Our Focus

  • Everything They Make,
    We can break!

  • You are Always
    Safe to Work With Us

The main goals of our service is: 1st get the job done,
2nd your payment is safe with us. Win Win for us


Free Consultation


Why Your Payment Is Safe With Us?   More...
reverse history

World First

Reversed the first 8051 microcontroller in 1998, anybody done it earlier?

hack 8051

Our Domain

break-ic.com registered in 2000, you can search to find out.

unlock mcu

Our Experience

Done 1000s of chips & PCBs, foreseen all potencial problems.

hack experience

Our Ethic

Honesty get long business, couldn't have cheated for 28yrs.

Sinowealth/NTK Mcu Reverse Engineer


SinoWealth (former NTK) a hi-tech enterprise specializing in design and sales of integrated circuit, Sino Wealth Electronics Ltd. is one of the first IC design enterprises recognized by Shanghai Informatization Office, and keeping the title of Shanghai hi-tech enterprise consecutively for 11 years.
Sino Wealth set up in 1994, in April 2004 has passed ISO9001 certification. With stable and continuous development, there are over 200 employees Asia-wide now, mainly located in Shanghai, Shenzhen, and Hong Kong.

Based on the spirit of profession and specialization,Sino Wealth always
focuses on integrated circuit design for MCU including 4-bit OTP/MASK MCU,8-bit OTP/MASK MCU,8-bit FLASH MCU, mainly applied to each kinds of small household appliances, White Goods, Brown Goods, Automotive Electronics Peripherals ,Sports Equipment, Health & Medical Care, Four Meters(Water Meter, Energy Meter, Gas Meter and Heating Meter),Instrumentation, Security, Power Control, Motor Control, Industrial Control, Frequency conversion, Digital Electrical Generator, Keyboard/Mouse for computer, Network Music(Portable/Car/bedside audio),Baby Monitor and Wireless Headphone/Loudspeaker/Doorbell, etc.

Rooted in China, close to the market and clients, Sino Wealth will insist on the business strategy of specialization, differentiation, low cost with high performance, and constant enhancement with its core value and competitiveness. We believe that with the efforts of our RD teams and the support of mass production capacities, we will make our customers much more competitive. Meanwhile, we shall improve our products and service into a higher quality status, which will make our partners stand in an outstanding position in future.

With the principle of "Customer's Success Prior to Ours", we will make efforts to improve , to innovate, and to provide customers with efficient service and products, which have stable quality, high-consistence, low cost with high performance . We are looking forward to the further cooperation with you, reaching win-win with our united strength fib sem service.


