What Is Firmware Extraction and When Do You Need It?
Firmware extraction is the process of reading the binary contents — program code and configuration data — out of a microcontroller’s on-chip flash or EEPROM memory. It is used for authorized purposes such as recovering lost source code from legacy products, duplicating firmware onto replacement chips during repair, verifying production programming integrity, or migrating designs to a new MCU platform when the original toolchain is no longer available.
Our engineers perform firmware extraction across more than 4,000 MCU part numbers spanning ARM Cortex-M, 8051, PIC, AVR, MSP430, Renesas RX/RL78, and proprietary architectures. Whether the chip’s read-protection fuse is set or the debug port has been disabled, we evaluate each device individually and report a realistic feasibility assessment before any work begins.
How Does Firmware Extraction Work?

The method depends entirely on the target chip’s architecture and the level of protection the original developer enabled. Below is a simplified breakdown of the three main approaches our lab uses.
1. Standard Debug-Port Readout
When read-protection is not enabled — or has been left at the factory default — firmware can be extracted non-invasively through JTAG, SWD, ICSP, UART bootloader, or a vendor-specific debug interface. This is the fastest and lowest-cost path, typically completed within 1–2 working days. For a deeper look at this approach, see our firmware readout service overview.
2. Glitching and Side-Channel Techniques
Many MCUs — particularly STM32F1/F4 series, certain PIC18F parts, and older 8051 variants — can be bypassed using voltage-glitch or clock-glitch attacks that momentarily disrupt the read-protection check during boot. Our lab uses precision pulse generators with sub-nanosecond timing resolution. Success rates vary by silicon revision; some STM32F1xx revisions yield in under 100 attempts, while newer revisions may require thousands of iterations or prove infeasible altogether.
3. Invasive / Semi-Invasive Methods
For chips with robust protection — hardware-encrypted flash, secure boot chains, or fuse-blown debug ports — we may decap the die and use UV exposure, micro-probing, or focused-ion-beam (FIB) editing. These methods are more expensive ($800–$3,000+) and carry a small risk of die damage, which we disclose upfront. Not every chip is a candidate; we will tell you if the protection exceeds what current techniques can address.
Supported Chip Families for Firmware Extraction
| Vendor / Family | Common Targets | Typical Protection Level | Estimated Success |
|---|---|---|---|
| ST STM32F0 / F1 | STM32F030, STM32F051, STM32F103 | RDP Level 1 | High |
| ST STM32F4 | STM32F405, STM32F407 | RDP Level 1–2 | Medium–High |
| ST STM32G4 / H7 | STM32G431, STM32H743 | RDP Level 2 / TrustZone | Case-by-case |
| ST STM32L | STM32L151, STM32L432 | RDP Level 1–2 | Medium–High |
| ST STM8 | STM8S003, STM8S105, STM8L051 | ROP | High |
| Microchip PIC16F | PIC16F877A, PIC16F1509 | CP bit | High |
| Microchip PIC18F | PIC18F452, PIC18F4550, PIC18F4520 | CP / CPB bits | High |
| Atmel / Microchip AVR | ATmega328P, ATmega2560 | Lock bits | High |
| TI MSP430 | MSP430F149, MSP430G2553 | JTAG fuse | Medium |
| NXP LPC / Kinetis | LPC1768, MK20DX256 | CRP1–CRP3 | Medium (CRP3 = low) |
| GigaDevice GD32 | GD32F103, GD32F303 | SWD lock | High |
| Renesas RL78 / RX | RL78/G13, RX631 | ID code / OCD lock | Medium |
The table above is a snapshot. If your chip isn’t listed, submit it for a free feasibility check — we maintain an internal database of over 4,000 tested part numbers with silicon-revision-specific notes.
