MCU reverse engineering

Microcontroller Unlock - MikaTech

Our values and goals

About MikaTech

Time went fast, from the day we did our first 8051 MCU reverse engineering project in 1998, to the day we set up our million dollar reverse engineering lab in 2012, 14 years went by. Now we start our new business of embedded visual system development, hope we can serve another 10 years.

sign Peter Lee Co-Founder & CEO

ChipON MCU Hack

  • Mikatech ChipON MCU reverse engineer list:
  • C61F1 C61F120 C61F132 C61F21 C61F121 C61F133 C61F23 C61F301 C61F302 C61F182 C61F183 C61F184 C61F186 C61F187 ...

ChipON (Shanghai ChipON Micro-Electronic Co., Ltd.)

ChipON develops self-developed KungFu8 (8-bit) and KungFu32 (32-bit) core MCUs, covering automotive-grade, industrial general-purpose, low-power, touch-sensing dedicated series, plus special automotive ASIC chips. All models start with the prefix KF, and there is a dedicated automotive special chip line SMC.

Note: Each base model has dozens of sub-models distinguished by Flash/RAM capacity, pin count, package, temperature grade; only core representative base model series are listed below.

1. 8-bit KungFu8 Core MCU Series

1.1 KF8A Series (Automotive Grade 8-bit MCUs, AEC-Q100 qualified)

Core representative base models:

KF8A004, KF8A008, KF8A016, KF8A032, KF8A064

Features: Small package, wide voltage, wide temperature, high ESD resistance, for body control, lighting, small automotive actuators

1.2 KF8F Series (Industrial General High-Reliability 8-bit MCUs)

Core representative base models:

KF8F108, KF8F116, KF8F132, KF8F208, KF8F216, KF8F232, KF8F410, KF8F412, KF8F413, KF8F4156

Features: Rich analog peripherals (ADC, DAC, PWM, ECCP), high anti-interference, for home appliances, industrial control, power supply

1.3 KF8L Series (Ultra-Low Power 8-bit MCUs for AIoT & Battery Devices)

Core representative base models:

KF8L16Z, KF8L22Z, KF8L22Z20, KF8L32Z

Features: nA-level sleep current, wide operating voltage 1.8V–5.5V, for sensors, handheld devices, wireless low-power modules

1.4 KF8TS Series (Capacitive Touch Dedicated 8-bit MCUs)

Core representative base models:

KF8TS408, KF8TS416, KF8TS816

Features: Built-in high-stability touch detection engine, support touch slider/wheel/button, for smart panels, kitchen appliances, consumer touch control

2. 32-bit KungFu32 Core MCU Series

2.1 KF32A Series (Automotive Grade 32-bit Functional Safety MCUs)

Core representative base models:

KF32A136, KF32A140, KF32A141, KF32A146, KF32A150, KF32A151, KF32A152, KF32A156, KF32A158, KF32A250, KF32A251

Features: ISO 26262 functional safety support, multi-channel high-speed PWM, CAN/LIN bus, for automotive dashboard, chassis control, new energy vehicle auxiliary control

2.2 KF32F Series (High-Performance Industrial 32-bit MCUs)

Core representative base models:

KF32F030, KF32F050, KF32F100, KF32F120, KF32F150, KF32F200, KF32F407

Features: High main frequency, large Flash/RAM, DSP extension instructions, multi-channel high-precision analog peripherals, for inverter, servo control, industrial PLC

2.3 KF32L Series (Low-Power High-Performance 32-bit AIoT MCUs)

Core representative base models:

KF32L030, KF32L050, KF32L100, KF32L120

Features: Balanced computing performance & ultra-low power, rich communication interfaces (UART, I2C, SPI), for smart home, wearable devices, battery-powered industrial sensors

2.4 KF32LS Series (Single-Supply Low-Voltage 32-bit MCUs)

Core representative base models:

KF32LS030, KF32LS050, KF32LS100

Features: Optimized single 3.3V power domain, simplified power circuit, cost-effective low-power IoT control

