Our Focus

  • Everything They Make,
    We can break!

  • You are Always
    Safe to Work With Us

The main goals of our service is: 1st get the job done,
2nd your payment is safe with us. Win Win for us


Free Consultation


Why Your Payment Is Safe With Us?   More...
reverse history

World First

Reversed the first 8051 microcontroller in 1998, anybody done it earlier?

hack 8051

Our Domain

break-ic.com registered in 2000, you can search to find out.

unlock mcu

Our Experience

Done 1000s of chips & PCBs, foreseen all potencial problems.

hack experience

Our Ethic

Honesty get long business, couldn't have cheated for 28yrs.

STC MCU Protection Unlock


STC offers a wide range of microcontrollers based on the 8051 architecture ranging in code density from 512 bytes to 62K bytes. The product line includes 8-bit microcontrollers based on the powerful, low-power Single-Cycle STC-51 core as well as MCS-51 industry standard socket drop-in devices and small footprint 8/16/18/20/28-pin derivatives and DIP/SOP/PLCC/SSOP/QFN packages. All manufactured in advanced Flash technologies by world famous semiconductor manufacturer TSMC. All members in this product line include ISP (In-System Programming) capability, while some also support IAP (In-Application Programming) mode which is able to modify the program ROM by the microcontroller itself.

There're many special features beside standard 80C51:
Internal Reset, RC Oscillator, WDT, Super Security, stand alone baud generater, low power

And also several application specified features:
ADC, PWM/PCA/DAC, SPI, up to 4 UARTs, up to 6 timers

STC single-cycle 8051 devices can be used in existing 80C51-based applications with binary-level code compatibility while substantially increasing performance by a factor of 6 to 12 times, up to 35MIPS.

Thanks to China's huge market, the cost STC 8051 micr controllers can beat any competitors without sacrifice quality and performance. This exciting family brings more features and peripherals to the users while reduce the cost dramatically.


  • Mikatech STC MCU reverse engineer list:
  • STC89Cxx Series MCU copy protection attack: STC89C51RC STC89C52RC STC89C53RC STC89C54RD+ STC89C58RD+ STC89C516RD STC89C516RD+ STC89C58RD ...

    STC89LExx/LVxx Series MCU copy protection attack: STC89LE51RC STC89LE52RC STC89LE53RC STC89LE54RD+ STC89LE58RD+ STC89LE516RD+ STC89LE516AD STC89LE516X2 STC89LE52AD STC89LE54AD STC89LE556AD STC89LE556X2 STC89LE58AD STC89LV516RD STC89LV58RD ...

    STC90Cxx Series MCU copy protection attack: STC90C51RC STC90C52RC STC90C53RC STC90LE51RC STC90LE52RC STC90LE53RC STC90C54RD+ STC90C58RD+ STC90C510RD+ STC90C512RD+ STC90C514RD+ STC90C516RD+ STC90LE54RD+ STC90LE58RD+ STC90LE510RD+ STC90LE512RD+ STC90LE514RD+ STC90LE516RD+ STC90C52AD STC90C54AD STC90C58AD STC90C514AD STC90C516AD STC90LE52AD STC90LE54AD STC90LE58AD STC90LE514AD STC90LE516AD ...

    STC10Fxx Series MCU copy protection read: STC10F04 STC10F04XE STC10F08 STC10F08XE STC10F12 STC10F12XE STC10F14X ...

    STC11Fxx Series MCU copy protection attack: STC11F01E STC11F02E STC11F03E STC11F04E STC11F05E IAP11F06 STC11F60XE STC11F56XE STC11F52XE STC11F48XE STC11F40XE STC11F32XE STC11F20XE STC11F16XE STC11F08XE STC11F62X ...

    STC12Cxx / STC12LExx Series MCU copy protection attack: STC12C1052 STC12C2052 STC12C4052 STC12C5052 STC12C5410 STC12C5410AD STC12C5402 STC12C5402AD STC12C5404 STC12C5404AD STC12C546 STC12C5406AD STC12C5408 STC12C5408AD STC12C5410 STC12C5410AD STC12C5412 STC12C5412RD STC12LE1052 STC12LE2052 STC12LE4052 STC12LE5052 STC12C5A08S2 STC12C5A16S2 STC12C5A32S2 STC12C5A40S2 STC12C5A48S2 STC12C5A52S2 STC12C5A56S2 STC12C5A60S2 IAP12C5A62S2 STC12LE5A08S2 STC12LE5A16S2 STC12LE5A32S2 STC12LE5A40S2 STC12LE5A48S2 STC12LE5A52S2 STC12LE5A56S2 STC12LE5A60S2 IAP12LE5A62S2 STC12C5A08AD STC12C5A16AD STC12C5A32AD STC12C5A40AD STC12C5A48AD STC12C5A52AD STC12C5A56AD STC12C5A60AD IAP12C5A62AD STC12LE5A08AD STC12LE5A16AD STC12LE5A32AD STC12LE5A40AD STC12LE5A48AD STC12LE5A52AD STC12LE5A56AD STC12LE5A60AD IAP12LE5A62AD STC12C5201AD STC12C5202AD STC12C5203AD STC12C5204AD STC12C5205AD STC12C5206AD STC12LE5201AD STC12LE5202AD STC12LE5203AD STC12LE5204AD STC12LE5205AD STC12LE5206AD STC12C5604AD STC12C5608AD STC12C5612AD STC12C5616AD STC12C5620AD STC12C5624AD STC12C5628AD STC12C5630AD STC12LE5604AD STC12LE5608AD STC12LE5612AD STC12LE5616AD STC12LE5620AD STC12LE5624AD STC12LE5628AD STC12LE5630AD ...

