ac': '04000000', 'ae': '04000000', 'b2': '04000000', 'c0': '0411415043444l34453047313136303032313101020209011e011d0001010001000a41313738335f326b5768', 'ce': '0410000000000000000000000000000000000111000000000000000000000000000000000000000000000000', 'd9': '0400000f640a00000000664a986a6858986a0000000000000000', 'da': '048000000000000000000001e00138047f00000038046405', 'dc': '040000000000', 'f9': '0401010201070005000000000007000500020209010202090106000300', 'fa': '0401010101001f0700000000000000000000000000', 'fd': '00', 'fe': '03faba0000'}
2026-09-17 07:21:44.401 DEBUG (MainThread) [SolixBLE.device] C1000G2(
    AC_OUTPUT: PortStatus.OUTPUT,
    AC_POWER_IN: 0,
    AC_POWER_OUT: 66,
    ADDRESS: 00:7F:1D:0C:C8:54,
    AVAILABLE: True,
    BATTERY_HEALTH: 0,
    BATTERY_PERCENTAGE: 100,
    CONNECTED: True,
    DC_OUTPUT: PortStatus.NOT_CONNECTED,
    DC_POWER_OUT: 0,
    LAST_UPDATE: 2026-09-17 07:21:44.401578,
    MAX_BATTERY_PERCENTAGE: 100,
    MIN_BATTERY_PERCENTAGE: 10,
    NAME: SOLIX C2000 Gen 2,
    NEGOTIATED: True,
    PART_NUMBER: A1783,
    POWER_OUT: 66,
    SERIAL_NUMBER: APCDKKF0G15400071,
    SOLAR_PORT: PortStatus.NOT_CONNECTED,
    SOLAR_POWER_IN: 0,
    TEMPERATURE: 33,
    USB_A1_POWER: 0,
    USB_C1_POWER: 0,
    USB_C2_POWER: 0,
    USB_C3_POWER: 0,
    USB_PORT_A1: PortStatus.NOT_CONNECTED,
    USB_PORT_C1: PortStatus.NOT_CONNECTED,
    USB_PORT_C2: PortStatus.NOT_CONNECTED,
    USB_PORT_C3: PortStatus.NOT_CONNECTED,
)

C1000 Gen 2 Profile.log

Unkown Profile.log

ADDITIONAL UPDATE / ASSUMPTION REGARDING EXPANSION BATTERY

While reviewing the decrypted debug logs, I found a string that likely
represents the connected expansion battery pack.

  • Expansion Battery Serial: APCDL4E0G11600211
  • Log Location: Parameter "c0" inside the decrypted telemetry payload

The hex-encoded value is:
415043444c344530473131363030323131

In the raw decrypted bytes, this serial number is explicitly listed right
next to the expansion battery identifier:
b'\x04\x11APCDL4E0G11600211...A1783_2kWh'

Activity

jusubbi commented on Sep 19, 2026

@jusubbi

Hi, similar setup to #51 (C2000 Gen 2), but I'm hitting a different, more fundamental issue: my unit's battery ran too low, and now the BMS appears to be in some kind of lockout state — the display shows 0% even though I've verified the individual cells are healthy and balanced (measured externally with a multimeter after charging them separately).

When I try to connect via BLE (both Generic and C1000G2 classes, latest SolixBLE version), the device:

Accepts the connection and GATT service discovery fine
Accepts the notify subscription on 8c850003 fine
But disconnects immediately (BleakError / native BlueZ pairing also fails with AuthenticationCanceled) the instant it receives the stage-0 negotiation write on 8c850002 — it never even sends back an 0801 stage-1 response

This happens 100% consistently across many attempts, with both a stale and a freshly-patched timestamp in NEGOTIATION_COMMAND_0.

I also attempted the OTA firmware update via a modified official app (to bypass the "battery too low to update" check) — the update UI reported "sub-battery updated OK" (nothing connected) but "main unit update failed" at 84%.

Has anyone else encountered this specific BMS-lockout-refuses-all-BLE-sessions behavior? Is there a known recovery procedure (official or otherwise), or a UART command sequence via the internal mainboard↔BMS serial link (RX/TX pins on the BMS connector, 38400 7N1) that's known to clear this kind of fault/lockout state? I can share raw captures. If anyone with a healthy C2000 Gen 2 could do the same tap and share their capture, a byte-level diff would very likely reveal the lockout flag directly

Happy to share full BLE/UART capture logs if useful.

flip-dots commented on Sep 20, 2026

@flip-dots
Owner

@R-a-K-i C2000G2 support is being worked on under #51, I assume your unit is using an older firmware? Newer firmwares of the G2 class of devices are currently not working due to changes to the authentication mechanism which has been holding up adding support for the C2000G2, progress is being made on it but its slow going.

flip-dots commented on Sep 20, 2026

@flip-dots
Owner

@jusubbi you might want to ask @kb1ibt, he seems to have figured out how to decompile the firmware and there might be some answers in there. I don't have a C1000G2 or C2000G2 so I am not able to do much when it comes to those devices.

jusubbi commented on Sep 20, 2026

@jusubbi

@flip-dots Thanks! I will contact him.

kb1ibt commented on Sep 20, 2026

@kb1ibt

I have a C2000G2 with BP2000, SolixBLE#50 has support for the expansion battery. But those PR numbers are going to be old, since I am switching the PRs to be easier for @flip-dots to handle/parse.

kb1ibt commented on Sep 20, 2026

@kb1ibt

But disconnects immediately (BleakError / native BlueZ pairing also fails with AuthenticationCanceled) the instant it receives the stage-0 negotiation write on 8c850002 — it never even sends back an 0801 stage-1 response

This is the absolute most recent firmware; it now blocks the unencrypted negotiation. That's why, in my most recent PRs, I am specifically checking the advertisement capability flag for those that provide it, so SolixBLE knows which type of authentication process to use. PR#70

R-a-K-i commented on Sep 20, 2026

@R-a-K-i
Author

@flip-dots

Thank you for the update!