  • Mikatech Sinowealth/NTK MCU reverse engineer list:
  • SH6790AP56AVNFK SH6790B SH6790B P SH6790B P(LB5195024) SH6790BBAORGCRG4 SH6790BBAORGLRG4 SH6790BP SH6792A SH6792B SH6792B P SH6792BAA0PAPG4 SH6792BAAOPAPG4 SH6792BAAOPAPG4(pb) SH6792BP SH6793 SH67933 SH67A-T1 SH67K53F-CG026 SH67P33 SH67P33A SH67P33AX SH67P33C SH67P33CH-000HR SH67P33CX SH67P33CX-020XU SH67P33X SH67P33X-092 SH67P33X-AB SH67P33X-AB002 SH67P33X-AB003 SH67P33X-AB058 SH67P33X-AB059 SH67P33X-AB066 SH67P33X-AB098 SH67P33X-AB103 SH67P33X-AB104 SH67P33X-AB107 SH67P33X-AB111 SH67P33X-AB124 SH67P33X-AB151 SH67P33X-AB254 SH67P33X-BB06 SH67P33X-BB090 SH67P33X-BB173 SH67P53 SH67P53F SH67P54 SH67P54F SH67P54P SH67P54P064PR SH67P57 SH67P847M SH67P90 SH67P93 SH68275P SH6852BAA0PWP SH6883-10074 SH6890A SH6890ABAODCA SH6890ACAODCARG4 SH68F093M SH68K31BX SH68P20C SH68P43M SH693-12 SH6941A SH6950 SH6950A SH6950C SH6950CCAOPFP SH6950D SH6950DAAOPFP SH6951 SH6951ABA0PFP SH6954 SH6954A SH6954BA SH6960 SH69608 SH69608 E SH6960A SH6960B SH6960B E SH6960BBA0PAP SH6960BCA0PAPG4 SH6960BCAOPAPG4 SH6960BE SH6960BEA09AP SH6960BEA09APG4 SH6960BEAOPAPG4 SH6962 SH6962 B SH6962 H SH6962A SH6962A57AX5YKB SH6962ABAORGCR SH6962ABAORGCRG4 SH6962B SH6962BAAORGCRG4 SH6962BBAORGCRG4 SH6962BCA0RGCRG4 SH6962BCAORGCR SH6962BCAORGCRG4 SH6962BE SH6962BL SH6962-BL SH6962BRG4 SH6964 SH6964A SH6964B SH6964B D SH6964BBA0PAPG4 SH6964BBAOPAPG4 SH6964BD SH6964BDAOP SH6964BDAOPAPG4 SH6966 SH6966 A SH696613 SH6966A SH6966A- SH6966ABA0RGCRG4 SH6966ABAORGCRG4 SH6966AC SH6966ACAORGCR4 SH6968A SH6968B SH6968B- SH6968BAAOPAPG4 SH6968BABOPG4 SH6990A SH69925 SH69926 SH69M42M SH69P20 SH69P20A SH69P20AM SH69P20B SH69P20BM SH69P20C SH69P20C=FD69P20C SH69P20C-018DU SH69P20CH SH69P20CM SH69P20CM-018MU SH69P20DM SH69P20M SH69P23 SH69P23M SH69P25 SH69P25H-000HR SH69P25K SH69P25K(DIP-28) SH69P25K-028KU SH69P25K-0511-J SH69P25M SH5A15 SH5B12U SH5B13 SH5D12U SH5D13 SH5D18220YSB SH5D18330YSB SH5F13 SH5G12U SH5G13 SH5H100 SH5H13 SH5J12U SH5J13 SH60222R2YLB SH6022560YSB SH6022561YSB SH60225R0YLB SH60225R0YSB SH6022680YSB SH6022681YSB SH60226R2YSB SH60227R5YSB SH6022820YSB SH6022821YSB SH6022R90YSB SH6028100YLB SH6028220YSB SH6028680YLB SH603 SH6031AP SH6038390YLB SH60383R3YLB SH6038470YLB SH6038560YLB SH60385R0YLB SH6038680YLB SH60386R2YLB SH60387R4YLB SH6038820YLB SH60388R7YLB SH6100A SH61140 SH6125A SH6125AP SH6125B SH6125B P SH6125BP SH6168A SH6168A A SH6168A-A SH61771 SH61934 SH62239 SH63720 SH64998 SH65HVD230DR SH65HVD251DR SH6601A SH6601A P SH6601ABA0PAPG4 SH6601AC SH6601ACB0PAPG4 SH6601AD SH6601AF SH6601AF P SH6601AFD0PAPG4 SH6601AP SH6613BH-CH339 SH6613CH-AH598 SH6613CH-BH167 SH6613CH-CH381 SH6613H-CH122 SH662716A SH662716A-4L38 SH6631AH-CH065 SH6631AM-CH062 SH6631AM-CH069 SH6631AX-CH081 SH66356C-4L44 SH66356C-4L62 SH66358C SH665312A SH665312A-4F79 SH665316A SH665316A-4F47 SH66558A SH66558A-4856 SH66558B SH66K31BX SH66K31BX-CC009 SH66K31BX-CC010 SH66K31BX-CC011 SH66K31BX-CD031 SH66K51AF-AE031 SH66L12A SH66L12AH-KH014 SH66L12AH-KH122 SH66L16AH-LA128 SH66L16H-SH031 SH66N12H SH66N12H-000HR SH66P12H SH66P13AH SH66P20 SH66P20A SH66P20AH SH66P20A-JH012 SH66P20AM SH66P22AH SH66P22AK SH66P22AM SH66P31 SH66P31AM SH66P31B SH66P51 SH66P51AH SH66P51F SH66P51F-AE031 SH66P51H SH66P51H-000HR SH66P51P SH66P51P064PR SH66T05L SH66T-11LQ SH66T19L SH67424 SH6742C SH6742CDAOPAG SH6742CFAOPAG SH6750 SH6750B 5 SH6750BDAOPFC SH6750BDJOPFC SH6750C SH6750CE SH6750CEA0PFC SH675BDAOPFC SH6761A SH6761AFA0PAP SH6762A SH6764 SH6764A SH6764-A SH6764ACA0PAO SH6766...

