Board-Level Microsoldering | Austin, TX Lab | From $500 | No Data, No Fee
Samsung Galaxy Water Damage Data Recovery
Liquid on a Galaxy board is an electrochemical problem, and it eats the power circuitry long before it reaches anything holding your files. We strip the board, clean it ultrasonically to stop the reaction, replace what the corrosion consumed, and bring the phone back to a lock screen you can unlock yourself.

Does a Water-Damaged Galaxy Still Have Your Data?
Liquid bridging two points held at different voltages turns that patch of board into a galvanic cell, and metal starts leaving one side & plating out on the other. Pads that carried a rail stop carrying it, and shorts appear between things that were never connected.
Storage rarely participates in that. The flash package keeps what it holds without any help from the board around it, so a phone that has been sitting in a drawer since the day it went in the sink still holds the same ciphertext it held that afternoon.
On an encryption-era Galaxy the per-file keys are wrapped by the secure environment on the original processor, so lifting the storage package off the board and reading it in a socket returns ciphertext with no filesystem a carver can walk. The route to your photos is the opposite one: fix the board, let verified boot finish, & let you enter the credential that unwraps credential-encrypted storage on the original hardware.
Generation changes the bench work and not the ending. The Android & Samsung recovery hub lays out which models ship eMMC & which ship UFS, and neither answer moves the credential requirement one inch.
Stop Charging It and Keep It Powered Off
Most of the damage we see on liquid boards was added after the accident, by somebody checking whether the phone still worked. Applied voltage is what drives the dissolution, so each attempt is another few minutes of the reaction running at speed.
- Unplug it and leave it unplugged. A charger is a current source pointed at an electrolyte. Unpowered, the same board oxidizes slowly enough that arrival date is the variable that matters most.
- Quit pressing the power button to check. Every attempt energizes rails that are sitting in solution. The answer does not improve with repetition, & the board gets worse each time.
- Keep it out of Download Mode. Odin writes Samsung-signed firmware and has no documented path for reading your files out. The CSC binary in a firmware package decides whether userdata survives, & flashing a phone whose real fault is a corroded board can finish off what is left.
- Skip the drying advice. Rice, and every other passive drying ritual, addresses moisture in an air gap. The corrosion is under the BGA packages where the liquid wicked in, and drying the outside of a phone does nothing about a pad that has already dissolved.
- Write down what it went into. Salt water and pool water leave dissolved minerals behind as deposits once the water is gone, so the board carries a conductive residue that no amount of sitting removes. Knowing the source changes how the board gets cleaned.
- Get it on a bench quickly. Mail-in works from any state, evaluation costs nothing, and there is no diagnostic charge, so finding out what is left does not commit you to a repair.
Which Silicon Does the Liquid Reach First?
Samsung builds its own power silicon, and on the Exynos-architecture boards with standard PMIC layouts the work is split between two part families.
- S2MU and S2DOS sub-PMIC
- The input side of the board: USB interfacing, AFC and Power Delivery negotiation, & charge control. This is the group sitting closest to the port, so it is the group liquid entering there attacks first.
- S2MPS and S2MPB main PMIC
- Every core rail comes out of this family: the supplies the processor, the RAM, and the storage package run on. Corrosion that reaches here is deeper into the board and changes the conversation, though it is still component work.
Triage is a multimeter in diode mode, not software. Nothing enumerates on a board that will not power, so each rail gets read to ground & compared against a known-good board of the same model. A rail at or near 0.000 V is a hard short; a line doing its job answers with a few hundred millivolts.
One rail carries a different meaning from the rest. A short on VDD_CORE points at the processor itself, & on a file-based-encryption phone a destroyed processor is a destroyed key set, because the keys never lived anywhere else. That is the reading that turns a recovery into a conversation about limits.
The full intake order, from current draw at the port through rail mapping, is written out on Samsung won't turn on data recovery.
