How would one go about reverse-engineering Bluetooth LE? Is it looking at packets through WireShark?
https://www.adafruit.com/product/2267 ($20)
Overview on using it as a sniffer: https://learn.adafruit.com/introducing-adafruit-ble-bluetoot...
Still a lot of work though, if it's anything like LED signs I've reverse engineered. Trying to figure out if it's length encoded payloads or delimited payloads, what obscure checksums it might use, weird encoding of images, etc. And experimenting often hangs the device, or changes it's behavior significantly.
https://www.mybluetoothreviews.com/what-is-bluetooth-hci-sno... shows how to capture the packets (you just go to the developer settings to turn it on)