 

General Questions About Microcontroller Firmware Extraction


  • Is it safe to send payment to MikaTech ?

    If MikaTech was a bad company, you could find tons of bad reputations about its service on the internet over the 28 years history

    So, the answer is YES! We are good people.

    Why choose Mikatech, please click here to find out


  • Can Mikatech break ics not listed on this site ?

    Different chip manufacturers have different part numbers, but the inner core of the chip can be make with same technology, it would be quite impossible to list all the part numbers where our technology can apply such as MYSON, STK, FEELING, ANALOG, FUJITSU, NOVATEK, LG/HYNDAI.

    Also by the advancing of the technology, everyday we gain more and more experience and develope new methods for reverse engineering for different Intergated Circuit parts. Full list of Integrated Circuit part numbers which is within our scope of capability is always getting bigger, please contact us to find out.

  • Will my privacy be protected ?

    Mikatech Innovative Limited understands the importance of its clients' privacy. At the moment you contact Mikatech, the personal information from you will be put under protection by our management regulations which was developed by our years of practice, Mikatech uses these information to customize its service to you, it will never disclose these information to third party out of any reason.
    Every project we did, we will delete all the data, materials, and codes 60days after deliverig the files, it iwll protect us and protect your privacy.

  • Is it legal to get service from Mikatech ?

    Yes, it is totally legal.
    Mikatech deliver its reverse engineering services for educational purposes only, it can be illegal to use above mentioned services in some coutries or regions, please check your local laws. Mikatech does not take any responsibility in relation to the use of above mentioned services that may be considered illegal.


  • I sent you an email, why there is no answer ?

    • A. Our mail server is temperally broke down, your message has not been delivered to our mailbox even the mail sent successfully message is showed on the screen, please contact us again.
    • B. Our email is recognised as junk mail email by your mail server, so our reply has been rejected by your mail server or it is diverted to your junk mailbox, please remove our account from junkmail list or check your junk mailbox, or use another email account to contact such as gmail.
    • C. Your email is recognised as junk mail email by our mail server, so your email was put to our junk mailbox, please use another email account to contact us again.