Board Symptoms and Their Data Prognosis
What the board does on a bench supply narrows the fault long before anything comes off it, and each behaviour carries its own answer about whether the data survived.
| What the board does | Circuit implicated | What it means for the data |
|---|---|---|
| Draws near zero from a known-good charger and never appears on a PC | The S2MU or S2DOS sub-PMIC, the USB-C assembly, or the charge control path around them | Best branch on this table. The fault never reached the processor or the storage, so the payload waits behind a component replacement |
| Draw comes up, then collapses, and one area of the board warms under the thermal camera | A shorted load on a rail the S2MPS or S2MPB main PMIC drives, or the main PMIC itself | Repairable. Which side of the rail is shorted decides whether the converter comes off or the load does |
| VDD_CORE reads at or near 0.000 V to ground after the board has been cleaned | The processor itself rather than anything feeding it | Worst branch. File-based encryption keeps the keys in the processor's secure hardware, so a destroyed processor takes them with it |
| Galaxy S22 Ultra generation: intermittent life, nothing visible on an external inspection | Liquid trapped inside the interposer layer between the two stacked boards, where the outside of the phone shows nothing | Repairable, mechanically. The stack gets separated so the shorts can be traced and cleaned between the boards |
| Foldable: no power, shutdowns past a fold angle, or false battery-temperature warnings | The hinge-routed flexible printed circuits carrying power rails and battery interconnects between the main board and the sub-board | Often good. The interconnects mimic a dead motherboard while both boards and the storage stay healthy |
Diode mode reports a voltage drop from a test point to ground, so the reading only means something next to a reference. A value that looks low on one model is normal on another, which is why the comparison is against a working board of the same model rather than against a number someone published.
Bench Sequence for a Corroded Galaxy Board
Order is most of the work. Probing a board before cleaning it measures the residue rather than the circuit, and energizing one before inspecting it can turn a two-component job into a much longer one.
- Disassemble and disconnect the battery. The cell is the one power source still attached to a phone nobody has plugged in, so it comes off before anything else happens.
- Pull the EMI shields. Those cans are soldered frames over the densest parts of the board, and liquid that got under one is liquid that cannot be reached with the shield in place. Leaving them on is how a board comes back three weeks later.
- Clean it ultrasonically. The ultrasonic cleaner halts the reaction and displaces what is trapped under the BGA packages, which is the one place the corrosion concentrates and the one place no wipe reaches.
- Inspect under the stereo microscope. Dendrites bridging pads, consumed traces, missing or blackened passives, and connector pins that no longer have plating on them. This is where the parts list for the repair comes from.
- Replace what the reaction consumed. Component work runs on a Hakko FM-2032 on an FM-203 or FX-951 base station; packages come off under Atten 862 hot air, & reballs run on a Zhuo Mao station. Severed traces get reconstructed with jumper wire under the scope.
- Power it on a leash. A current-limited DC supply feeds the board with a ceiling on what any remaining short is allowed to pull, and a FLIR thermal camera watches which part turns that current into heat. The part identifies itself instead of being guessed at.
- Boot it, then hand it to you. Once verified boot completes and the phone reaches the lock screen, the rest is yours: your PIN, pattern, or password unwraps credential-encrypted storage on the original hardware, and the files copy off normally.
Nothing in that sequence is a drying step, because drying is not the problem being solved. A board can be bone dry and still be dissolving.
All of it happens at one bench in Austin, so nothing gets handed to a partner lab for the parts of the job that are inconvenient.
Galaxy S22 Ultra Stacked Boards and Interposer Ingress
Boards on the S22 Ultra generation come as two layers joined by an interposer, which gives liquid somewhere to sit that an external inspection never finds. A phone can look clean on both faces while a short grows in the layer between them.
Repair means separating the stack, cleaning between the boards, and dealing with oxidized pads on the interposer connections rather than hunting for a component on a surface.
That same architecture carries a sibling failure class that shows up without any liquid. Thermal stress fractures BGA joints under the processor or inside the interposer, and the phone loops at the boot splash or dies intermittently.
The tell the board-repair community documents is temperature: chilling the phone contracts the stack and can re-bridge a fractured joint for a few minutes. That window is a diagnostic clue and a chance to copy files, never a repair, & the lasting path is separation and a reball.
None of this comes from a Samsung defect notice. It is board-repair community consensus, written up by the people opening these phones, and nobody has published how often it happens. Samsung Galaxy boot loop recovery covers the thermal half of that class in full.
