Skip to main contentSkip to navigation
Lab Operational Since: 17 Years, 8 Months, 23 DaysFacility Status: Fully Operational & Accepting New Cases

Monolithic NVMe Data Recovery: Package Architecture

How an NVMe drive is packaged decides how it can be recovered. A multi-chip M.2 2280 carries a separate controller & separate NAND packages, so the NAND can be desoldered. A true monolithic BGA drive fuses the controller & NAND into one package, so the NAND can never be separated & the recovery path is board-level revival of the original silicon. We map the package first, then choose the method, at our Austin, TX lab.

Author01/12
Louis Rossmann
Written by
Louis Rossmann
Founder & Chief Technician
Updated 2026-07-24

If a failing NVMe drive holds data you need, stop applying power to it. Repeated power-ups push current through whatever is shorted on the package or board, so a single failed rail can spread to neighboring parts.

If the controller is partly alive, re-powering also risks it completing queued TRIM or Deallocate commands the host already issued, after which garbage collection erases the NAND cells. Pull the drive & call (512) 212-9111 for a free evaluation.

Call (512) 212-9111No data, no recovery feeFree evaluation, no diagnostic fees
Bluf02/12

What Does Monolithic Mean on an NVMe SSD?

On an NVMe SSD, monolithic describes how the controller & NAND are packaged. A multi-chip M.2 drive carries a separate controller chip & separate NAND packages on a circuit board, so the NAND can be desoldered on its own. A true monolithic BGA drive fuses the controller, NAND, & often DRAM into one package that cannot be separated.

That packaging choice sets the ceiling on recovery before any tool touches the drive. If the NAND is a separate package, chip-off is at least physically on the table. If the controller & NAND are fused in one BGA package, chip-off of the NAND alone is off the table for good, & the only paths run through the original controller.

So the first job on any dead NVMe drive is not to grab a tool. It is to identify the package. We read the drive's form factor & board layout during the free evaluation, then pick a method the physics allows.

Package Types03/12

Multi-Chip M.2 vs Single-Package BGA NVMe

There are two NVMe package types, & conflating them is the most common technical mistake on this topic. A multi-chip M.2 2280 has a controller BGA & one or more NAND BGAs as distinct parts on the PCB. A single-package BGA NVMe drive, the kind soldered into thin laptops & tablets, puts the controller, NAND, & often DRAM inside one sealed BGA package.

The difference is not cosmetic. It decides whether the NAND can ever be read as a separate chip, & therefore which recovery methods exist.

AttributeMulti-chip M.2 2280Single-package BGA NVMe
Physical layoutSeparate controller BGA + separate NAND package(s) on a PCBController, NAND, & often DRAM fused in one BGA package
Can the NAND be desoldered alone?Yes, the NAND package can be removed on its own (chip-off)No, there is no separate NAND chip to remove
What a raw read yieldsScrambled, ECC-encoded, unmapped data; ciphertext if hardware-encryptedNot separable; the NAND cannot be read apart from the controller
Recovery pathsRevive the original controller, or chip-off only on older unencrypted partsBoard repair in place, or reball the whole package onto an identical-model donor board

On the multi-chip M.2, the NAND can come off, but reading it means reversing the controller's XOR data scrambling, its LDPC error correction, & its flash translation layer. On a hardware-encrypted drive the media key is bound to the original controller, so a raw off-chip read returns ciphertext. Not every consumer NVMe drive runs hardware AES, but the scrambling & error correction are barriers on their own.

On the single-package BGA drive there is nothing to chip-off. If the fault is on the surrounding board, we repair it in place. If the board is damaged past repair but the package itself survives, the package reballs onto a donor board of the identical model.

Both keep the original controller doing the reading. For the general chip-off procedure on discrete NAND, see the chip-off NAND recovery page; for single-fused-die USB & microSD monoliths, which are a different form factor read through test pads, see the monolithic NAND recovery page.

Pcie Path04/12

Why a Dead NVMe Controller Leaves Nothing to Talk To

NVMe wires the controller's PCIe lanes straight to the CPU with no SATA or AHCI bridge in between. When the controller dies, no intermediary answers in its place, so no block device appears & no software can scan it. Reaching the data means a controlled PCIe link to the original controller, or reviving it first.