    STC15Fxx Series MCU copy protection read: STC15F100W STC15F101W STC15F102W STC15F104W STC15F2K08S2 STC15F2K16S2 STC15F2K24AS STC15F2K32S2 STC15F2K40S2 STC15F2K48AS STC15F2K48S2 STC15F2K56S2 STC15F2K60S STC15F2K60S2 IAP15F105W IAP15F2K61S IAP15F2K61S2 IAP15F2K61S2 IRC15F107W IRC15F107W IRC15F2K63S2 ...

  • STC15Lxx Series MCU unlock protection read: STC15L100W STC15L101W STC15L102W STC15L104W STC15L2K08S2 STC15L2K16S2 STC15L2K32S2 STC15L2K40S2 STC15L2K48S2 STC15L2K56S2 STC15L2K60S2 IAP15L105W IAP15L2K61S2 ...

  • STC15Wxx Series MCU copy protection dump: STC15W100 STC15W101 STC15W102 STC15W104 STC15W1K08PWM STC15W1K16PWM STC15W1K16S STC15W1K24S STC15W201S STC15W202S STC15W203S STC15W204S STC15W401AS STC15W402AS STC15W404AS STC15W404S STC15W408AS STC15W408S STC15W410S STC15W413AS STC15W4K16S4 STC15W4K32S4 STC15W4K40S4 STC15W4K48S4 STC15W4K56S4 IAP15W1K29S IAP15W205S IAP15W413S IAP15W4K58S4 IAP15W4K61S4 IRC15W107 IRC15W1K31 IRC15W207S IRC15W415AS IRC15W415S IRC15W4K63S4 ...

 

General Questions About Microcontroller Firmware Extraction


  • Is it safe to send payment to MikaTech ?

    If MikaTech was a bad company, you could find tons of bad reputations about its service on the internet over the 28 years history

    So, the answer is YES! We are good people.

    Why choose Mikatech, please click here to find out


  • Can Mikatech break ics not listed on this site ?

    Different chip manufacturers have different part numbers, but the inner core of the chip can be make with same technology, it would be quite impossible to list all the part numbers where our technology can apply such as MYSON, STK, FEELING, ANALOG, FUJITSU, NOVATEK, LG/HYNDAI.

    Also by the advancing of the technology, everyday we gain more and more experience and develope new methods for reverse engineering for different Intergated Circuit parts. Full list of Integrated Circuit part numbers which is within our scope of capability is always getting bigger, please contact us to find out.

  • Will my privacy be protected ?

    Mikatech Innovative Limited understands the importance of its clients' privacy. At the moment you contact Mikatech, the personal information from you will be put under protection by our management regulations which was developed by our years of practice, Mikatech uses these information to customize its service to you, it will never disclose these information to third party out of any reason.
    Every project we did, we will delete all the data, materials, and codes 60days after deliverig the files, it iwll protect us and protect your privacy.

  • Is it legal to get service from Mikatech ?

    Yes, it is totally legal.
    Mikatech deliver its reverse engineering services for educational purposes only, it can be illegal to use above mentioned services in some coutries or regions, please check your local laws. Mikatech does not take any responsibility in relation to the use of above mentioned services that may be considered illegal.


  • I sent you an email, why there is no answer ?

    • A. Our mail server is temperally broke down, your message has not been delivered to our mailbox even the mail sent successfully message is showed on the screen, please contact us again.
    • B. Our email is recognised as junk mail email by your mail server, so our reply has been rejected by your mail server or it is diverted to your junk mailbox, please remove our account from junkmail list or check your junk mailbox, or use another email account to contact such as gmail.
    • C. Your email is recognised as junk mail email by our mail server, so your email was put to our junk mailbox, please use another email account to contact us again.

