Microcontroller Unlock Service

A locked microcontroller is not a dead end. Read-out protection, code-read-protect bits and debug-port locks are all implemented in silicon, and anything implemented in silicon can be reversed given the right approach and enough patience. What varies is the method, the cost and whether the part survives.

We work across the major MCU families and select the approach per silicon revision, not per datasheet claim — because the same part number often ships in several revisions with materially different protection strength.

Families we work with

Vendor Families Common protection
STMicroelectronics STM32 F0/F1/F2/F3/F4/F7/L0/L1/L4, STM8 RDP level 1 and 2
GigaDevice GD32 F1/F3/F4/E1 series SPC / read-out protect
Microchip PIC10/12/16/18/24/32, dsPIC Code-protect and config fuses
Atmel / Microchip ATmega, ATtiny, AT89 series Lock bits and security fuse
NXP LPC1100/1300/1700/4000, Kinetis K/KL/KE, S32K CRP levels, flash security register
Texas Instruments MSP430, CC253x, CC26xx, TMS320 JTAG fuse, BSL lock
Renesas RL78, RX, RA, R8C, M16C ID code and option-byte lock
Legacy 8051 derivatives, Infineon XC800, Fujitsu, Holtek, Sonix Security fuse, OTP lock

What unlocking actually involves

  • Identification first. Markings alone are not reliable — re-marked parts and die revisions with different protection strength both exist. Where it matters we confirm the actual die before choosing a method.
  • Non-invasive first. Debug interface re-enablement, bootloader paths, update channels and known silicon errata. If one of these works, the device is returned to you unmodified and fully functional.
  • Semi-invasive where needed. Package opening followed by optical or laser injection against the protection state machine, with the device running under controlled clock and voltage.
  • Invasive only as a last resort. Micro-probing or FIB work on the die to reach the protection logic or read the array directly.

What you receive

  • The unlocked device and/or the recovered firmware image, depending on the method used
  • A memory map note and load address so the binary can be loaded straight into your toolchain
  • A written record of the protection found, the method applied and whether the method is repeatable on further samples

Frequently asked questions

Can every protected MCU be unlocked?
No. Most can, but some cannot within a sensible budget — typically parts where the protection is hardware-enforced on a recent die revision with no observable side channel and no exploitable interface. The honest answer is that we assess first and tell you the probability before you commit to the destructive stage.

Will the MCU still work after unlocking?
It depends entirely on the method. Non-invasive unlocking leaves the part untouched and fully functional. Semi-invasive work usually leaves it functional but with the package opened, which is fine for bench use and unsuitable for production. Invasive methods generally make the part unusable, and in those cases the deliverable is the firmware rather than a working device.

Can you unlock many identical units?
Yes, and it is usually cheaper per unit than the first one, because the first engagement pays for the method development. If you have a batch, tell us the quantity up front — for some families the repeatable path is a fixture-based procedure rather than a per-device attack.

How long does unlocking take?
A known method on a common family typically takes three to ten working days. A device requiring new method development runs two to six weeks. We give you a realistic estimate after assessment rather than a best-case number.

Is there a cheaper alternative to unlocking?
Sometimes. If your actual goal is to understand a device’s behaviour or replace it rather than to recover its code, then reverse engineering, functional reproduction or simply buying the part may be cheaper. Tell us the end goal, not just the request, and we will say if there is a shorter route.

Send a device for assessment

Supply the part number, the board if available, the quantity you need unlocked, and what you intend to do with the result. We will confirm the protection type, the realistic method, the probability of success and whether the device survives. Work is accepted only where the requester can demonstrate ownership or written authorisation.