One little box, everything a network needs.
SpookyWrt is a custom OpenWrt firmware + toolkit for the Seeed LinkStar H68K (a $99 Rockchip RK3568 mini-router). It turns the box into a router, Wi-Fi access point, NAS, VPN gateway, and security lab — on a modern mainline kernel, so the hardware the vendor OS can't drive (Wi-Fi, 2.5 GbE) actually works. This page is the honest map of what it does.
Four things live here
The full capability matrix
Honest by design. works = confirmed on real hardware · caveat = works with a condition · USB = needs a USB adapter · opt-in = a build variant you choose.
| Router — DHCP, NAT, firewall | works | full OpenWrt gateway; eth0=WAN by default |
| 4 wired ports — 2× 2.5 GbE + 2× 1 GbE | works | RTL8125B (2.5G) + RTL8211F (1G) — all up on the mainline kernel |
| Dumb AP / bridge mode | works | extend an existing network |
| Multi-WAN failover / balance | works | mwan3 across the 4 ports |
| QoS / anti-bufferbloat, band steering, DDNS, DoH | works | SQM, DAWN, ddns-scripts, https-dns-proxy |
| 2.4 / 5 GHz AP — internal MT7921 | works | WPA2/WPA3; dead on the vendor OS, alive here on kernel 6.x |
| 6 GHz (Wi-Fi 6E/7) AP | USB caveat | needs an MT7925 USB adapter + iw reg set CA (US regdb blocks 6 GHz AP) |
| Guest network (isolated VLAN) | works | separate SSID, firewalled from LAN |
| Monitor mode + packet injection | opt-in | wifi-audit variant; consent-gated, authorized use only |
| Samba (SMB) file shares | works | share a USB drive to your whole network |
| USB 3.0 storage — ext4 / exFAT / NTFS / vFAT | works | auto-mount; also where packet captures land |
| WireGuard — commercial (NordLynx/Mullvad/Proton) + your own | works | in flagship; one-command via spooky vpn |
| Tailscale — zero-config mesh | works | reach the box + LAN from anywhere, no port-forwarding |
| Split-tunnel — route some devices via VPN | works | policy-based routing (pbr) |
| OpenVPN + ZeroTier | works | in Pro "Poltergeist" & up (WireGuard + Tailscale are in every edition) |
| AdGuard DNS ad-block · banIP threat blocking | works | network-wide, in flagship |
| Honeypot mode — decoy ports + auto-ban | works | deception + capture; your network only |
| Packet capture → Wireshark | works | spooky-capture → USB or RAM ring, or live-to-Mac |
| Wi-Fi audit toolkit (aircrack, hcxdumptool…) | opt-in | wifi-audit variant, fail-closed consent gate — authorized use only |
spooky — control shell (SSH/console) | works | status · network · Wi-Fi · diagnostics · services · capture · VPN in one command |
| Web dashboard — live status & controls | works | ubus-powered gauges, quick toggles, clients |
| First-time setup over Wi-Fi (no cable) | works | join SpookyWrt-Setup → browse to 192.168.1.1 |
| LuCI (the full OpenWrt web UI) | works | material theme; everything advanced lives here |
Three images, one recipe
🚀 flagship default
- Router + Wi-Fi + NAS + WireGuard/Tailscale + AdGuard + capture
- The everyday image — everything most people want, on by default only where it's safe
🕵️ wifi-audit opt-in
- Adds monitor/injection drivers + audit tools + 6 GHz supplicant
- Consent-gated, tools off
$PATHuntil you attest authorization
🔐 vpn opt-in
- Adds OpenVPN + ZeroTier on top of the flagship's WireGuard/Tailscale
- For heavier / multi-provider VPN setups
🧩 Or any OpenWrt target
- The same toolkit runs on other RK3568 boards, x86, and more
- Build any of them from Control
Why not just use the box as it shipped?
The vendor sells the H68K with Ubuntu/Android on a 2019-era 4.19 kernel. On that kernel the Wi-Fi doesn't work at all (no MT7921 driver) and the 2.5 GbE ports are flaky — the hardware you paid for is half-asleep. SpookyWrt runs real OpenWrt on a mainline 6.x kernel, which is why Wi-Fi and 2.5 G come alive. The tradeoff: 6 GHz needs a USB adapter (the internal radio is Wi-Fi 6, 2.4/5 GHz only), and it's a router OS — for a desktop, the Ubuntu/Armbian tracks are documented too.