  • Bypassing MCU Read-Out Locks Without Decapsulation

    Side-Channel Attack Vectors: Bypassing MCU Read-Out Locks Without Decapsulation. Traditional microcontroller (mcu) security defenses rely on fuse blowing, lockbit configuration, and read-out protection rules to block external firmware access, yet modern side-channel attacks can bypass these barriers without destructive decapsulation or permanent hardware modification. Side-channel techniques exploit unintended physical leakage from operating mcu devices, including power consumption traces, electromagnetic emissions, and timing variations, to infer protected memory data and bypass logical lock states. This article explains non-invasive side-channel workflows to unlock secured mcu units, dump restricted flash and eeprom data, achieve firmware extraction without die exposure, and analyze how reverse engineering leverages leaked traces for code recovery and duplicate firmware creation, embedding all mandatory keywords randomly across more than 120 complete sentences. Unlike chip-off attacks that require physical decapsulation of the mcu package, side-channel attacks operate on fully packaged, functional devices without altering the hardware structure permanently. The core principle behind side-channel vulnerabilities is that every computational operation executed by the microcontroller produces unique physical signatures correlated to processed data values and internal security state transitions. When an mcu enforces lockbit checks during boot, the power draw and electromagnetic radiation patterns subtly differ based on whether fuses are blown intact or whether read-out protection is active or disabled. Attackers capture these subtle differences to deduce hidden security configurations without direct fuse mapping or package removal. The most widely deployed side-channel method is power analysis, which uses high-resolution oscilloscopes to measure current draw across the mcu’s power supply pin during boot and memory access sequences. By profiling power traces, adversaries can identify the exact clock cycles where lockbit validation and fuse state sampling occur during the startup routine. Once these critical time windows are located, precision voltage glitching injects nanosecond-scale power dips to corrupt the security check computation, effectively forcing the mcu to unlock its debug and memory access interfaces prematurely. After bypassing the initial lock barrier, attackers initiate standard communication commands to dump flash memory contents over existing debug or serial interfaces that were previously restricted by read-out protection. Electromagnetic analysis extends this capability by capturing radio frequency emissions from the mcu die through near-field probes placed above the packaged device. EM leakage correlates directly to internal bus activity, allowing attackers to observe hidden memory read operations even when external debug ports are fully disabled by lockbit settings. This enables passive data collection that reconstructs eeprom storage contents without sending explicit read commands to the locked microcontroller. Timing analysis focuses on subtle execution delays introduced by conditional security branches in the bootloader code. When fuse states differ or lockbit values change, the boot sequence executes slightly more or fewer instruction cycles, creating measurable timing gaps that reveal hidden security configuration data. Attackers combine timing datasets with power traces to build comprehensive models of the mcu’s internal security logic, enabling reliable unlock sequences tailored to specific device models. A key advantage of side-channel unlock methods is their stealth; the device remains physically intact with no visible signs of tampering after the attack completes. Unlike decapsulation, which permanently alters chip packaging, glitching and trace analysis leave no forensic evidence that the mcu security state was modified during access. After unlocking the device via side-channel manipulation, adversaries perform full flash dump operations to retrieve executable program code and separate eeprom dump procedures to extract persistent configuration keys stored outside main memory. The recovered binary data undergoes structured code recovery workflows to repair fragmented memory segments and rebuild complete firmware images suitable for further inspection. Reverse engineering teams then analyze the side-channel recovered binaries to decompile proprietary logic, identify cryptographic implementations, and document anti-tamper routines embedded by original developers. The final adversarial objective is to duplicate the analyzed firmware onto blank microcontroller hardware, producing cloned devices that replicate the original functionality without authorization or licensing rights. To defend against side-channel attacks, mcu manufacturers integrate dedicated hardware countermeasures into silicon design and firmware runtime logic. Dynamic lockbit randomization alters security register read timing continuously during boot to break trace correlation between physical leakage and fuse state data. Noise injection circuits add controlled electromagnetic and power noise to mask distinctive operational signatures, preventing accurate trace profiling by external probes. Fuse state obfuscation introduces dummy sampling cycles during startup to mislead timing analysis tools about real security configuration values. Developers enhance firmware defenses by implementing constant-time execution for all lock validation routines, eliminating data-dependent timing variations that enable timing-based side-channel inference. Additionally, read-out protection logic is tightly coupled with on-chip voltage monitors that detect glitching attempts and trigger immediate temporary lock re-enforcement to block ongoing dump operations. Eeprom memory is further protected via interleaved storage schemes that scatter key bits across non-adjacent cells, making partial side-channel data reconstruction ineffective for complete code recovery. Many embedded developers underestimate side-channel risks because these attacks require advanced laboratory equipment and signal processing expertise compared to basic software exploits. However, affordable open-source tools now enable hobbyist and criminal actors to perform basic glitching and power analysis on mass-market mcu devices, lowering the technical barrier for unauthorized unlock and firmware extraction. It is critical to note that side-channel attacks cannot bypass properly implemented permanent fuse locks that physically disable core circuitry, as these hardware barriers exist outside the scope of runtime computational leakage. This makes complementary fuse programming essential alongside side-channel countermeasures for comprehensive mcu security. In summary, non-invasive side-channel attacks provide a powerful method to unlock protected microcontroller devices without decapsulation, exploiting physical leakage to bypass lockbit enforcement and read-out protection barriers. Defending against these vectors requires coordinated silicon-level hardening, firmware constant-time logic, and sensor-based tamper detection to block unauthorized flash and eeprom dump attempts, prevent covert firmware extraction, impede reverse engineering workflows, and stop malicious duplicate production of secured embedded devices.


    microcontroller_hack_time

    Years

    28 +
    microcontroller hack countries

    Countries

    110 +
    microcontroller attack clients

    Clients

    5000 +
    microcontroller projects unlocked

    Projects

    60000 +