Supported IC List for IC Unlock — Complete Reference Guide
Our supported IC list for IC unlock spans more than 70 distinct microcontroller and memory IC families from 15+ silicon vendors. Every entry below represents a part our engineers have successfully recovered firmware from under authorized conditions — the requester owns the IP, holds a valid license, or requires legacy maintenance access. If your specific part number does not appear on this supported IC list, submit a free feasibility inquiry through our IC unlock service; we evaluate new devices weekly and add roughly 5–10 new part numbers every quarter.
How We Organize the Supported IC List for IC Unlock

ICs are grouped by vendor, then by protection mechanism. This structure matters because the unlock method, turnaround time, and cost all depend on the type and generation of read protection — not just the part number. A device with single-level RDP (Read-out Protection) is fundamentally different from one using TrustZone or hardware-fuse encryption.
For each family on the supported IC list we note:
- Protection type — software lock bits, OTP fuses, hardware encryption, or combined.
- Typical success tier — High (>90%), Moderate (60–90%), or Case-by-case (<60%, dependent on silicon revision).
- Turnaround range — working days from receipt of the physical IC or valid dump.
- Package notes — where BGA or WLCSP handling adds preparation time.
ARM Cortex-M MCUs (STMicroelectronics)
STM32 parts are the single most requested family on our supported IC list for IC unlock. STMicroelectronics implements Read-out Protection in three levels: Level 0 (unprotected), Level 1 (debug access blocked but reversible), and Level 2 (permanent OTP fuse). The distinction between Level 1 and Level 2 is critical — Level 1 recovery is well-documented and repeatable, while Level 2 requires invasive die-level techniques that are silicon-revision dependent.
| Family / Part Prefix | Core | Protection | Success Tier | Turnaround |
|---|---|---|---|---|
| STM32F0xx | Cortex-M0 | RDP Level 1 | High | 3–5 days |
| STM32F1xx | Cortex-M3 | RDP Level 1 | High | 3–5 days |
| STM32F2xx | Cortex-M3 | RDP Level 1/2 | High (L1) / Moderate (L2) | 5–10 days |
| STM32F3xx | Cortex-M4 | RDP Level 1 | High | 3–7 days |
| STM32F4xx | Cortex-M4F | RDP Level 1/2 | High (L1) / Case-by-case (L2) | 5–12 days |
| STM32F7xx | Cortex-M7 | RDP Level 1/2 | Moderate | 7–14 days |
| STM32L0xx / L1xx | Cortex-M0+/M3 | RDP Level 1 | High | 3–5 days |
| STM32G0xx / G4xx | Cortex-M0+/M4 | RDP Level 1/2 | High (L1) / Moderate (L2) | 5–10 days |
| STM32H7xx | Cortex-M7 | RDP Level 1/2 + Secure area | Case-by-case | 10–20 days |
| STM32WB55 | Cortex-M4 + M0+ | RDP + Secure area | Moderate | 7–14 days |
Important caveat: STM32 RDP Level 2 permanently disables the debug port via OTP fuses. Recovery from Level 2 requires invasive techniques that are silicon-revision dependent. We provide a candid feasibility assessment before quoting Level 2 jobs — no charge, no obligation. On STM32F4 parts specifically, certain die revisions manufactured before Q3 2019 have a higher success rate than later steppings.
NXP / Freescale Kinetis & LPC
NXP’s LPC and Kinetis lines use Code Read Protection (CRP) levels 1 through 3 and Flash Security bytes respectively. CRP1 restricts ISP commands but leaves partial access; CRP2 blocks most read paths; CRP3 disables ISP entry entirely. Our IC unlock engineers have documented repeatable success on CRP1 and CRP2 across all tested LPC revisions, while CRP3 outcomes depend on specific die characteristics.
| Family | Core | Protection | Success Tier | Turnaround |
|---|---|---|---|---|
| LPC1100 / LPC1300 | Cortex-M0/M3 | CRP Levels 1–3 | High (CRP1/2) / Case-by-case (CRP3) | 3–10 days |
| LPC1700 / LPC1800 | Cortex-M3/M3 | CRP Levels 1–3 | High (CRP1/2) | 5–10 days |
| LPC2100 / LPC2300 | ARM7TDMI | CRP | High | 3–5 days |
| LPC54xxx | Cortex-M4 | CRP + Secure boot | Moderate | 7–14 days |
| MK60 (Kinetis K60) | Cortex-M4 | Flash Security + FSEC byte | High | 5–7 days |
| MKE02 (Kinetis E) | Cortex-M0+ | Flash Security | High | 3–5 days |
Nuvoton & Renesas
| Family | Protection | Success Tier | Turnaround |
|---|---|---|---|
| NUC131 (Nuvoton) | Flash lock bits | High | 3–5 days |
| NUC029 / NUC100 / NUC200 | Flash lock bits | High | 3–7 days |
| N76E003 | Lock byte | High | 3–5 days |
| R5F (Renesas RX / RL78) | ID code protection | Moderate | 5–10 days |
| R8C / M16C (Renesas) | ID code | High | 5–7 days |
| RA2 / RA4 (Renesas) | TrustZone + DLM | Case-by-case | 10–20 days |
Nuvoton’s NUC and N76E families use straightforward flash lock bits that our lab clears with high reliability. Renesas ID-code protection on the older R8C and M16C lines is similarly well-understood. The newer RA-series parts with Device Lifecycle Management (DLM) and TrustZone are evaluated individually — silicon revision and key provisioning state both affect the outcome.
Nordic Semiconductor (BLE SoCs)
Nordic’s nRF5x series is widely used in IoT, wearables, and industrial sensors. The APPROTECT mechanism disables SWD access when set. Our lab has repeatable methods for certain silicon revisions of the nRF51 and nRF52 families, making them frequent entries on our supported IC list.
| Part | Protection | Success Tier | Turnaround |
|---|---|---|---|
| nRF51822 | RBPCONF / APPROTECT | High | 3–7 days |
| nRF52832 | APPROTECT | Moderate | 5–10 days |
| nRF52840 | APPROTECT + Secure boot | Moderate | 7–14 days |
Newer nRF53 and nRF91 parts use ARM TrustZone and hardware root-of-trust. These are evaluated strictly on a case-by-case basis — contact us with the full part marking and revision code. Early nRF52832 revisions (QFAA-Bx0) tend to yield higher success rates than later steppings.
Cypress / Infineon PSoC
PSoC devices combine configurable analog blocks with an ARM or M8C core, making them common in industrial controls and medical peripherals. Flash protection on PSoC 1 (CY8C2xxxx) is software-configurable; PSoC 4/5/6 adds multi-level protection rows.
| Family | Protection | Success Tier | Turnaround |
|---|---|---|---|
| CY8C21x / CY8C24x / CY8C27x (PSoC 1) | Flash protection bits | High | 3–7 days |
| CY8C4xxx (PSoC 4) | Chip-level protection + row protection | Moderate | 7–12 days |
| CY8C5xxx (PSoC 5LP) | Multi-level protection | Case-by-case | 10–20 days |
| CY8C6xxx (PSoC 6) | Secure boot + eFuse | Case-by-case | 14–25 days |
Microchip PIC & AVR, TI MSP430, STC
These families represent some of the highest-volume IC unlock requests we handle. Microchip’s PIC and AVR lines use code-protect (CP) bits and lock bits respectively — both are well-characterized across decades of silicon revisions. TI’s MSP430 relies on a JTAG fuse that, once blown, blocks debug access; our techniques restore read capability on all tested MSP430F and MSP430G variants.
| Family | Protection | Success Tier | Turnaround |
|---|---|---|---|
| PIC16F / PIC18F (Microchip) | Code protect bits (CP) | High | 3–7 days |
| PIC24 / dsPIC33 | Code Guard / General Segment | Moderate | 5–10 days |
| PIC32MX / PIC32MZ | Code protect + Boot Flash protection | Moderate | 7–12 days |
| ATmega / ATtiny (Microchip/Atmel) | Lock bits | High | 3–5 days |
| MSP430 (Texas Instruments) | JTAG fuse | High | 3–7 days |
| STC15 / STC8 | Proprietary ISP lock | High | 3–5 days |
Serial EEPROM & Flash Memory ICs

Memory ICs are often overlooked, but they frequently store calibration data, configuration parameters, or even full application firmware in systems that boot from external flash. These devices typically use write-protect pins or software lock-down registers rather than cryptographic protection, making readout highly reliable. They form one of the simplest categories on our supported IC list for IC unlock.
| Part | Interface | Density | Success Tier | Turnaround |
|---|---|---|---|---|
| 24C02 | I²C | 2 Kbit | High | 1–2 days |
| 24C64 | I²C | 64 Kbit | High | 1–2 days |
| 24C256 | I²C | 256 Kbit | High | 1–2 days |
| AT24C512 | I²C | 512 Kbit | High | 1–2 days |
| 93C46 | Microwire | 1 Kbit | High | 1–2 days |
| 93C56 | Microwire | 2 Kbit | High | 1–2 days |
| M95080 | SPI | 8 Kbit | High | 1–2 days |
| SST25VF series | SPI | Up to 32 Mbit | High | 1–3 days |
| W25Q series (Winbond) | SPI | Up to 128 Mbit | High | 1–3 days |
| MX25L series (Macronix) | SPI | Up to 256 Mbit | High | 1–3 days |
Maxim (Analog Devices) Specialty MCUs
| Family | Protection | Success Tier | Turnaround |
|---|---|---|---|
| MAX32660 | Flash protection register | Moderate | 5–10 days |
| MAX32630 | Flash protection + Secure bootloader | Case-by-case | 10–15 days |
What Determines Whether an IC Can Be Unlocked?
Three factors control feasibility more than anything else:
- Protection level and generation. A single software lock bit (e.g., STM32 RDP Level 1 or PIC CP bit) is far easier to bypass than a hardware OTP fuse or AES-encrypted boot chain. Newer silicon revisions within the same family sometimes patch previously viable attack vectors — an STM32F1 from 2012 may respond to a technique that fails on a 2022 lot.