A SATA SSD sits behind a host bus adapter that speaks AHCI, an electrical buffer between the drive & the rest of the board. NVMe removes that layer for speed. The controller either trains its PCIe link & enumerates, or the host sees nothing at all.

Recovery software like R-Studio, Disk Drill, or PhotoRec has its place. It works when the drive is physically healthy & the operating system can already see it: a deleted file, a dropped partition, a formatted volume.

It has no path to a controller that never enumerated, because there is no block device to scan. That is the line between a software job & a lab job.

That is why a dead NVMe controller is not a software problem. The electrical & link-training side, the shorted rails, the severed differential pairs, & the LTSSM stalls that keep a controller from coming up, is covered in depth on the NVMe PCIe lane faults page & the PCIe lane diagnostics page. This page stays on the package architecture that dictates the method.

Pricing05/12

How Much Does Monolithic NVMe Recovery Cost?

Board-level repair that revives the original controller runs $600–$900. Firmware & FTL reconstruction on a live controller runs $900–$1,200. Reballing the package onto a donor board runs $1,200–$2,500. The tier is set by the fault: a board short, a corrupted translation layer, or a package that has to move to a donor.

The tier follows the fault, not the drama. Most dead NVMe drives are a board repair: we revive the power tree or the failed passive so the original controller boots, which is the tier that preserves the encryption key. When the controller powers but its firmware or FTL is corrupted, the work moves to system-area reconstruction with PC-3000 SSD.

Reballing onto a donor board is the last resort, used only when the original board is damaged past repair while the package survives. It requires a 50% deposit because donor parts are consumed in the attempt, & the donor cost is additional. A donor drive is a matching SSD used for its circuit board. Typical donor cost: $40–$100 for common models, $150–$300 for discontinued or rare controllers. No data recovered means no charge. +$100 rush fee to move to the front of the queue.

  1. Low complexity

    Simple Copy

    Your NVMe drive works, you just need the data moved off it

    Functional drive; data transfer to new media

    Rush available: +$100

    $200

    3-5 business days

  2. Low complexity

    File System Recovery

    Your NVMe drive isn't showing up, but it's not physically damaged

    File system corruption. Visible to recovery software but not to OS

    Starting price; final depends on complexity

    From $250

    2-4 weeks

  3. Medium complexity

    Circuit Board Repair

    Your NVMe drive won't power on or has shorted components

    PCB issues: failed voltage regulators, dead PMICs, shorted capacitors

    May require a donor drive (additional cost)

    $600–$900

    3-6 weeks

  4. Medium complexity

    Most Common

    Firmware Recovery

    Your NVMe drive is detected but shows the wrong name, wrong size, or no data

    Firmware corruption: ROM, modules, or system files corrupted

    Price depends on extent of bad areas in NAND

    $900–$1,200

    3-6 weeks

  5. High complexity

    PCB / NAND Swap

    Your NVMe drive's circuit board is severely damaged and requires NAND chip transplant to a donor PCB

    NAND swap onto donor PCB. Precision microsoldering and BGA rework required

    50% deposit required; donor drive cost additional

    50% deposit required

    $1,200–$2,500

    4-8 weeks

Hardware Repair vs. Software Locks

Our "no data, no fee" policy applies to hardware recovery. We do not bill for unsuccessful physical repairs. If we replace a hard drive read/write head assembly or repair a liquid-damaged logic board to a bootable state, the hardware repair is complete and standard rates apply. If data remains inaccessible due to user-configured software locks, a forgotten passcode, or a remote wipe command, the physical repair is still billable. We cannot bypass user encryption or activation locks.

No data, no fee. Free evaluation and firm quote before any paid work. Full guarantee details. NAND swap requires a 50% deposit because donor parts are consumed in the attempt.

Rush fee
+$100 rush fee to move to the front of the queue
Donor drives
A donor drive is a matching SSD used for its circuit board. Typical donor cost: $40–$100 for common models, $150–$300 for discontinued or rare controllers.
Target drive
The destination drive we copy recovered data onto. You can supply your own or we provide one at cost plus a small markup. All prices are plus applicable tax.