I'm located in Europe and running the latest firmware versions available here:

  • SOLIX C2000 Gen 2: v1.2.1.1
  • Expansion Battery: v1.9.2.2

The SOLIX C2000 Gen 2 actually works and communicates perfectly fine using the C1000 G2 profile. However, the integration does not recognize or display the expansion battery itself.

It seems the core communication works with this firmware version, but the parameters/entities for the expansion battery are missing.

kb1ibt commented on Sep 20, 2026

@kb1ibt

@R-a-K-i --

I'm located in Europe and running the latest firmware versions available here:

  • SOLIX C2000 Gen 2: v1.2.1.1
  • Expansion Battery: v1.9.2.2

The SOLIX C2000 Gen 2 actually works and communicates perfectly fine using the C1000 G2 profile. However, the integration does not recognize or display the expansion battery itself.

It seems the core communication works with this firmware version, but the parameters/entities for the expansion battery are missing.

what you are looking for is the C2000G2 code in PR#72 which is waiting for @flip-dots to accept 70 and 71 as well

kb1ibt commented on Sep 23, 2026

@kb1ibt

@jusubbi
take a look at https://www.ti.com/lit/an/sluaa81a/sluaa81a.pdf and https://www.ti.com/lit/an/sluaaq5/sluaaq5.pdf since the battery controllers are TI BQ76952

The MainMCU talks to the BQ over I2C1, not UART, but what you are looking to do is something like:

BQ769x2, 7-bit address 0x08 (write 0x10, read 0x11), I2C-with-CRC, poly 0x07
Send a subcommand: write the 16-bit value little-endian to register 0x3E/0x3F
EXIT_DEEPSLEEP 0x000E (firmware sends this once, then SLEEP_DISABLE,
and checks Control Status bit 2)
SLEEP_DISABLE 0x009A
FET_ENABLE 0x0022 (toggle: only acts when Manufacturing Status FET_EN is clear)
ALL_FETS_ON 0x0096
FET_CONTROL 0x0097 + data byte

I have not tested this myself, since I have not actually removed any feet or screws on my device, only been disassembling the firmware.

jusubbi commented on Sep 24, 2026

@jusubbi

@kb1ibt

Thanks! I will look it.

jusubbi commented on Sep 24, 2026

@jusubbi

@kb1ibt

I managed to download firmware from bms board (GD32F303). Here is the link: https://limewire.com/d/II6ul#KA0cmkX0Tc

kb1ibt commented on Sep 25, 2026

@kb1ibt

@jusubbi, thank you. That provides a couple of things I didn't have, specifically the region below 0x08008000 that isn't included in the OTA files.

jusubbi commented on Sep 26, 2026

@jusubbi

@kb1ibt

Sorry I spam this thread, but I don't know how else I contact you.

I'm still in same situation. OTA update will hangs at 84% after while it goes to 100% and says that, expansion battery updated (I don't even have that) and main failed. I managed to get power from main battery to mainboard by flashing modified firmware to bms:

cat << 'EOF' > patch.py
def patch_firmware(filename):
with open(filename, "rb") as f:
data = bytearray(f.read())

offset = 0x2a0b4
print(f"Ennen patchausta osoitteessa 0x{offset:X}: {data[offset:offset+4].hex()}")

patch_bytes = b'\x00\x20\x70\x47'
for i, b in enumerate(patch_bytes):
    data[offset + i] = b
    
print(f"Jälkeen patchauksen osoitteessa 0x{offset:X}: {data[offset:offset+4].hex()}")

patched_filename = filename.replace(".bin", "_patched.bin")
with open(patched_filename, "wb") as f:
    f.write(data)
print(f"Tallennettu patchattu tiedosto nimellä: {patched_filename}")

patch_firmware("firmware.bin")
EOF

python3 patch.py

this will skip some check. it still needs me to start st-util once, then I can close it and power stays. Display still shows 0% and temp shows now -17C. I don't have any I2C usb capable device, so all I do must go througt st-link. I can still do someting in gdb. Also powerbutton can shutdown unit, but not power on. After while bluetooh connection starts to work even device is "off". reset button power on device again. If I want to really shutdown unit, I need first run gdb-multiarch -q firmware_original.elf and then target extended-remote localhost:4242. That drains voltage from mainboard. If I quit from gdb voltage returns to mainboard. Now I flashed back original firmware, so it's stays off.

kb1ibt commented on Sep 26, 2026

@kb1ibt

@jusubbi

Sorry I spam this thread, but I don't know how else I contact you.

Fire an email over to me, use jusubbi@kb1ibt.com (I own the whole domain, so it'll just land in a folder filtered for you).

jusubbi commented on Sep 26, 2026

@jusubbi

@kb1ibt Thanks! I will mail now and stop spam this thread.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions