High-Tech PCB Reverse Engineering Serices PCB Clone & IC Unlock

Unlockable chip list

Our unlock database covers 5000+ chip models. Published below are 126 of them across 28 families, with typical turnaround. Not finding yours does not mean no: it means we have not published it yet.

Complete Unlockable Chip List for Authorized Firmware Recovery

Our unlockable chip list covers more than 40 microcontroller and memory IC families across 15 vendors. Each entry reflects lab-verified results — not theoretical claims. If your chip appears in the “High” success column, we can typically deliver a binary readout within 5–10 working days. If it falls in the “Evaluate” column, we need the physical device for a no-cost feasibility check before committing. This page is the fastest way to determine whether your authorized recovery project is viable before you ship a single sample.

How to Use This Unlockable Chip List

unlockable chip list: Desoldered microcontroller chips on an antistatic mat beside a stereo microscope and programmer

Find your chip vendor in the tables below, then locate the specific family or part number. Each row tells you three things: the protection mechanism the silicon uses, our current success category (High / Moderate / Evaluate / Not Feasible), and the typical turnaround once we accept the job. “High” means ≥90 % historical success across multiple samples. “Moderate” sits between 60–89 %. “Evaluate” means results depend on the specific revision, fuse configuration, or batch — we need your device on our bench first.

All IC unlock work requires proof of ownership or written authorization. We operate under NDA and refuse jobs that lack legitimate documentation.

Microcontroller Families — Unlock Feasibility Table

Vendor Family / Series Protection Type Success Category Typical Turnaround
STMicroelectronics STM8S (all sub-variants) ROP Level 1 / Level 2 High (Level 1); Evaluate (Level 2) 5–8 days
STMicroelectronics STM8L series ROP Level 1 / Level 2 High (Level 1); Evaluate (Level 2) 5–10 days
STMicroelectronics STM32F0 / F1 / F2 / F3 RDP Level 1 High 5–8 days
STMicroelectronics STM32F4 / F7 / H7 RDP Level 1; TrustZone (H7) Moderate (F4); Evaluate (F7/H7) 7–15 days
Microchip PIC10 / PIC12 / PIC16 CP / CPD fuse bits High 3–7 days
Microchip PIC18 / PIC24 / dsPIC33 Code-protect fuse, JTAG lock High (PIC18); Moderate (PIC24/dsPIC) 5–10 days
Microchip PIC32MX / MZ Code-protect + secure boot Moderate 8–12 days
Nuvoton NUC131 / NUC029 / NUC100 Flash lock bit High 5–8 days
Nuvoton M451 / M480 / M2351 Security lock + TrustZone (M2351) Moderate (M451/M480); Not Feasible (M2351 TZ) 7–12 days
NXP / Freescale MK60 / MK64 / MK66 Flash security byte (FSEC) High 5–10 days
NXP / Freescale MKE02 / MKE04 Flash security byte High 5–8 days
NXP LPC1100 / LPC1300 / LPC1700 CRP Level 1 / 2 / 3 High (CRP1); Moderate (CRP2); Not Feasible (CRP3) 5–12 days
Renesas R5F (RL78 / RX family) ID code protection High (RL78); Moderate (RX) 5–10 days
Renesas SH7050 / SH7080 ID code + on-chip key Evaluate 10–15 days
Atmel (Microchip) ATmega48 / 88 / 168 / 328 Lock bits (LB1/LB2/LB3) High 3–7 days
Atmel ATxmega / SAMD21 NVM lock / BOOTPROT Moderate (ATxmega); Evaluate (SAMD21) 7–12 days
Cypress CY8C (PSoC 1 / 3 / 4 / 5) Flash protection rows High (PSoC 1); Moderate (PSoC 4); Evaluate (PSoC 5) 5–12 days
Nordic nRF52832 APPROTECT (UICR) Moderate 7–12 days
Nordic nRF52840 APPROTECT + Secure APPROTECT Evaluate 10–15 days
Maxim MAX32660 SWD lock + flash protection Moderate 8–12 days
TI MSP430F / MSP430G JTAG fuse blow High (G series); Moderate (F series) 5–10 days
TI CC2540 / CC2541 / CC2640 Debug lock + flash protect Moderate (CC254x); Evaluate (CC2640) 7–15 days
STC STC89 / STC12 / STC15 Encryption download High (STC89); Moderate (STC12/15) 5–10 days
GigaDevice GD32F103 / GD32F303 SWD lock + OB protection High 5–8 days

EEPROM and Serial Flash — Readout Feasibility

Memory-only ICs are generally easier to read than microcontrollers because they lack execute-in-place code protection. However, some devices use write-protect registers, OTP zones, or password-locked sectors that complicate extraction. The table below covers the serial EEPROM and SPI/NOR flash families we handle most often.

Type Part Family Interface Success Category Notes
I²C EEPROM 24C02 I²C High Standard read; no security
I²C EEPROM 24C64 I²C High 64 Kbit; straightforward
I²C EEPROM 24C256 I²C High 256 Kbit; occasional write-protect pin lock
I²C EEPROM AT24C512 I²C High 512 Kbit; may need address pin config
SPI EEPROM M95080 SPI High 8 Kbit; block-protect bits clearable
Microwire EEPROM 93C46 Microwire High 1 Kbit; legacy automotive/industrial
Microwire EEPROM 93C56 Microwire High 2 Kbit; same protocol family
SPI NOR Flash SST25VF series SPI High Up to 32 Mbit; AAI write mode
SPI NOR Flash W25Q32 / W25Q128 SPI High Sector/block protect clearable via status register
SPI NOR Flash MX25L series SPI High OTP area may be locked; main array readable

What Determines Whether a Chip Is Unlockable?

Three factors control feasibility more than anything else: the protection architecture, the silicon revision, and the physical condition of the die. Our engineers evaluate each one before committing to a job.

Protection Architecture

Single-level read-out protection (like STM8 ROP Level 1 or NXP CRP Level 1) is almost always recoverable using non-invasive or semi-invasive techniques. Multi-level schemes — STM32 RDP Level 2, NXP CRP Level 3, or hardware-rooted TrustZone — permanently disable debug interfaces and may require micro-probing or UV fault injection, which drops success rates below 50 % and raises cost significantly.

Silicon Revision

Vendors patch vulnerabilities between die revisions. An STM32F1 Rev Z may respond to a glitching vector that Rev Y has hardened against. We maintain a revision-specific database, but new revisions occasionally appear in the field before we can characterize them — hence the “Evaluate” category.

Physical Condition

Chips pulled from fire-damaged, water-damaged, or heavily corroded boards can still be candidates, but bond-wire integrity and passivation layer condition affect micro-probing yield. If the die is cracked, success drops to near zero. We photograph every device under a stereo microscope before starting invasive work.

Chips We Cannot Currently Unlock

Technician placing a TQFP microcontroller into a ZIF socket for firmware readout

Transparency matters. The following families are either not feasible with current techniques or carry success rates too low to justify quoting at a fixed price:

  • STM32 with RDP Level 2 confirmed — debug port permanently disabled by fuse blow; requires die-level attack with no guaranteed outcome.
  • NXP LPC with CRP Level 3 — mass-erase-only recovery; firmware cannot be read.
  • Infineon AURIX TC2xx / TC3xx — HSM-based protection with hardware key store; no known non-destructive vector.
  • Renesas RH850 with ICU-S — secure hardware module; not currently in our capability set.
  • Any chip with active secure-boot chain and encrypted flash — even if the debug port is recovered, the binary is encrypted at rest and useless without the key.

If your part falls into this category, we will tell you during the free feasibility evaluation rather than accepting the job and failing silently.

Our Evaluation and Readout Process

  1. Intake: You submit the part number, package marking photo, and proof of ownership. We cross-reference our unlockable chip list and reply within one business day with a preliminary assessment.
  2. Feasibility check (if needed): For “Evaluate” parts, ship us 1–2 samples. We perform non-destructive probing at no charge and report back within 3–5 days.
  3. Readout: Once confirmed feasible, we extract the firmware binary (Intel HEX, Motorola S-record, or raw BIN — your choice). Typical turnaround: 5–15 working days depending on complexity.
  4. Verification: We program the extracted binary onto a blank device of the same part number and verify functional equivalence before delivery.

[pcb_cta type=”feasibility”]

Authorization and Legal Requirements

Every project requires a signed declaration of ownership or a letter of authorization from the IP holder. We will not proceed without this documentation. Our NDA covers all project data, extracted binaries, and communication records. For more detail on how we handle IP protection and compliance, see our trust and authorization policy.

Frequently Asked Questions

Is this unlockable chip list exhaustive?

No. We update it quarterly as we verify new families and silicon revisions. If your specific part number is not listed, submit a feasibility request with the full marking — our lab may already have data on it that has not yet been published. We add roughly 5–10 new confirmed part numbers per quarter.

What does “Evaluate” mean for my project timeline?

It means we need the physical device before we can commit to a success rate or fixed price. The evaluation itself takes 3–5 working days and is free of charge. If we determine the chip is not recoverable, we return your samples at our expense. Total project time for an Evaluate-category chip is typically 10–20 working days end to end.

Can you read a chip that has been desoldered or damaged?

Desoldered chips are fine — we work with bare ICs routinely. Damaged chips depend on the failure mode. Cracked dies are almost never recoverable. Corroded packages or lifted bond pads reduce success by roughly 30–40 %, but we have recovered firmware from flood-damaged industrial boards where the die itself was intact under the epoxy.

How do EEPROM reads differ from MCU firmware extraction?

EEPROMs like the 24C02 or 93C46 store data, not executable code, and typically lack code-protection fuses. Readout is usually a standard bus transaction — fast, inexpensive, and near 100 % successful. MCU extraction must bypass active protection circuits, which is why it costs more and takes longer.

Do you offer bulk pricing for production-volume readouts?

Yes. For batches of 10+ identical ICs, per-unit cost drops 20–40 % because setup and characterization are amortized. Contact us with your volume and part number for a custom quote.

[pcb_cta type=”quote”]

{
“@context”: “https://schema.org”,
“@type”: “Service”,
“name”: “IC Unlock / Chip Firmware Recovery”,
“url”: “https://pcb-copy.com/unlockable-chip-list/”,
“provider”: {
“@type”: “Organization”,
“name”: “PCB-Copy.com”
},
“description”: “Authorized firmware extraction and chip readout service covering 40+ MCU and memory IC families. Free feasibility evaluation for unlisted parts.”,
“serviceType”: “IC Unlock and Firmware Recovery”
}

{
“@context”: “https://schema.org”,
“@type”: “BreadcrumbList”,
“itemListElement”: [
{“@type”: “ListItem”, “position”: 1, “name”: “Home”, “item”: “https://pcb-copy.com/”},
{“@type”: “ListItem”, “position”: 2, “name”: “Unlockable Chip List”, “item”: “https://pcb-copy.com/unlockable-chip-list/”}
]
}

{
“@context”: “https://schema.org”,
“@type”: “FAQPage”,
“mainEntity”: [
{
“@type”: “Question”,
“name”: “Is this unlockable chip list exhaustive?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “No. We update it quarterly as we verify new families and silicon revisions. If your specific part number is not listed, submit a feasibility request with the full marking — our lab may already have data on it.”
}
},
{
“@type”: “Question”,
“name”: “What does Evaluate mean for my project timeline?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “It means we need the physical device before we can commit to a success rate or fixed price. The evaluation takes 3–5 working days and is free of charge. Total project time is typically 10–20 working days.”
}
},
{
“@type”: “Question”,
“name”: “Can you read a chip that has been desoldered or damaged?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “Desoldered chips are fine. Damaged chips depend on the failure mode. Cracked dies are almost never recoverable, but corroded packages may still yield firmware if the die is intact.”
}
},
{
“@type”: “Question”,
“name”: “How do EEPROM reads differ from MCU firmware extraction?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “EEPROMs store data and typically lack code-protection fuses, making readout a standard bus transaction that is fast and inexpensive. MCU extraction must bypass active protection circuits, increasing cost and turnaround.”
}
},
{
“@type”: “Question”,
“name”: “Do you offer bulk pricing for production-volume readouts?”,
“acceptedAnswer”: {
“@type”: “Answer”,
“text”: “Yes. For batches of 10+ identical ICs, per-unit cost drops 20–40% because setup and characterization are amortized. Contact us with your volume and part number for a custom quote.”
}
}
]
}

ModelFamilyPackageStatusTypical lead time
STM32F103C8T6 STM32 F0/F1 LQFP unlockable 3-5 working days
STM32F103RCT6 STM32 F0/F1 LQFP unlockable 3-5 working days
STM32F103VET6 STM32 F0/F1 LQFP unlockable 3-5 working days
STM32F030C8T6 STM32 F0/F1 LQFP unlockable 3-5 working days
STM32F051R8T6 STM32 F0/F1 LQFP unlockable 3-5 working days
STM32F072CBT6 STM32 F0/F1 LQFP unlockable 3-5 working days
STM32F407VGT6 STM32 F4 LQFP/UFQFPN unlockable 5-7 working days
STM32F401CCU6 STM32 F4 LQFP/UFQFPN unlockable 5-7 working days
STM32F405RGT6 STM32 F4 LQFP/UFQFPN unlockable 5-7 working days
STM32F411CEU6 STM32 F4 LQFP/UFQFPN unlockable 5-7 working days
STM32F429ZIT6 STM32 F4 LQFP/UFQFPN unlockable 5-7 working days
STM32L051C8T6 STM32 L/G LQFP unlockable 5-8 working days
STM32L151C8T6 STM32 L/G LQFP unlockable 5-8 working days
STM32L476RGT6 STM32 L/G LQFP unlockable 5-8 working days
STM32G071RBT6 STM32 L/G LQFP unlockable 5-8 working days
STM32G474RET6 STM32 L/G LQFP unlockable 5-8 working days
STM8S003F3P6 STM8 TSSOP/LQFP unlockable 3-5 working days
STM8S105K4T6 STM8 TSSOP/LQFP unlockable 3-5 working days
STM8S207RBT6 STM8 TSSOP/LQFP unlockable 3-5 working days
STM8L151K4T6 STM8 TSSOP/LQFP unlockable 3-5 working days
PIC16F877A Microchip PIC DIP/SOIC unlockable 3-5 working days
PIC16F628A Microchip PIC DIP/SOIC unlockable 3-5 working days
PIC16F1937 Microchip PIC DIP/SOIC unlockable 3-5 working days
PIC12F508 Microchip PIC DIP/SOIC unlockable 3-5 working days
PIC12F675 Microchip PIC DIP/SOIC unlockable 3-5 working days
PIC18F4550 Microchip PIC DIP/SOIC unlockable 3-5 working days
PIC18F45K80 Microchip PIC DIP/SOIC unlockable 3-5 working days
PIC18F2550 Microchip PIC DIP/SOIC unlockable 3-5 working days
PIC24FJ64GA002 PIC24/dsPIC SOIC/TQFP unlockable 5-8 working days
PIC24EP256GP204 PIC24/dsPIC SOIC/TQFP unlockable 5-8 working days
DSPIC30F4011 PIC24/dsPIC SOIC/TQFP unlockable 5-8 working days
DSPIC33FJ128GP802 PIC24/dsPIC SOIC/TQFP unlockable 5-8 working days
ATMEGA8A AVR ATmega DIP/TQFP unlockable 3-5 working days
ATMEGA16A AVR ATmega DIP/TQFP unlockable 3-5 working days
ATMEGA32A AVR ATmega DIP/TQFP unlockable 3-5 working days
ATMEGA48PA AVR ATmega DIP/TQFP unlockable 3-5 working days
ATMEGA88PA AVR ATmega DIP/TQFP unlockable 3-5 working days
ATMEGA128A AVR ATmega DIP/TQFP unlockable 3-5 working days
ATMEGA328P AVR ATmega DIP/TQFP unlockable 3-5 working days
ATMEGA2560 AVR ATmega DIP/TQFP unlockable 3-5 working days
ATTINY13A AVR ATtiny DIP/SOIC unlockable 3-5 working days
ATTINY85 AVR ATtiny DIP/SOIC unlockable 3-5 working days
ATTINY2313 AVR ATtiny DIP/SOIC unlockable 3-5 working days
ATTINY861 AVR ATtiny DIP/SOIC unlockable 3-5 working days
AT89C51 AT89 8051 DIP/PLCC unlockable 3-5 working days
AT89C52 AT89 8051 DIP/PLCC unlockable 3-5 working days
AT89C2051 AT89 8051 DIP/PLCC unlockable 3-5 working days
AT89S52 AT89 8051 DIP/PLCC unlockable 3-5 working days
AT89C51RD2 AT89 8051 DIP/PLCC unlockable 3-5 working days
STC89C52RC STC 8051 DIP/LQFP unlockable 3-5 working days
STC12C5A60S2 STC 8051 DIP/LQFP unlockable 3-5 working days
STC15W4K56S4 STC 8051 DIP/LQFP unlockable 3-5 working days
STC8H8K64U STC 8051 DIP/LQFP unlockable 3-5 working days
STC15F2K60S2 STC 8051 DIP/LQFP unlockable 3-5 working days
C8051F340 Silicon Labs TQFP/QFN unlockable 5-8 working days
C8051F020 Silicon Labs TQFP/QFN unlockable 5-8 working days
C8051F410 Silicon Labs TQFP/QFN unlockable 5-8 working days
EFM8BB31F16G Silicon Labs TQFP/QFN unlockable 5-8 working days
N76E003AT20 Nuvoton TSSOP/LQFP unlockable 3-5 working days
NUC131LD2AE Nuvoton TSSOP/LQFP unlockable 3-5 working days
M0516LDN Nuvoton TSSOP/LQFP unlockable 3-5 working days
M051 Nuvoton TSSOP/LQFP unlockable 3-5 working days
NUC029FAE Nuvoton TSSOP/LQFP unlockable 3-5 working days
LPC1768FBD100 NXP LPC LQFP unlockable 6-10 working days
LPC2148FBD64 NXP LPC LQFP unlockable 6-10 working days
LPC11C14FBD48 NXP LPC LQFP unlockable 6-10 working days
LPC824M201 NXP LPC LQFP unlockable 6-10 working days
MK10DN512VLL10 Kinetis / Freescale LQFP unlockable 6-10 working days
MKL25Z128VLK4 Kinetis / Freescale LQFP unlockable 6-10 working days
MC9S12XS128 Kinetis / Freescale LQFP unlockable 6-10 working days
MC9S08AW32 Kinetis / Freescale LQFP unlockable 6-10 working days
R5F100LEA Renesas LQFP unlockable 7-12 working days
R5F21134 Renesas LQFP unlockable 7-12 working days
M30620FCAFP Renesas LQFP unlockable 7-12 working days
RL78G13 Renesas LQFP unlockable 7-12 working days
MSP430F149 TI MSP430 LQFP/TSSOP unlockable 3-5 working days
MSP430G2553 TI MSP430 LQFP/TSSOP unlockable 3-5 working days
MSP430F5529 TI MSP430 LQFP/TSSOP unlockable 3-5 working days
MSP430FR5969 TI MSP430 LQFP/TSSOP unlockable 3-5 working days
TMS320F28035 TI C2000 LQFP review first 7-12 working days
TMS320F28335 TI C2000 LQFP review first 7-12 working days
TMS320F280049 TI C2000 LQFP review first 7-12 working days
GD32F103C8T6 GigaDevice GD32 LQFP unlockable 3-5 working days
GD32F303RCT6 GigaDevice GD32 LQFP unlockable 3-5 working days
GD32E230C8T6 GigaDevice GD32 LQFP unlockable 3-5 working days
GD32F470ZGT6 GigaDevice GD32 LQFP unlockable 3-5 working days
CH32V307VCT6 WCH CH32/CH5xx LQFP/SOP unlockable 3-5 working days
CH32F103C8T6 WCH CH32/CH5xx LQFP/SOP unlockable 3-5 working days
CH552G WCH CH32/CH5xx LQFP/SOP unlockable 3-5 working days
CH340G WCH CH32/CH5xx LQFP/SOP unlockable 3-5 working days
HT66F318 Holtek SOP/DIP unlockable 3-5 working days
HT46R064B Holtek SOP/DIP unlockable 3-5 working days
HT48R30A-1 Holtek SOP/DIP unlockable 3-5 working days
XC866 Infineon LQFP/BGA review first 10-15 working days
XMC1100 Infineon LQFP/BGA review first 10-15 working days
TC1782 Infineon LQFP/BGA review first 10-15 working days
SAK-TC275 Infineon LQFP/BGA review first 10-15 working days
CY8C4245AXI Cypress PSoC TQFP unlockable 6-10 working days
CY7C68013A Cypress PSoC TQFP unlockable 6-10 working days
CY8C5868AXI Cypress PSoC TQFP unlockable 6-10 working days
MB90F546 Fujitsu FM LQFP unlockable 7-12 working days
MB95F204 Fujitsu FM LQFP unlockable 7-12 working days
MB91F467 Fujitsu FM LQFP unlockable 7-12 working days
S3F9454 Samsung SOP/BGA review first 10-15 working days
S3C2440 Samsung SOP/BGA review first 10-15 working days
S3F94C4 Samsung SOP/BGA review first 10-15 working days
AT24C02 EEPROM / Flash SOIC/DIP unlockable 2-4 working days
AT24C256 EEPROM / Flash SOIC/DIP unlockable 2-4 working days
24LC64 EEPROM / Flash SOIC/DIP unlockable 2-4 working days
93C46 EEPROM / Flash SOIC/DIP unlockable 2-4 working days
W25Q64 EEPROM / Flash SOIC/DIP unlockable 2-4 working days
W25Q128 EEPROM / Flash SOIC/DIP unlockable 2-4 working days
SST25VF016B EEPROM / Flash SOIC/DIP unlockable 2-4 working days
EPM7128SLC84 CPLD PLCC/TQFP review first 10-20 working days
EPM240T100C5 CPLD PLCC/TQFP review first 10-20 working days
XC9536XL CPLD PLCC/TQFP review first 10-20 working days
XC2C64A CPLD PLCC/TQFP review first 10-20 working days
LC4032V CPLD PLCC/TQFP review first 10-20 working days
XC6SLX9 FPGA TQFP/BGA review first 10-20 working days
EP4CE6E22C8 FPGA TQFP/BGA review first 10-20 working days
EP2C5T144 FPGA TQFP/BGA review first 10-20 working days
STC8G1K08 Other 8-bit MCU DIP/SOP unlockable 3-5 working days
SN8P2711 Other 8-bit MCU DIP/SOP unlockable 3-5 working days
EM78P153 Other 8-bit MCU DIP/SOP unlockable 3-5 working days
MDT2005 Other 8-bit MCU DIP/SOP unlockable 3-5 working days
NY8A051 Other 8-bit MCU DIP/SOP unlockable 3-5 working days

Chip not on the list?

The table only holds parts we have already published, a fraction of the 5000+ models in the database. Most unlisted markings are still workable, especially older 8-bit parts and anything in a DIP, SOP or QFP package. Send the marking and you get a yes or no with a price.

Ask about a specific chip
Free check

Send the marking, get the answer today

Photograph the top of the chip. If the marking is worn we can often still identify it from the package and the board.

A clear photo of the marking usually removes one round of questions.

Judy answers personally, High-Tech PCB Reverse Engineering Serices. NDA available before you send any file.

WhatsApp Send board details