Chip-off is the process of physically separating a NAND flash or eMMC memory chip from the PCB using a desoldering station and inserting it into a dedicated programmer device to take a raw read. It is a hardware-level, last-resort forensics method applied to mobile phones, USB sticks, SSDs, and embedded devices when the operating system cannot boot or the device has suffered physical damage.

TL;DR

  • Chip-off is the removal of a NAND/eMMC chip from the PCB and reading it with a programmer.
  • JTAG and ISP are less invasive alternatives; chip-off is the most aggressive method.
  • Hardware: PC-3000 Flash, Easy JTAG Plus, FlashCAT-USB, Medusa Pro II.
  • Typical duration: 4 to 48 hours. The success rate is around 90%+ if the chip is intact.
  • For acceptance as evidence in court, an ISO/IEC 27037 compliant process and a hash are mandatory.

Detailed Answer

When is chip-off needed?

Chip-off is brought into play when less invasive methods have been exhausted. The following situations are typical triggers:

Scenario Recommended method
Running, password-protected device Logical extraction, JTAG
Boots but is software-locked ISP (In-System Programming)
Dead device after water, fire, or physical impact Chip-off
USB/SSD with a faulty controller chip Chip-off + virtual translator
Encrypted (BitLocker, FBE) device Chip-off + limited key recovery

Process steps

  1. The device is documented, photographed, and an ISO/IEC 27037 compliant chain of evidence is started.
  2. The PCB is disassembled, and the NAND/eMMC chip is separated from the solder with a BGA heat station (typically 220-240 degrees preheat, 280-310 degrees top nozzle).
  3. The chip pads are cleaned; reballing is done if necessary.
  4. The chip is placed into a socketed programmer; a read is taken according to the manufacturer's pinout.
  5. The SHA-256 and MD5 values of the raw bin file are calculated and reported.
  6. ECC resolution, page/spare separation, and XOR/scrambling reverse engineering are applied.
  7. The manufacturer-specific FTL (Flash Translation Layer) is reconstructed; a logical image is created.

As part of a broader forensics process, we covered the hardware details in our article on data recovery from NAND flash with chip-off.

Hardware inventory (2026 market)

  • ACE Lab PC-3000 Flash: the industry standard for monolithic USB sticks and SSD chip-off.
  • Easy JTAG Plus: JTAG/ISP/eMMC, a lower-cost, mobile-focused set.
  • FlashCAT-USB Mk2: a general-purpose unit with TSOP-48 and BGA-152/162/169/221 adapters.
  • Medusa Pro II: a common choice for mobile technical services, ISP-focused.
  • Rusolut Visual NAND Reconstructor: used on the software side for FTL resolution.

Who performs it?

Chip-off is carried out by certified digital forensics laboratories, the cybercrime units of law enforcement, and private data recovery firms. To provide a service in this scope in Turkey, you need digital forensics expert authorization, a dedicated ESD-protected clean area, a calibrated soldering station, and hash-verifiable chain-of-evidence software.

Success rate and risk

If the NAND chip is physically intact, the success rate is above 90%. However, two risks stand out in modern devices:

  • Full disk encryption (Android FBE, iOS Secure Enclave, BitLocker, LUKS): even if a raw read is taken, the content is meaningless without the key.
  • On-chip encryption (Apple A7+, modern Samsung): chip-off practically fails; JTAG/ISP is not a solution either.

For this reason, in the cyber incident response playbook process, the evidence priority should be live memory (RAM) and the logical image, and chip-off should be planned as a last resort.

Legal framework

In Turkey, the collection of digital evidence is framed by CMK 134 and ISO/IEC 27037:2012. The integrity of the extracted image is verified with a hash (SHA-256 is recommended), and a report is signed in the presence of two witnesses. Otherwise, the evidence may be rejected in proceedings. In corporate incident management, it is advisable to run it in parallel with the KVKK 72-hour data breach notification template.

Cost

As of 2026, a chip-off operation for a single device in Turkey is roughly in the 8,000 to 35,000 TL range. The price rises when chip reballing and a special programmer adapter are required. In SSD multi-chip scenarios, the labor increases because each chip requires a separate read plus FTL resolution. For cost planning, you can refer to the RAID cost calculator tool; the same logic also applies to multi-chip SSDs.

Modern comparison: chip-off, JTAG, ISP

Method Invasive? Typical duration Encrypted device Hardware cost
Logical No 1-4 hours Limited Low
ISP Light (test pad soldering) 4-12 hours Difficult Medium
JTAG Light (TAP pins) 4-12 hours Difficult Medium
Chip-off High (chip removal) 8-48 hours Without the key, the data stays raw and encrypted High

The right method choice depends on the device's condition, manufacturer, and encryption scheme. In the decision matrix, the least invasive method is tried first; if it fails or the device is physically damaged, chip-off is brought into play.

Frequently Asked Questions (FAQ)

Can a device that has had chip-off performed be used again?

No. After the chip is removed, the device is not expected to regain its original function. In some cases, it is resoldered with reballing, but this operation affects the manufacturer's warranty and the device's reliability.

Does chip-off work on an iPhone?

On the iPhone 5s and later models, since the Secure Enclave keys are held inside the chip, even if chip-off takes a raw read, the content stays encrypted. For iPhone, logical methods such as GrayKey or Cellebrite are preferred today.

Can deleted data be recovered with chip-off?

Yes, if the TRIM command did not run on the NAND or if data remained in the overprovisioning area, deleted blocks can be recovered. On SSDs, if TRIM is active, deleted data is most likely unrecoverable.

What is the difference between JTAG and chip-off?

JTAG does not remove the chip; it takes a read through the test pins (TAP) on the PCB. It is less risky, but the success rate is low on encrypted or locked devices. Chip-off, on the other hand, physically removes the chip and provides raw access.

Is there a chip-off service provider in Turkey?

Yes. DSET carries out chip-off, JTAG, and ISP processes in an ISO/IEC 27037 compliant manner at its Hacettepe Teknokent Beytepe location. Contact: +90 536 662 38 09, [email protected].