MCU reverse engineering

Microcontroller Unlock - MikaTech

Our values and goals

About MikaTech

Time went fast, from the day we did our first 8051 MCU reverse engineering project in 1998, to the day we set up our million dollar reverse engineering lab in 2012, 14 years went by. Now we start our new business of embedded visual system development, hope we can serve another 10 years.

sign Peter Lee Co-Founder & CEO

MXIC Microcontroller reverse engineering

Macronix International Co., Ltd, MXIC, is the largest and the most advanced supplier of ROM products worldwide. As one of the top world-class suppliers of nonvolatile memory semiconductors, we currently produce a wide range of ROM and NOR Flash products and solutions across various densities in embedded, consumer, and enterprise applications. Macronix is one of the very few suppliers offering a wide range of Serial Flash products from 512Kbit to 128Mbit densities. We also provide Flash products with extremely small packages as well as very thin packages in space-constrained applications to satisfy the market demand. In our ROM Business, XtraROM? products with 65-nanometer process have been delivered. Macronix also offers a Known Good Die (KGD) program for System In Package (SIP) solutions. Macronix owns one 8-inch wafer fab (Fab 2) and one 6-inch wafer fab (Fab 1). Macronix designs and fabricates its nonvolatile memory products in Fab 2. For increasing demands in the hot season, we also plan to utilize outsourced capacity. Fab 1 focuses on strategic foundry business for niche logic products. Macronix plans to restructure its 6-inch fab as an independent subsidiary company in the future.

 

  • Mikatech Macronix MCU reverse engineer list:
  • MX25L (2.7V–3.6V Standard 3V Flash) MX25L512, MX25L10, MX25L20, MX25L40, MX25L80, MX25L16, MX25L32, MX25L64, MX25L128, MX25L256, MX25L512, MX25L1G MX25V (2.3V–2.7V Mid Low-Voltage Flash) MX25V512, MX25V10, MX25V20, MX25V40, MX25V80, MX25V16, MX25V32, MX25V64, MX25V128, MX25V256 MX25U (1.65V–2.0V Ultra-Low Voltage Flash) MX25U512, MX25U10, MX25U20, MX25U40, MX25U80, MX25U16, MX25U32, MX25U64, MX25U128, MX25U256, MX25U512, MX25U1G Octal variants: MX25UMxxx, MX25UWxxx MX25R (Wide 1.65V–3.6V Ultra-Low Power Flash) MX25R20, MX25R40, MX25R80, MX25R16, MX25R32, MX25R64 MX25S (1.14V–1.6V 1.2V Ultra-Low Voltage Wearable Flash) MX25S80, MX25S16, MX25S32, MX25S64 2. MX66 High-Speed DTR Multi-I/O Serial NOR Flash MX66L (2.7V–3.6V High-Bandwidth Quad/Dual Flash) MX66L128, MX66L256, MX66L512, MX66L1G MX66U (1.7V–2.0V Low-Voltage High-Speed Multi-I/O Flash) MX66U128, MX66U256, MX66U512, MX66U1G Octal variants: MX66UMxxx, MX66UWxxx 3. MX29 Parallel NOR Flash (x8/x16 Parallel Bus) MX29LV 3V Low-Voltage Parallel NOR MX29LV400, MX29LV800, MX29LV160, MX29LV320, MX29LV640, MX29LV128, MX29LV256 MX29GL High-Density Wide-Temp Parallel NOR MX29GL640, MX29GL128, MX29GL256, MX29GL512, MX29GL1G 4. MX30 Serial SLC NAND Flash with Built-In ECC MX30LF Standard 3V SLC NAND MX30LF1G08, MX30LF1G18, MX30LF2G18, MX30LF2G28, MX30LF4G28 MX30UF 1.8V Low-Voltage SLC NAND MX30UF1G18, MX30UF2G18, MX30UF2G28, MX30UF4G28 5. MX52 Industrial & Automotive eMMC Embedded Storage MX52LM04, MX52LM08, MX52LM16, MX52LM32, MX52LM64 6. MX69 Stacked MCP Multi-Chip Package (NOR Flash + PSRAM) MX69GL64, MX69GL128 MX69N64, MX69N128, MX69N256 7. MX23 Mask ROM (Factory One-Time Programmed Read-Only Memory) MX23C16, MX23C32, MX23C64, MX23C128 MX23LV16, MX23LV32, MX23LV64.