The full failure-class breakdown & the M.2 and U.2 form factors we work on live on the NVMe recovery overview. Published pricing, free diagnostics, & 4.9 stars across 1,837+ Google reviews back the work, all of it done in-house at a single Austin lab since 2008.

Why Reading Raw NAND Off a Dead NVMe Controller Is Hard

A raw NAND read is not a file system. The controller scrambles the data, adds LDPC error correction only its logic can decode, & holds the flash translation layer that maps logical sectors to physical pages. Reading a desoldered die needs a dedicated NAND reader, & a hardware-encrypted drive returns ciphertext without the original controller.

Say the drive is a multi-chip M.2 & the NAND package can physically come off. You are still nowhere near the files. The controller wrote that NAND through several transforms, & every one of them has to be undone in the exact order that specific controller used.

XOR data scrambling
A reversible XOR polynomial the controller applies before writing, to break up repetitive bit patterns that cause electrical interference & uneven wear. It is a reliability layer, not encryption, but the polynomial & controller architecture have to be known to reverse it.
LDPC error correction
Modern 3D TLC & QLC NAND relies on the controller's LDPC soft-decision engine, which re-reads cells at shifted reference voltages. A standalone reader does hard-decision reads only, so an offline dump carries uncorrectable bit flips even with no encryption present.
Flash translation layer (FTL)
The map from logical sectors to physical pages, interleaved across dies & planes. It lives in the controller's memory, so a raw dump is a fragmented, interleaved binary matrix until the spare-area metadata on every page is parsed to rebuild it.

Two ways exist to get at the raw NAND without a working controller, & both are why direct reads are the exception, not the rule:

  1. Desolder & read the die. Remove the NAND package & read it on a dedicated NAND reader. This works only where the NAND is a separate package, which rules out every single-package BGA drive.
  2. Tap the internal bus. Intercept the controller-to-NAND ONFI or Toggle bus with a bus-tap instrument. It is slow, controller-specific, & still leaves the scrambling, ECC, & FTL to reverse afterward.

Then the encryption wall. On a hardware-encrypted drive the media key is generated inside the original controller & wrapped by a key tied to that controller's hardware-unique root, so it never leaves the original silicon. A raw read returns ciphertext, & a donor controller of the same part number cannot unwrap it.

So the realistic path is to revive the original controller so it reads & decrypts its own NAND. Direct raw-NAND reconstruction is a last resort for older, unencrypted parts. None of this is platter work, so none of it needs a cleanroom.

Sata Vs Nvme06/12

Is Chip-Off Easier on a SATA SSD Than on an NVMe SSD?

Generally, yes. SATA SSDs tend to use simpler controller stacks with more mature tooling, so an older unencrypted SATA drive is more tractable for chip-off. NVMe raises the barrier on three fronts: hardware encryption is more common, the FTL is more complex, & packaging trends toward BGA & single-package monolithic designs that cannot be separated.

This is a tendency, not a law. Plenty of SATA drives are encrypted & plenty of NVMe drives are not. But when you line up the two interfaces, the NVMe side consistently pushes the work away from raw-NAND reading & toward reviving the original controller.

FactorSATA SSDNVMe SSD
Chip-off tooling maturityMore mature; simpler, older controller stacks are well mappedLess mature; complex, newer controllers with proprietary logic
Hardware encryptionPresent on some drives; many budget parts use only XOR scramblingMore commonly present, binding the media key to the controller
FTL complexitySimpler translation layers on many partsMore complex, higher-throughput interleaving to reverse
PackagingOften separate NAND packages that can be desolderedTrends to BGA & single-package designs that cannot be separated
Typical realistic pathChip-off viable on older unencrypted parts; else controller revivalRevive the original controller through board repair
Recovery Path07/12

Choosing the Recovery Path by Package & Controller

The method falls out of two questions: is the NAND separable, & is the controller alive or revivable. Package architecture answers the first. The controller family answers the second, because tool support for live-controller work is stratified.

  1. Controller powers & enumerates. If the drive trains a link, we image through the original controller with a PC-3000 Portable III on a controlled, stepped-down PCIe link, so it decrypts & descrambles its own NAND.
  2. Controller powers, firmware corrupted. If the link trains but the controller never asserts ready, PC-3000 SSD reconstructs the system area & FTL on the live controller before imaging.
  3. Controller dead, board repairable. Board-level microsoldering revives the power tree or failed passives so the original silicon boots. On an encrypted drive this is the recovery, because only that controller can decrypt its NAND.
  4. Board damaged past repair. On a multi-chip drive the NAND transplants to a donor PCB; on a single-package BGA drive the whole package reballs onto an identical-model donor board.

