What Is Chip-Off and Who Performs It? The NAND Flash Forensics Method
Chip-off = a data recovery / forensics method in which the NAND flash memory is desoldered and read with a programmer. JTAG and ISP are alternatives. PC-3000 Flash and Easy JTAG Plus hardware.
Chip-off is the process of physically separating a NAND flash or eMMC memory chip from the PCB using a desoldering station and inserting it into a dedicated programmer device to take a raw read. It is a hardware-level, last-resort forensics method applied to mobile phones, USB sticks, SSDs, and embedded devices when the operating system cannot boot or the device has suffered physical damage.
TL;DR
- Chip-off is the removal of a NAND/eMMC chip from the PCB and reading it with a programmer.
- JTAG and ISP are less invasive alternatives; chip-off is the most aggressive method.
- Hardware: PC-3000 Flash, Easy JTAG Plus, FlashCAT-USB, Medusa Pro II.
- Typical duration: 4 to 48 hours. The success rate is around 90%+ if the chip is intact.
- For acceptance as evidence in court, an ISO/IEC 27037 compliant process and a hash are mandatory.
Detailed Answer
When is chip-off needed?
Chip-off is brought into play when less invasive methods have been exhausted. The following situations are typical triggers:
| Scenario | Recommended method |
|---|---|
| Running, password-protected device | Logical extraction, JTAG |
| Boots but is software-locked | ISP (In-System Programming) |
| Dead device after water, fire, or physical impact | Chip-off |
| USB/SSD with a faulty controller chip | Chip-off + virtual translator |
| Encrypted (BitLocker, FBE) device | Chip-off + limited key recovery |
Process steps
- The device is documented, photographed, and an ISO/IEC 27037 compliant chain of evidence is started.
- The PCB is disassembled, and the NAND/eMMC chip is separated from the solder with a BGA heat station (typically 220-240 degrees preheat, 280-310 degrees top nozzle).
- The chip pads are cleaned; reballing is done if necessary.
- The chip is placed into a socketed programmer; a read is taken according to the manufacturer's pinout.
- The SHA-256 and MD5 values of the raw bin file are calculated and reported.
- ECC resolution, page/spare separation, and XOR/scrambling reverse engineering are applied.
- The manufacturer-specific FTL (Flash Translation Layer) is reconstructed; a logical image is created.
As part of a broader forensics process, we covered the hardware details in our article on data recovery from NAND flash with chip-off.
Hardware inventory (2026 market)
- ACE Lab PC-3000 Flash: the industry standard for monolithic USB sticks and SSD chip-off.
- Easy JTAG Plus: JTAG/ISP/eMMC, a lower-cost, mobile-focused set.
- FlashCAT-USB Mk2: a general-purpose unit with TSOP-48 and BGA-152/162/169/221 adapters.
- Medusa Pro II: a common choice for mobile technical services, ISP-focused.
- Rusolut Visual NAND Reconstructor: used on the software side for FTL resolution.
Who performs it?
Chip-off is carried out by certified digital forensics laboratories, the cybercrime units of law enforcement, and private data recovery firms. To provide a service in this scope in Turkey, you need digital forensics expert authorization, a dedicated ESD-protected clean area, a calibrated soldering station, and hash-verifiable chain-of-evidence software.
Success rate and risk
If the NAND chip is physically intact, the success rate is above 90%. However, two risks stand out in modern devices:
- Full disk encryption (Android FBE, iOS Secure Enclave, BitLocker, LUKS): even if a raw read is taken, the content is meaningless without the key.
- On-chip encryption (Apple A7+, modern Samsung): chip-off practically fails; JTAG/ISP is not a solution either.
For this reason, in the cyber incident response playbook process, the evidence priority should be live memory (RAM) and the logical image, and chip-off should be planned as a last resort.
Legal framework
In Turkey, the collection of digital evidence is framed by CMK 134 and ISO/IEC 27037:2012. The integrity of the extracted image is verified with a hash (SHA-256 is recommended), and a report is signed in the presence of two witnesses. Otherwise, the evidence may be rejected in proceedings. In corporate incident management, it is advisable to run it in parallel with the KVKK 72-hour data breach notification template.
Cost
As of 2026, a chip-off operation for a single device in Turkey is roughly in the 8,000 to 35,000 TL range. The price rises when chip reballing and a special programmer adapter are required. In SSD multi-chip scenarios, the labor increases because each chip requires a separate read plus FTL resolution. For cost planning, you can refer to the RAID cost calculator tool; the same logic also applies to multi-chip SSDs.
Modern comparison: chip-off, JTAG, ISP
| Method | Invasive? | Typical duration | Encrypted device | Hardware cost |
|---|---|---|---|---|
| Logical | No | 1-4 hours | Limited | Low |
| ISP | Light (test pad soldering) | 4-12 hours | Difficult | Medium |
| JTAG | Light (TAP pins) | 4-12 hours | Difficult | Medium |
| Chip-off | High (chip removal) | 8-48 hours | Without the key, the data stays raw and encrypted | High |
The right method choice depends on the device's condition, manufacturer, and encryption scheme. In the decision matrix, the least invasive method is tried first; if it fails or the device is physically damaged, chip-off is brought into play.
Frequently Asked Questions (FAQ)
Can a device that has had chip-off performed be used again?
No. After the chip is removed, the device is not expected to regain its original function. In some cases, it is resoldered with reballing, but this operation affects the manufacturer's warranty and the device's reliability.
Does chip-off work on an iPhone?
On the iPhone 5s and later models, since the Secure Enclave keys are held inside the chip, even if chip-off takes a raw read, the content stays encrypted. For iPhone, logical methods such as GrayKey or Cellebrite are preferred today.
Can deleted data be recovered with chip-off?
Yes, if the TRIM command did not run on the NAND or if data remained in the overprovisioning area, deleted blocks can be recovered. On SSDs, if TRIM is active, deleted data is most likely unrecoverable.
What is the difference between JTAG and chip-off?
JTAG does not remove the chip; it takes a read through the test pins (TAP) on the PCB. It is less risky, but the success rate is low on encrypted or locked devices. Chip-off, on the other hand, physically removes the chip and provides raw access.
Is there a chip-off service provider in Turkey?
Yes. DSET carries out chip-off, JTAG, and ISP processes in an ISO/IEC 27037 compliant manner at its Hacettepe Teknokent Beytepe location. Contact: +90 536 662 38 09, [email protected].
Kimliğinizi doğrulayın
Yetkilendirilmiş erişim alanı. Tüm giriş denemeleri kayıt altına alınır.