When people come to us
Almost every enquiry starts the same way. A machine on the floor has failed, the board that runs it is out of production, and the company that wrote the firmware is either gone or no longer interested. The board is repairable, but the microcontroller on it is read-protected, so nobody can copy the program onto a replacement part.
That is the job. We take the physical chip, get the program out of it, and hand it back to you in a form your own programmer can write to new parts.
How a chip is opened
There is no single method. Which one applies depends on the die, the process node and how the security bits were implemented.
- Software attackProtocol and bootloader flaws
- Fault injectionClock and voltage glitching
- Side channelPower and timing analysis
- InvasiveDecapsulation and microprobing
Non-invasive routes are tried first because they leave your sample usable. Invasive work destroys the sample chip, which is why we ask for two where possible and always say in advance which route a part is likely to need.
Families we handle
The published families below are the ones asked for most often. The full database runs to 5000+ models.
What you receive
- Bin fileRaw memory image
- Hex fileReady for any programmer
- 2 programmed chipsBlank parts written with your program
- Read-out reportMethod used, memory map, fuse settings
Not sure whether your part can be read?
Send the marking. The check costs nothing and takes less than a working day.
Check my chipWhat we do not do
We turn down work aimed at counterfeiting a product still on sale, at defeating licensing on equipment you do not own, or at anything where the requester cannot show ownership or written authorisation. That policy costs us orders every month and it stays.