STM32 Family — Our Most Requested Targets
STM32 parts account for roughly 40 % of our firmware extraction requests. The protection mechanism — ST’s Read-Out Protection (RDP) — comes in three levels. Level 0 is unprotected. Level 1 blocks debug reads but can often be bypassed via glitch attacks. Level 2 permanently disables the debug interface and requires invasive techniques; success is silicon-revision-dependent. Explore specific feasibility details for parts like the STM32F103, STM32F407, or STM32H743.
PIC Microcontrollers
Microchip’s PIC16F and PIC18F families use code-protection (CP) configuration bits. Older PIC16F parts such as the PIC16F877A are well-understood targets with high extraction success. PIC18F devices like the PIC18F4550 add boot-block protection (CPB) and write-protection (WRT), but established techniques still achieve reliable results in most cases.
What Does Firmware Extraction Cost?
| Scenario | Price Range (USD) | Turnaround |
|---|---|---|
| Unprotected chip, standard debug readout | $150 – $300 | 1–3 working days |
| Level-1 / single-fuse protection, glitch attack | $300 – $800 | 3–7 working days |
| High-security protection, invasive/semi-invasive | $800 – $3,000+ | 7–20 working days |
| Feasibility assessment only | Free | 1–2 working days |
Pricing depends on the chip family, protection level, silicon revision, and whether we already have a proven attack path in our database. Repeat orders for the same part number are typically discounted 20–30 % because the engineering effort has already been invested.
Deliverables You Receive

- Binary file (.bin / .hex / .s19) — exact image of the flash and EEPROM contents, ready to program onto a blank chip.
- Fuse / option-byte map — the configuration register state needed to reproduce the chip’s clock, brownout, and watchdog settings.
- Verification report — CRC/SHA-256 checksum, extraction method used, and any caveats (e.g., encrypted segments that remain opaque).
- Optional disassembly listing — annotated assembly output for code review or porting, available at additional cost.
What Can Go Wrong — Honest Limitations
We are transparent about failure modes because they directly affect your project timeline and budget:
- RDP Level 2 / CRP3 / permanent lock: Some protection schemes are designed to be irreversible. Invasive methods may still work, but success is never guaranteed, and the chip is consumed in the attempt.
- Encrypted firmware: Extraction recovers the ciphertext. Without the decryption key (stored in OTP or a secure element), the binary may be unusable for porting — though it can still be cloned onto an identical chip.
- Die damage: Decapping and micro-probing carry a 5–10 % risk of destroying the die. We mitigate this by requesting 2–3 sample chips when invasive work is needed.
- Silicon revisions: Two chips with the same part number but different revision letters can have different vulnerability profiles. We identify the revision before quoting.
Authorization and Legal Requirements
Firmware extraction is performed exclusively for authorized purposes. Before we begin, clients provide proof of ownership or a signed authorization letter confirming they have the legal right to access the firmware — for example, recovering their own production code, maintaining legacy equipment they own, or performing security audits under contract. We operate under NDA by default and can execute client-supplied confidentiality agreements. For full details on our compliance framework, visit our trust and legal overview.
Our Process — From Inquiry to Delivery
- Submit your chip details — part number, package, quantity available, and the reason for extraction.
- Free feasibility report — we check our database, identify the protection scheme, and return a success estimate within 1–2 working days.
- Quote and NDA — fixed-price quote with a “no data, no charge” policy on most glitch-based extractions.
- Ship the chips — we typically request 1 chip for non-invasive work, 2–3 for invasive methods.
- Extraction and verification — binary is read, checksummed, and optionally re-programmed onto a blank chip to confirm functional equivalence.
- Secure delivery — files delivered via encrypted transfer; chips returned or disposed of per your instruction.
[pcb_cta type=”feasibility”]
Is firmware extraction the same as firmware readout?
The terms overlap. “Firmware readout” usually implies reading an unprotected or lightly protected chip through its standard debug interface. “Firmware extraction” is the broader term that includes readout plus techniques for bypassing active code-protection mechanisms — glitching, side-channel attacks, and invasive die-level methods.