 

General Questions About Microcontroller Firmware Extraction


  • Is it safe to send payment to MikaTech ?

    If MikaTech was a bad company, you could find tons of bad reputations about its service on the internet over the 28 years history

    So, the answer is YES! We are good people.

    Why choose Mikatech, please click here to find out


  • Can Mikatech break ics not listed on this site ?

    Different chip manufacturers have different part numbers, but the inner core of the chip can be make with same technology, it would be quite impossible to list all the part numbers where our technology can apply such as MYSON, STK, FEELING, ANALOG, FUJITSU, NOVATEK, LG/HYNDAI.

    Also by the advancing of the technology, everyday we gain more and more experience and develope new methods for reverse engineering for different Intergated Circuit parts. Full list of Integrated Circuit part numbers which is within our scope of capability is always getting bigger, please contact us to find out.

  • Will my privacy be protected ?

    Mikatech Innovative Limited understands the importance of its clients' privacy. At the moment you contact Mikatech, the personal information from you will be put under protection by our management regulations which was developed by our years of practice, Mikatech uses these information to customize its service to you, it will never disclose these information to third party out of any reason.
    Every project we did, we will delete all the data, materials, and codes 60days after deliverig the files, it iwll protect us and protect your privacy.

  • Is it legal to get service from Mikatech ?

    Yes, it is totally legal.
    Mikatech deliver its reverse engineering services for educational purposes only, it can be illegal to use above mentioned services in some coutries or regions, please check your local laws. Mikatech does not take any responsibility in relation to the use of above mentioned services that may be considered illegal.


  • Decapsulation and Physical Reverse Engineering of Microcontrollers

    When software-based attacks and fault injection techniques fail, the most determined adversaries turn to physical reverse engineering through decapsulation—the process of removing a microcontroller's packaging to expose the bare silicon die beneath. This invasive approach represents the ultimate escalation in the cat-and-mouse game of MCU security, allowing attackers to bypass virtually all software and firmware-level protections by directly inspecting the chip's hardware implementation. The decapsulation process typically involves the application of fuming nitric or sulfuric acid to dissolve the epoxy packaging while preserving the integrity of the underlying silicon. Once a microcontroller has been successfully decapsulated, attackers can employ a variety of imaging and probing techniques to extract firmware and configuration data. High-resolution optical microscopy can reveal the physical layout of memory arrays, including flash memory, EEPROM, and one-time programmable fuses. For microcontrollers that store security-critical information in mask ROM, researchers have developed sophisticated techniques for photographing the die, removing metal layers through chemical etching, and converting the resulting images into binary data. This approach, while destructive and time-consuming, is comprehensive and guaranteed to work regardless of the protection mechanisms implemented by the MCU manufacturer. The history of microcontroller decapsulation for reverse engineering includes notable successes such as the hacking of the PIC18F1320, where researchers identified metal shields covering security fuse transistors and developed techniques to reset security fuses without corrupting the flash code array. These physical attacks reveal a fundamental truth about hardware security: once an adversary has physical possession of a chip, no software-based protection can provide absolute assurance of confidentiality. The best that manufacturers can do is raise the cost and complexity of the attack to the point where it becomes economically unattractive for most adversaries. Despite the sophistication of decapsulation techniques, there are practical limitations. The process requires specialized equipment, chemical handling expertise, and significant time investment. Moreover, fully decapsulating a microcontroller typically destroys the device, making it unsuitable for subsequent dynamic analysis. However, for high-value targets—such as automotive ECUs, industrial controllers, or cryptographic devices—the investment in decapsulation and physical reverse engineering can be well justified. As the Internet of Things continues to proliferate and embedded systems become increasingly critical to infrastructure, the demand for physical security evaluation through decapsulation and die-level analysis will likely continue to grow.

    microcontroller_hack_time

    Years

    28 +
    microcontroller hack countries

    Countries

    110 +
    microcontroller attack clients

    Clients

    5000 +
    microcontroller projects unlocked

    Projects

    60000 +