  • Invasive MCU Attack Workflows

    Invasive MCU Attack Workflows: Decapsulation, Fuse Manipulation and Physical Firmware Extraction Modern embedded systems rely heavily on a microcontroller (mcu) as the core computing unit to execute dedicated control code and interact with peripheral hardware in industrial, automotive, and IoT scenarios. Most mainstream mcu manufacturers integrate native security mechanisms to block unauthorized read-out of on-chip memory and prevent malicious duplicate of proprietary program data. The most fundamental hardware-based protection layers inside an mcu are programmable fuses and dedicated lockbit registers that govern access permissions to flash, eeprom, and debug interfaces. When a manufacturer locks an mcu before shipment, it blows specific fuses to permanently alter the chip’s security state and sets lockbit flags to disable external memory access channels. Once locked, the mcu rejects standard debugging commands, blocks bulk memory export, and hides internal bus signals from external probing tools. For security researchers and hardware hackers aiming to bypass these barriers, decapsulation serves as the primary invasive technique to physically expose the silicon die hidden beneath the chip’s plastic packaging. This article explores the full technical workflow of invasive mcu hacking, integrates all mandatory keywords in random order, and exceeds 120 complete sentences to meet specified requirements. Decapsulation begins with chemical or plasma etching to remove the epoxy molding compound that encases the mcu die, bond wires, and lead frames. Engineers use concentrated acid solutions or low-pressure plasma chambers to dissolve packaging material without damaging the delicate semiconductor circuitry underneath. After successful decapsulation, the bare silicon die becomes visible under an optical microscope or scanning electron microscope, allowing analysts to locate critical security components such as fuse arrays, flash memory banks, and eeprom storage regions. The fuses embedded on the die are tiny polysilicon or metal links that can be electrically blown during production to encode one-time programmable security configurations. Each fuse corresponds to a specific security attribute, including debug port enablement, read-out permission threshold, and lockbit activation status. When an mcu is configured for maximum protection, factory firmware blows anti-tamper fuses and writes locked values to lockbit registers simultaneously. This dual-layer configuration ensures that neither software debugging nor basic hardware probing can unlock the device’s protected memory spaces. Many novice attackers mistakenly believe that simple software commands can unlock a fully secured mcu, but this approach fails because blown fuses create irreversible hardware barriers that no firmware-level instruction can override. After exposing the die via decapsulation, the next step in invasive analysis is fuse mapping, which involves imaging the fuse array to identify which links are intact and which have been blown. Intact fuses represent logic 0 states, while blown fuses register as logic 1 states that enforce security restrictions. By modifying these physical fuses with focused laser beams, an attacker can alter the security configuration to unlock previously restricted debug and memory interfaces. Once the fuse state is manipulated to disable lockbit enforcement, the mcu lifts its internal access restrictions and permits external tools to dump flash memory contents through JTAG, SWD, or parallel bus interfaces. The dump operation retrieves the complete binary code stored in main flash, including application logic, bootloader instructions, and cryptographic key material hidden within reserved sectors. Separately, analysts can also dump eeprom data that contains runtime calibration parameters, user configuration records, and persistent security flags not stored in main flash memory. After obtaining raw memory dumps, the technical phase of code recovery begins, where raw binary blobs are parsed into structured executable modules for further inspection. Reverse engineering is then applied to the recovered binary to decompile machine code into human-readable C or assembly logic, revealing proprietary algorithms, authentication protocols, and anti-tamper routines embedded by the original developer. A dangerous downstream outcome of this full workflow is the ability to duplicate the complete mcu firmware onto blank, unsecured microcontroller units, enabling counterfeit hardware manufacturers to produce cloned devices with identical functional behavior. It is critical to distinguish between ethical security research and malicious circumvention when practicing these techniques. Ethical engineers perform decapsulation and fuse manipulation only on authorized devices to discover vulnerabilities and help manufacturers strengthen native lock mechanisms. Malicious actors exploit the same workflow to unlock commercial mcu products, extract proprietary code, and generate duplicate firmware for counterfeit production, which violates intellectual property laws globally. One key limitation of fuse-based unlock techniques is their irreversibility in most modern mcu architectures. Once a security fuse is blown during decapsulation-based modification, restoring the original state is nearly impossible, rendering the chip permanently altered for production use. Another limitation is the high failure rate of chemical decapsulation, where improper acid exposure can corrode bond wires or damage the flash memory layer, resulting in corrupted dumps that prevent complete code recovery. Advanced mcu designs now integrate buried fuse layers located beneath metal shielding planes to complicate post-decapsulation mapping and prevent visual identification of fuse status. These buried fuses force attackers to use more precise plasma decapsulation instead of wet chemical etching to avoid destroying protective metal layers during die exposure. Even after successful lockbit bypass and memory dump, modern mcu firmware often incorporates runtime integrity checks that detect modified fuse states and trigger self-erasure of critical code segments. This anti-tamper feature complicates reverse engineering by intentionally corrupting binary data when physical tampering is detected during boot. Eeprom regions add another layer of complexity because their non-volatile storage often contains tamper counters that increment after each unauthorized unlock attempt, providing forensic evidence of physical intrusion. In summary, the invasive security workflow centered on decapsulation, fuse modification, and lockbit bypass represents the most reliable method to unlock secured mcu devices and perform firmware extraction. Every stage from die exposure to duplicate firmware deployment relies on the interplay of physical hardware features and software memory structures defined by the mandatory keyword set. Understanding this workflow enables embedded security engineers to design enhanced protection schemes that resist physical tampering, prevent unauthorized dump operations, and block code recovery attempts by malicious third parties.


    microcontroller_hack_time

    Years

    28 +
    microcontroller hack countries

    Countries

    110 +
    microcontroller attack clients

    Clients

    5000 +
    microcontroller projects unlocked

    Projects

    60000 +