Hinge Ingress on Galaxy Z Fold and Z Flip Phones
Foldable ingress ratings run behind the slab flagships, and the spec sheet is worth reading before assuming a phone was sealed.
| Generation | Ingress rating | What the rating certifies |
|---|---|---|
| Fold 1, Fold 2, and the original Z Flip | None | No certified protection against either water or dust |
| Fold 3 and Flip 3 through Fold 5 and Flip 5 | IPX8 | Water resistance tested; the X records zero certified dust protection |
| Fold 6 and Flip 6 | IP48 | The first certified dust rating on a Galaxy foldable, alongside the water rating |
No Galaxy foldable through that generation carries an IP68 rating, which is the number people assume they bought. Dust rides the hinge into the chassis on the earlier models, wears the folding interconnects, and presses into the inner OLED from its unsupported underside.
Liquid uses the same opening & finds a different board layout on the other side. A Fold or Flip splits its electronics across a main board and a sub-board, and every power rail, battery interconnect, display signal, and data line between the halves crosses the hinge on flexible printed circuits. One battery cell sits in each half.
Two consequences follow on the bench. Liquid entering at the hinge spreads across the main board, the sub-board, and the display driver at once, so short tracing runs across more than one board instead of one. And a worn or corroded hinge interconnect presents as total power loss, charging failure, shutdowns past a certain fold angle, or a false battery-temperature warning, all of which read like a dead motherboard while both boards are alive.
Reaching any of that means removing displays that teardowns treat as destroyable during disassembly, so a foldable power job gets quoted with that liability stated before work starts rather than after. An inner panel that has gone black along the crease is, in the typical documented case, a display fault: the boards are running and the encrypted data is intact behind the dead screen.
What Can Desktop Recovery Software Do for a Wet Galaxy?
The demo scans are honest about what they are once you know what to look for. A tool listing photos off a working phone is listing files that still exist, plus cached thumbnails it never had to decrypt anything to reach.
Three separate barriers sit between that demo and a liquid-damaged handset. There is no block device to read, because credential-encrypted file keys only exist in kernel memory after the owner has unlocked the phone.
USB debugging has to have been switched on before the accident. And an ADB session needs the host's RSA key approved in a dialog on an unlocked screen, which is a screen this phone no longer has.
Deleted files are a separate question with a harder answer. Under file-based encryption each file carries its own key, deletion destroys that key, and the storage layer trims the blocks, so permanently deleted internal-storage data is not coming back from any scan. A factory reset does the same thing to everything at once.
What does work sits off the handset or in an app-level holding area, & it is worth checking before a board ever ships:
- Samsung Gallery Trash holds recently deleted photos for about 30 days, because those items were never actually deleted. It needs a working, unlocked phone.
- The unified My Files trash in One UI 6 and later also holds recently deleted Gallery and Voice Recorder items, with the same requirement of a phone you can get into.
- Google Photos and OneDrive trash live on a server, so a drowned phone has no vote in whether you can reach them.
- Existing Smart Switch backups sit on a PC or another device and predate the accident.
- Older Samsung Cloud backups restore without the handset. Backups made under Knox Matrix Enhanced Data Protection in One UI 6.1 and later are end-to-end encrypted, and those need the recovery code you were given when you turned it on.
If one of those already has your photos, we will say so and charge you nothing for the sentence. Board work is what is left when they do not.
Some Liquid-Damaged Boards Are Past Recovery
A lab earns its credibility by naming the states where the answer is no, and we would rather hand you that answer at intake than three weeks later with an invoice attached.
- Cracked or electrically destroyed processor die
- The hardware-held keys died with it, so moving the storage package to a donor board produces a phone with unreadable ciphertext in it.
- Dead UFS controller on a file-based-encryption phone
- The host cannot query the device descriptor, and the payload behind that controller is hardware encrypted, so there is no fallback of the kind an older eMMC board sometimes allows. That older class has its own treatment on eMMC data recovery.
- A factory reset that already happened
- Key material for every file is destroyed at once, and no scan reverses it.