Can you extract firmware from a chip that has been BGA-reballed or desoldered?
Yes. We routinely work with desoldered chips. For BGA packages, we can re-ball and mount the device on a breakout board for extraction. The chip must be electrically functional — physical cracks in the die or bond-wire damage will prevent a successful read.
What if the firmware is encrypted — is extraction still useful?
Extraction recovers whatever is stored in flash, encrypted or not. If your goal is to clone the firmware onto an identical replacement chip, encrypted data works fine — the same chip model will decrypt it at runtime. If you need to modify or port the code, you will also need the decryption key, which may reside in OTP fuses or an external secure element.
How many chips do I need to send?
For non-invasive and glitch-based extraction, one chip is usually sufficient. For invasive methods (decapping, micro-probing), we recommend sending 2–3 units to account for the small risk of die damage during processing.
Do you offer a “no data, no charge” guarantee?
For most glitch-based and non-invasive extractions, yes — if we cannot recover valid firmware, you pay nothing beyond shipping. Invasive methods involve consumable lab costs (decapping chemicals, FIB time), so a partial fee may apply even if extraction is unsuccessful. This is disclosed in the quote.
{
“@context”: “https://schema.org”,
“@type”: “Service”,
“serviceType”: “Firmware Extraction”,
“name”: “Firmware Extraction Service”,
“description”: “Professional firmware extraction from microcontrollers including STM32, PIC, AVR, MSP430, and more. Non-invasive readout, glitch attacks, and invasive die-level recovery.”,
“provider”: {
“@type”: “Organization”,
“name”: “PCB-Copy”,
“url”: “https://pcb-copy.com”
},
“url”: “https://pcb-copy.com/firmware-extraction/”
}
{
“@context”: “https://schema.org”,
“@type”: “FAQPage”,
“mainEntity”: [
{
“@type”: “Question”,
“name”: “Is firmware extraction the same as firmware readout?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “The terms overlap. Firmware readout usually implies reading an unprotected or lightly protected chip through its standard debug interface. Firmware extraction is the broader term that includes readout plus techniques for bypassing active code-protection mechanisms — glitching, side-channel attacks, and invasive die-level methods.”
}
},
{
“@type”: “Question”,
“name”: “Can you extract firmware from a chip that has been BGA-reballed or desoldered?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “Yes. We routinely work with desoldered chips. For BGA packages, we can re-ball and mount the device on a breakout board for extraction. The chip must be electrically functional.”
}
},
{
“@type”: “Question”,
“name”: “What if the firmware is encrypted — is extraction still useful?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “Extraction recovers whatever is stored in flash, encrypted or not. If your goal is to clone the firmware onto an identical replacement chip, encrypted data works fine. If you need to modify or port the code, you will also need the decryption key.”
}
},
{
“@type”: “Question”,
“name”: “How many chips do I need to send?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “For non-invasive and glitch-based extraction, one chip is usually sufficient. For invasive methods, we recommend sending 2–3 units to account for the small risk of die damage during processing.”
}
},
{
“@type”: “Question”,
“name”: “Do you offer a no data, no charge guarantee?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “For most glitch-based and non-invasive extractions, yes. Invasive methods involve consumable lab costs, so a partial fee may apply even if extraction is unsuccessful. This is disclosed in the quote.”
}
}
]
}
{
“@context”: “https://schema.org”,
“@type”: “BreadcrumbList”,
“itemListElement”: [
{“@type”: “ListItem”, “position”: 1, “name”: “Home”, “item”: “https://pcb-copy.com/”},
{“@type”: “ListItem”, “position”: 2, “name”: “Firmware Extraction”, “item”: “https://pcb-copy.com/firmware-extraction/”}
]
}
Working on a board like this?
Send the chip marking or two photos. You get feasibility, lead time and price within 24 hours, and the check costs nothing.
Get a free quote