Today, credit card terminals are undergoing a drastic evolution, moving from specialized hardware and custom-built operating systems to Android devices similar to ordinary smartphones. While this change results in smarter and more capable devices, it also dramatically extends their attack surface. Nonetheless, little to no research has been published exploring these new “Smart POS” devices, showing their peculiarities and highlighting what weaknesses they might conceal. In this talk, we will go through our exploration and reverse engineering of one of the most popular “Smart POS” credit card terminals currently in use worldwide. We will delve into the details of the research process that led us to the discovery of multiple software vulnerabilities, ultimately granting us persistent root access to the device's operating system. The first vulnerability allowed us to open a shell and run arbitrary commands on the device. Then, flaws in other system components paved the way to a root privilege escalation. Finally, we managed to make root access persist across reboots, all without unlocking the bootloader and triggering the anti-tamper mechanisms that would erase the secret keys from the built-in hardware security module. We will also demonstrate how an attacker could exploit these vulnerabilities to weaponize a payment terminal and steal credit card information from unsuspecting customers. We will suggest some future research projects to discover the remaining aspects that our research did not cover. Lastly, we will discuss how we responsibly disclosed the vulnerabilities to the manufacturer.