- Physical condition of the die. Corrosion, reballing damage, or decapsulation artifacts reduce success rates. We inspect every device under 200× magnification before committing to invasive work.
- Package and bond-wire accessibility. BGA and WLCSP packages require more preparation than LQFP or DIP. Turnaround for BGA parts typically adds 1–3 working days. QFN packages with exposed pads are intermediate in difficulty.
If your IC is not on this supported IC list, that does not mean recovery is impossible — it means we have not yet documented repeatable success. We accept evaluation samples for new parts at no charge beyond return shipping.
Authorization & Legal Requirements
Every IC unlock engagement requires proof of ownership or written authorization from the IP holder. This protects both parties and keeps the service within the bounds of legitimate reverse engineering for interoperability, maintenance, and archival purposes. Before work begins, clients sign an NDA and provide one of the following:
- Purchase order or invoice showing device procurement.
- Written authorization from the original equipment manufacturer.
- A declaration of ownership for legacy/end-of-life hardware recovery.
We maintain strict chain-of-custody documentation throughout the process. Read more about our compliance and IP-protection policies.
Typical Workflow for IC Unlock Requests
- Submit your part number and protection details — use our online form or email. Include the full part marking (top and bottom lines), package type, and any known protection level.
- Receive a feasibility report — within 1–2 working days, we confirm whether the device is on our supported IC list for IC unlock and provide a quote with turnaround estimate.
- Ship the device or board — we accept bare ICs or complete PCBAs. For EEPROM readout, a board photo with pinout is often sufficient for remote guidance.
- Firmware extraction and verification — recovered data is verified against known checksums or functional testing where possible. Deliverable formats include Intel HEX, Motorola S-Record, or raw BIN.
- Secure delivery — files are transferred via encrypted channel. Physical devices are returned insured.
For projects that also require full board-level duplication — schematic capture, Gerber generation, and BOM extraction — our PCB reverse engineering service integrates directly with IC unlock to deliver a complete reproduction package.
[pcb_cta type=”feasibility”]
Deliverable Formats & Verification
Recovered firmware is delivered in the format most useful for your reprogramming workflow. Standard options include:
| Format | Extension | Typical Use |
|---|---|---|
| Intel HEX | .hex | Most flash programmers, IDE import |
| Motorola S-Record | .srec / .s19 | Freescale/NXP toolchains, automotive ECUs |
| Raw Binary | .bin | Direct flash image, EEPROM writers |
| Annotated Memory Map | .pdf + .bin | Multi-region devices (bootloader + app + data) |
For multi-region devices — common in STM32 and PIC32 parts with separate bootloader, application, and EEPROM data sections — we provide an annotated memory map at no extra charge, identifying each region’s start address, size, and CRC where applicable.
Pricing Signals & Turnaround Summary
IC unlock pricing depends on the protection mechanism, not just the part number. As a general guide:
- EEPROM / simple lock-bit MCUs (24Cxx, ATmega, PIC16F, STC): starting from approximately $50–$150, 1–5 working days.
- Mid-tier protection (STM32 RDP L1, NXP CRP1/2, MSP430 JTAG fuse): starting from approximately $150–$500, 3–10 working days.
- High-tier / invasive (STM32 RDP L2, NXP CRP3, nRF52 APPROTECT, PSoC 5LP): quoted per-project after feasibility assessment, 7–25 working days.
Exact pricing is provided after we confirm the part number and protection state. Request a quote through our project quotation page.
Frequently Asked Questions
How often is the supported IC list updated?
We add new part numbers as our engineers validate repeatable IC unlock methods — typically 5–10 new entries per quarter. If your device is not listed, request a free evaluation. Newly validated parts are published within two weeks of confirmed success.
Can you unlock an IC with RDP Level 2 or CRP Level 3?
These are the highest software-protection tiers offered by STM32 and NXP LPC respectively. Success depends on the specific silicon revision and die-level characteristics. We provide an honest feasibility assessment before quoting — if we cannot recover the firmware, you pay nothing for the evaluation.
Do I need to remove the IC from the board before shipping?
Not necessarily. For many MCUs, we can connect via debug headers or test points on the assembled PCBA. For invasive techniques or EEPROM readout, desoldering may be required — our technicians handle this in-house to avoid damage.
Is IC unlock legal?
Authorized firmware recovery — for hardware you own, legacy maintenance, or interoperability — is legal in most jurisdictions under provisions like the DMCA §1201 exemptions and EU Directive 2009/24/EC. We require proof of ownership and operate under NDA for every project. See our trust and compliance page for details.
What if my IC family is not on the supported IC list?
An unlisted part does not mean recovery is impossible. Ship us an evaluation sample or provide the full part marking and package details, and our engineers will assess feasibility within 1–2 working days at no charge. We regularly expand the supported IC list for IC unlock based on client requests and new tooling investments.
Working on a board like this?
Send the chip marking or two photos. You get feasibility, lead time and price within 24 hours, and the check costs nothing.
Get a free quote