3. Special Automotive Dedicated ASIC Chips (SMC Series)

Special customized automotive silicon chips for chassis braking, vehicle actuators, mass production vehicle-specific ICs:

SMC6008AF, SMC6012, SMC6024, SMC6032

Supplementary Important Notes

  1. Naming Rule Explanation
  2. Full device naming template: [Family][Capacity][Suffix]-[Package][Temperature]
  3. Example: KF8F4132QP → KF8F series, 32KB Flash, Q low-power variant, QFN package, Industrial temperature grade
  4. Suffix definition:
  • Z: Ultra-low power
  • Q: Low quiescent current
  • UN: DIP through-hole package
  • QP/QN: QFN surface mount package
  • SN: SOIC package
  1. Application Classification Summary
  • Automotive chips: KF8A, KF32A, SMC dedicated ASIC
  • Industrial control general chips: KF8F, KF32F
  • Low-power IoT/battery equipment: KF8L, KF32L, KF32LS
  • Touch control consumer electronics: KF8TS
  1. Tool & Ecosystem
  2. All ChipON chips support ChipON IDE, ChipON PRO programming software, KungFu Minipro debugger/programmer, compatible with standard JTAG/SWD download interfaces.
  3. Exclusion Statement
  4. This list only covers standard mass-produced off-the-shelf MCU and dedicated automotive ASICs; customer-specific customized mask ICs are not included. Thousands of full complete part numbers (differentiated by Flash size, pin count, package, temperature) cannot be fully enumerated one by one.

Pure English Document Version (Directly Copy & Save as Markdown/Word File)

Full Catalog of ChipON (Shanghai ChipON Micro-Electronic Co., Ltd.) Chip Product Families

Overview

ChipON Microelectronics designs microcontrollers based on proprietary KungFu8 (8-bit) and KungFu32 (32-bit) processor IP cores. Its product portfolio consists of automotive-grade MCUs, industrial general-purpose MCUs, ultra-low-power IoT MCUs, touch-sensing dedicated MCUs, and automotive special ASIC chips. All standard MCU models adopt the "KF" prefix, while automotive dedicated ASICs use the "SMC" naming prefix.

1. 8-bit KungFu8 Core Microcontroller Families

1.1 KF8A Automotive-Grade 8-bit MCUs (AEC-Q100 Certified)

Core representative models:

KF8A004, KF8A008, KF8A016, KF8A032, KF8A064

Key features: Miniature packages, wide operating voltage & temperature range, high ESD immunity, targeted for automotive body electronics, exterior lighting, small actuators.

1.2 KF8F Industrial High-Reliability General-Purpose 8-bit MCUs

Core representative models:

KF8F108, KF8F116, KF8F132, KF8F208, KF8F216, KF8F232, KF8F410, KF8F412, KF8F413, KF8F4156

Key features: Comprehensive analog peripherals (12-bit ADC, DAC, multi-channel PWM/ECCP), strong electromagnetic interference resistance, for household appliances, switching power supplies, small industrial controllers.

1.3 KF8L Ultra-Low Power 8-bit MCUs for Battery & AIoT Devices

Core representative models:

KF8L16Z, KF8L22Z, KF8L22Z20, KF8L32Z

Key features: Nanoampere-level sleep current, 1.8V~5.5V wide supply voltage, optimized for wireless sensors, handheld instruments, wearable electronics.

1.4 KF8TS Capacitive Touch Dedicated 8-bit MCUs

Core representative models:

KF8TS408, KF8TS416, KF8TS816

Key features: Integrated high-stability touch detection hardware engine, supports touch buttons, sliders and rotary wheels, widely used in smart control panels and kitchen appliances.

2. 32-bit KungFu32 Core Microcontroller Families

2.1 KF32A Automotive Functional Safety 32-bit MCUs

Core representative models:

KF32A136, KF32A140, KF32A141, KF32A146, KF32A150, KF32A151, KF32A152, KF32A156, KF32A158, KF32A250, KF32A251

Key features: ISO 26262 functional safety compliant, built-in CAN/LIN automotive communication interfaces, multi-channel high-resolution PWM, for automotive instrument clusters, chassis control systems, new energy vehicle auxiliary modules.