Live-controller firmware & FTL work depends on the controller family. PC-3000 SSD covers the Silicon Motion, Phison, & Marvell NVMe families on ACELab's supported-drive list.

The newest in-house Gen4 & Gen5 controller designs are not on that list, so those drives cannot get logical firmware work & instead depend on board-level revival of the original silicon. We confirm the exact controller during the free evaluation before quoting a method.

Apple Storage08/12

Apple T2 & M-Series NVMe Storage

Apple T2 & M-series Macs are the sharp edge of the encryption rule. The NAND sits as discrete BGA packages on the logic board, but the encryption key stays inside the Secure Enclave. A raw NAND read yields ciphertext, & a chip-off recovers nothing usable.

The only path is reviving the original board so the Secure Enclave can decrypt its own storage. We do not crack, defeat, or work around that security. A full treatment of Apple storage recovery lives on its own page; the point here is that the package holds discrete NAND yet still cannot be read off-chip, which is why board revival is the method.

Trim Barrier09/12

Can Deleted Files Be Recovered From an NVMe SSD?

Only if TRIM did not execute on those blocks. The host operating system issues the TRIM or NVMe Deallocate command; the controller unmaps those blocks & returns deterministic zeros when the addresses are read, then garbage collection erases the cells. Once a block is unmapped & collected, no software & no lab can recover it.

TRIM is a logical deallocate, not an instant physical erase, & the host is the one that issues it; the controller only executes what the operating system commands. The controller unmaps the blocks from its translation table & returns deterministic zeros (RZAT) when those addresses are read, then garbage collection erases the physical cells afterward.

Recovery of deleted files is only possible when TRIM did not run: the drive was pulled immediately, TRIM was disabled, or the file system does not support it. This is separate from a dead drive. A drive that failed physically before any deallocate ran still holds its data, waiting on a controller revival, not a deleted-file scan.

Lab Sequence10/12

The Lab Sequence for a Monolithic NVMe Drive

The sequence runs package-first, cheapest test before anything irreversible. Every step happens on an ESD-safe bench with the drive off any production host.

  1. Package identification. Read the form factor & board under a microscope to classify it as multi-chip M.2 or single-package BGA. This decides whether chip-off is even possible.
  2. Power-tree triage. Apply the rail through a current-limited supply & read the draw. A hard short points at a failed PMIC or passive before any link attempt.
  3. Thermal fault localization. Inject current on the shorted rail & find the hot part with a FLIR thermal camera.
  4. Board repair. Replace the shorted part with a Hakko FM-2032 on its FM-203 base, an Atten 862 hot air station for surrounding parts, & a Zhuo Mao BGA rework station for package-level work, then verify the rails.
  5. Controlled-link imaging. Bring up a PC-3000 Portable III, step the link down to a stable state, read the controller identity, & image through the original silicon so it decrypts its own NAND.
  6. Firmware path if the handshake fails. If the controller powers but never asserts ready, reconstruct the system area & FTL with PC-3000 SSD before imaging.

Board repair on an encrypted NVMe drive is the recovery, not a step before it. Only the original controller can decrypt its own NAND, so reviving that silicon is what puts the data back within reach.

Data Recovery Standards & Verification

Our Austin lab operates on a transparency-first model. We use industry-standard recovery tools, including PC-3000 and DeepSpar, combined with strict environmental controls to maintain drive integrity. This approach allows us to serve clients nationwide with consistent technical standards.

Open-drive work is performed in a ULPA-filtered laminar-flow bench, validated to 0.02 µm particle count, verified using TSI P-Trak instrumentation.

Transparent History

Serving clients nationwide via mail-in service since 2008. Our lead engineer holds PC-3000 and HEX Akademia certifications for hard drive firmware repair and mechanical recovery.

Media Coverage

Our repair work has been covered by The Wall Street Journal and Business Insider, with CBC News reporting on our pricing transparency. Louis Rossmann has testified in Right to Repair hearings in multiple states and founded the Repair Preservation Group.