- A tripped Knox warranty fuse
- The fuse is one-way, and a tripped one withholds the Secure Folder container keys permanently. Everything outside that container is a separate question.
- An end-to-end-encrypted cloud backup with no recovery code
- Samsung holds ciphertext by design in that configuration, and the code is the only thing that opens it.
Those are cryptography and physics rather than effort levels, so no price and no tool moves any of them.
Between repair and terminal sits the transplant, and it is narrower than the version people are usually quoted. The storage chip never moves alone.
A viable transplant moves the processor with its package-on-package RAM and the storage package together as a paired set, and on Galaxy S21 and newer flagships the discrete secure element goes with them or the repaired phone boots and then rejects the correct PIN. Budget models such as the A05 carry no such element to move.
The storage is bound to the original processor through its Replay Protected Memory Block, which is why a cloned or substituted package is rejected outright rather than merely unreadable. Samsung's heavy underfill turns the removal itself into a long job before any reballing starts, and it quotes from the same range as a charging-circuit repair.
Your credential is the last boundary, and it is not one we pretend to move. Keys for credential-encrypted storage come from what you know combined with secrets the secure hardware releases, wrong attempts are throttled inside that hardware by Gatekeeper and Weaver, and a lock, Factory Reset Protection, or the Knox fuse is not something this bench removes or works around.
What Does Galaxy Water Damage Recovery Cost?
No data, no fee. Free evaluation. No diagnostic charges. The number is quoted firm after the board has been cleaned and measured, so nothing is authorized against an estimate, and a paired-set transplant does not add a surcharge on top of it.
Every step happens in-house at 2410 San Antonio Street in Austin, Texas, in a shop that has been doing board-level work since 2008. It is one location that has never franchised or outsourced a job. A board that comes back terminal leaves you owing nothing.
Drop it off during business hours, or put it in the mail from any state. A free evaluation comes first, then a firm number, then your decision.
Data Recovery Standards & Verification
Our Austin lab operates on a transparency-first model. We use industry-standard recovery tools, including PC-3000 and DeepSpar, combined with strict environmental controls to maintain drive integrity. This approach allows us to serve clients nationwide with consistent technical standards.
Open-drive work is performed in a ULPA-filtered laminar-flow bench, validated to 0.02 µm particle count, verified using TSI P-Trak instrumentation.
Transparent History
Serving clients nationwide via mail-in service since 2008. Our lead engineer holds PC-3000 and HEX Akademia certifications for hard drive firmware repair and mechanical recovery.
Media Coverage
Our repair work has been covered by The Wall Street Journal and Business Insider, with CBC News reporting on our pricing transparency. Louis Rossmann has testified in Right to Repair hearings in multiple states and founded the Repair Preservation Group.
Aligned Incentives
Our "No Data, No Charge" policy means we assume the risk of the recovery attempt, not the client.
Technical Oversight
Louis Rossmann
Our engineers review all lab protocols to maintain technical accuracy and honest service. Since 2008, his focus has been on clear technical communication and accurate diagnostics rather than sales-driven explanations.
We believe in proving standards rather than just stating them. We use TSI P-Trak instrumentation to verify that clean-air benchmarks are met before any drive is opened.
See our clean bench validation data and particle test videoQuestions About Liquid-Damaged Galaxy Phones
Does putting a wet Galaxy in rice save it?
My Galaxy got wet and still turns on. Do I need to do anything?
Does a tripped liquid detection indicator affect data recovery?
Is salt water worse than tap water?
Can you get data off a Galaxy that never powered on again?
Do you need my PIN, pattern, or password?
What does liquid-damage data recovery cost on a Galaxy?
Related services
Related Samsung Recovery Pages
Generations, encryption reality, and the rest of the fault catalog
Current draw at the port and the per-rail prognosis map
Thermal fracture, interposer cracking, and Odin flash semantics
Controller death and what sits behind it on legacy boards
How to ship a liquid-damaged phone to the Austin lab
What happens when a recovery does not produce data
Phone went in the water?
Take it off the charger and send it before more current runs through the corrosion. Evaluation is free, the quote is firm, and a recovery that produces nothing is not billed.