2.2 KF32F High-Performance Industrial 32-bit MCUs

Core representative models:

KF32F030, KF32F050, KF32F100, KF32F120, KF32F150, KF32F200, KF32F407

Key features: High main operating frequency, large Flash & SRAM capacity, DSP arithmetic extensions, high-speed analog peripherals, for frequency converters, servo drives, industrial PLC equipment.

2.3 KF32L Low-Power High-Performance 32-bit AIoT MCUs

Core representative models:

KF32L030, KF32L050, KF32L100, KF32L120

Key features: Balanced computing capability and ultra-low power consumption, rich serial communication peripherals (UART, I2C, SPI), suitable for smart home equipment, battery-powered industrial sensors.

2.4 KF32LS Single-Supply Low-Voltage 32-bit MCUs

Core representative models:

KF32LS030, KF32LS050, KF32LS100

Key features: Optimized single 3.3V power domain design, simplified peripheral power circuits, cost-effective solution for low-power IoT control terminals.

3. SMC Series Automotive Special ASIC Chips

Mass-production dedicated silicon ICs for automotive chassis braking and vehicle actuator systems:

SMC6008AF, SMC6012, SMC6024, SMC6032

General Supplementary Technical Notes

  1. Part Number Naming Specification
  2. Standard full ordering part number format: [Family Series][Flash Size][Power/Package Suffix]-[Package Code][Temperature Grade]
  3. Example: KF8F4132QP
  • KF8F: Base product family
  • 4132: Flash capacity & hardware resource variant
  • Q: Low quiescent current power variant
  • P: QFN surface-mount package

Common suffix definitions:

  • Z: Ultra-low standby power
  • Q: Low quiescent operating current
  • UN: DIP through-hole plastic package
  • QP / QN: QFN surface mount package
  • SN: SOIC narrow-body surface mount package
  1. Application Market Classification
  • Automotive electronics: KF8A, KF32A, SMC dedicated ASIC
  • Industrial automation & power control: KF8F, KF32F
  • Battery-powered IoT & wearable devices: KF8L, KF32L, KF32LS
  • Consumer touch control panels: KF8TS
  1. Development Tool Compatibility
  2. All ChipON MCU devices are fully supported by ChipON IDE integrated development environment, ChipON PRO programming software, and KungFu Minipro debug & programming adapter, with standard JTAG/SWD download interfaces.
  3. Scope Limitation
  4. This catalog only covers standard mass-produced off-the-shelf MCUs and dedicated automotive ASICs. Custom customer-specific mask ROM chips are excluded. Each base model has hundreds of complete orderable part numbers differentiated by flash size, GPIO count, package and temperature grade, which cannot be fully listed individually.

General Questions About Microcontroller Firmware Extraction


  • Is it safe to send payment to MikaTech ?

    If MikaTech was a bad company, you could find tons of bad reputations about its service on the internet over the 28 years history

    So, the answer is YES! We are good people.

    Why choose Mikatech, please click here to find out


  • Can Mikatech break ics not listed on this site ?

    Different chip manufacturers have different part numbers, but the inner core of the chip can be make with same technology, it would be quite impossible to list all the part numbers where our technology can apply such as MYSON, STK, FEELING, ANALOG, FUJITSU, NOVATEK, LG/HYNDAI.

    Also by the advancing of the technology, everyday we gain more and more experience and develope new methods for reverse engineering for different Intergated Circuit parts. Full list of Integrated Circuit part numbers which is within our scope of capability is always getting bigger, please contact us to find out.

  • Will my privacy be protected ?

    Mikatech Innovative Limited understands the importance of its clients' privacy. At the moment you contact Mikatech, the personal information from you will be put under protection by our management regulations which was developed by our years of practice, Mikatech uses these information to customize its service to you, it will never disclose these information to third party out of any reason.
    Every project we did, we will delete all the data, materials, and codes 60days after deliverig the files, it iwll protect us and protect your privacy.

  • Is it legal to get service from Mikatech ?

    Yes, it is totally legal.
    Mikatech deliver its reverse engineering services for educational purposes only, it can be illegal to use above mentioned services in some coutries or regions, please check your local laws. Mikatech does not take any responsibility in relation to the use of above mentioned services that may be considered illegal.


  • Voltage Glitching Countermeasures in Modern MCUs

    Voltage glitching is a common fault injection technique. The MCU lockbit lock must resist it. Modern MCUs incorporate brown-out detectors (BODs) that reset the chip if the supply drops below a threshold. But BODs have a reaction time. Fast glitches can escape detection. To counter this, MCUs use two-stage BODs. The first stage triggers a warning. The second stage triggers a hard reset. The warning can be used to abort sensitive operations. For example, if a voltage dip is detected during a read-out of an EEPROM processor, the operation is aborted. Similarly, dump flash and eeprom commands are ignored. Decapsulation and code recovery are not relevant here because glitching is non-invasive. But the MCU lockbit lock monitors the supply continuously. It uses an analog comparator. The comparator has a high bandwidth. It can detect glitches as short as 1 ns. This is much faster than typical BODs. The comparator output is connected to a digital filter. The filter rejects noise. If a genuine glitch is detected, the MCU enters a safe state. In that state, all memory access is blocked. The read-out of an EEPROM processor is disabled. Dump flash and eeprom is disabled. The lockbit lock is reinforced. Some MCUs also include a voltage monitor that checks the slew rate. A rapid drop indicates an attack. The monitor triggers an immediate shutdown. The shutdown includes a zeroization of all volatile memories. This prevents copy contents of crypto memory. Microcontroller reverse engineering will find an erased chip. Firmware extraction is impossible. Another countermeasure is to use an internal voltage regulator that filters out glitches. The regulator has a large capacitor. The capacitor stores enough charge to ride through short glitches. This makes the MCU immune to nanosecond-scale glitches. The MCU lockbit lock benefits from this regulated supply. Additionally, the clock generation circuit is monitored. A glitch on the clock can also be detected. The MCU uses a phase-locked loop (PLL) that locks to a reference. If the clock deviates, the PLL unlocks. The unlock signal triggers a reset. So clock glitches are also countered. The combination of voltage and clock monitoring makes the MCU lockbit lock very robust. However, attackers can use more sophisticated glitches. They can modulate the supply with a specific waveform. The waveform might fool the monitor. To prevent this, the monitor uses a window comparator. The supply must stay within a narrow window. If it goes outside, the alarm triggers. The window is set with hysteresis. This avoids false alarms from normal noise. The MCU lockbit lock is thus hardened. But no system is perfect. Attackers can also glitch the monitor itself. The monitor has its own power supply. That supply is derived from the main supply. So a glitch on the main supply also affects the monitor. The monitor's logic might misbehave. To avoid this, the monitor is implemented in analog circuitry. Analog circuits are less susceptible to digital glitches. They operate on continuous voltages. A glitch might still shift the reference. But the monitor uses a bandgap reference that is very stable. The bandgap is insensitive to supply variations. So even if the supply dips, the reference remains. Thus, the comparator output is reliable. The MCU lockbit lock relies on this comparator. In summary, voltage glitching countermeasures include fast BODs, slew-rate monitors, regulators, PLL locks, window comparators, and analog references. These make the MCU lockbit lock resistant to glitching attacks. The read-out of an EEPROM processor, dump flash and eeprom, decapsulation, copy contents, reverse engineering, and firmware extraction are all protected against fault injection.

    microcontroller_hack_time

    Years

    28 +
    microcontroller hack countries

    Countries

    110 +
    microcontroller attack clients

    Clients

    5000 +
    microcontroller projects unlocked

    Projects

    60000 +