Aligned Incentives

Our "No Data, No Charge" policy means we assume the risk of the recovery attempt, not the client.

We believe in proving standards rather than just stating them. We use TSI P-Trak instrumentation to verify that clean-air benchmarks are met before any drive is opened.

See our clean bench validation data and particle test video
Faq11/12

Frequently Asked Questions

What does monolithic mean on an NVMe SSD?
It describes how the controller and NAND are packaged. A multi-chip M.2 2280 drive carries a separate controller chip and one or more separate NAND packages soldered to a circuit board, so the NAND package can be desoldered on its own. A true monolithic BGA NVMe drive, the kind used in thin laptops and tablets, fuses the controller, the NAND, and often the DRAM into one BGA package, so the NAND cannot be separated from the controller. That packaging choice decides which recovery methods are even physically possible.
Can you chip-off the NAND from a single-package BGA NVMe drive?
No. On a single-package BGA drive the controller and NAND dies share one sealed package, so there is no separate NAND chip to desolder. Chip-off of the NAND alone is physically impossible. The two paths are board-level repair of the original package where it sits, or reballing the whole BGA package onto a donor board of the identical model when the surrounding circuit board is damaged past repair. Both paths keep the original controller in the loop, which matters because on a hardware-encrypted drive only that controller can decrypt its own NAND.
Why not skip a dead NVMe controller and read the NAND directly?
Because a raw NAND read is not a file system. Even when the NAND package can be desoldered, the controller scrambles the data with an XOR polynomial, layers on LDPC error correction that only its logic can decode, and holds the flash translation layer that maps logical sectors to physical pages. Reading a desoldered die needs a dedicated NAND reader, and the dump still has to be descrambled, ECC-corrected, and re-mapped. On a hardware-encrypted drive the media key is bound to the original controller, so the dump is ciphertext. Reviving the original controller so it reads and decrypts its own NAND is the realistic path.
Is chip-off easier on a SATA SSD than on an NVMe SSD?
Generally, yes. SATA SSDs tend to use simpler controller stacks and there is more mature tooling for them, so an older unencrypted SATA drive with a separate NAND package is more tractable for chip-off and reconstruction. NVMe raises the barrier on three fronts: hardware encryption is more common, the flash translation layer is more complex, and the packaging trends toward BGA and single-package monolithic designs that cannot be separated. None of that makes NVMe recovery impossible; it moves the work toward reviving the original controller rather than reading raw NAND.
Can data be recovered from the NVMe storage in a MacBook?
On Apple T2 and M-series Macs the NAND sits as discrete BGA packages, but the encryption key stays inside the Secure Enclave on the logic board, so a raw NAND read yields ciphertext and a chip-off recovers nothing usable. The only path is reviving the original board so the Secure Enclave can decrypt its own storage. We do not crack, defeat, or work around that security; a full treatment of Apple storage recovery lives on its own page.
How much does monolithic NVMe recovery cost?
The evaluation is free and there is no diagnostic fee. Board-level repair that revives the original controller in place runs $600–$900. If the controller powers but its firmware or FTL is corrupted, system-area reconstruction runs $900–$1,200. Reballing the package onto a donor board runs $1,200–$2,500 with a 50% deposit, donor cost additional. You get a firm quote before any paid work, and no data recovered means no charge. +$100 rush fee to move to the front of the queue.
Can deleted files be recovered from an NVMe SSD?
Only if TRIM did not execute on those blocks. The host operating system issues the TRIM or NVMe Deallocate command; the controller then unmaps those blocks from its translation table and returns deterministic zeros when the addresses are read, and garbage collection erases the physical cells shortly after. Once a block is unmapped and collected, no software and no lab can recover it. Recovery of deleted files is only possible when the drive was pulled immediately, TRIM was disabled, or the file system does not support TRIM.
Related12/12

NVMe drive dead or unreadable?

Free evaluation. We identify the package, revive the original controller through board-level repair, then image through it with a PC-3000 Portable III. Recovery from $600–$900. No data, no fee.

(512) 212-9111Mon-Fri 10am-6pm CT
No diagnostic fee
No data, no fee
4.9 stars, 1,837+ reviews