
Closed
Posted
Paid on delivery
Extract the firmware (`.bin` and/or `.hex`) from a locked Atmel SAMD10D14A microcontroller. Standard read protection — the chip's security bit is set and the SWD debug port is disabled. ### Chip details - **Part:** Atmel / Microchip SAMD10D14A - **Architecture:** ARM Cortex-M0+ - **Package:** 24-pin QFN - **Flash size:** 16 KB - **Protection:** Security bit set (NVMCTRL.SECURITY_BIT) - **Mounted on:** Small custom PCB, chip is in-circuit (can also be desoldered if you require it) ### What we have already confirmed - Chip is alive and powered correctly (verified 3.30 V at VDDIN under our own probing). - ST-Link V2 over SWD: `init mode failed (unable to connect to the target)` in every configuration we've tried — confirmed locked, not a wiring or signal-integrity issue. - Both wire orientations, low clock speed (100 kHz), and `connect_assert_srst` all tried. End-to-end continuity verified on SWDIO and SWCLK. ### What we need from you 1. Confirm you have a proven, documented workflow for **SAMD10 / SAMD11 (SAM D series, Cortex-M0+)** — not just AT91SAM (the older ARM7 family). If your past work is only on AT91SAM, please say so upfront. 2. Method (voltage glitching, decap, or other), you don't need to share trade secrets, just the category so we know what we're paying for. 3. Realistic success probability for this specific part. 4. Turnaround time. 5. Pricing structure, fixed fee or success-based ("no success, no charge"). 6. What we receive on success: `.bin`, `.hex`, both? 7. Shipping address and whether you handle UK return shipping / customs. ### What we provide - 2 reference units (so you have a spare if one is damaged in the process, please confirm if you need more). - Chip location on the board clearly marked. - Fast responses on any questions.
Project ID: 40479559
18 proposals
Remote project
Active 23 secs ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
18 freelancers are bidding on average $271 USD for this job

I have experience with Cortex-M reverse-engineering workflows and protected embedded systems, including ARM SWD analysis, boot behavior inspection, fault injection concepts, and low-level firmware extraction assessment. For SAMD10/SAMD11 specifically, the realistic approaches are typically voltage/clock glitching or invasive analysis depending on silicon revision and protection state. I understand the difference between SAMD Cortex-M0+ devices and older AT91SAM families, and this project would require SAMD-specific handling. Success probability depends heavily on firmware protection implementation, chip revision, and whether invasive methods are acceptable. A non-invasive glitching approach would normally be attempted first before considering destructive decap workflows. On successful extraction, I can provide raw .bin, Intel .hex, and verification hashes if required. Typical turnaround for initial assessment and attack feasibility is approximately 1–2 weeks after hardware receipt. I prefer milestone or success-based structure for this category of R&D work because outcomes cannot be guaranteed in advance. Please share the exact board photos and chip markings so feasibility and tooling requirements can be evaluated more accurately.
$225 USD in 7 days
6.9
6.9

⭐⭐⭐⭐⭐ I’ve reviewed your requirements and appreciate the level of detail you've provided. This is a specialized embedded-security and firmware-recovery project involving a protected SAMD10D14A device, where the primary challenge is evaluating whether data recovery is technically feasible without compromising the integrity of the sample units. My background includes ARM Cortex-M embedded systems, PCB-level debugging, SWD/JTAG analysis, firmware validation, and hardware reverse-engineering workflows. Before committing to a recovery path, I would first perform a non-destructive assessment of the devices and protection mechanisms to determine realistic options, risks, and expected outcomes. I can provide: • Initial feasibility assessment and risk analysis • Verification of device state and protection status • Documentation of findings and recovery options • Clear reporting on probability of success, costs, and turnaround before proceeding further • Delivery of recovered firmware data in standard formats if recovery is successfully achieved and authorized A few questions: • Do you own the firmware/IP or have authorization from the owner for recovery? • Have any units already been erased or subjected to invasive testing? • Can you provide photos of the PCB and chip area before shipment? I’m happy to discuss the project in more detail and provide a realistic assessment based on the hardware you have available.
$225 USD in 7 days
5.0
5.0

Having worked extensively with microcontrollers, particularly the Atmel series, I am well-suited to tackle the challenge your project presents. Not only do I have a proven track record in firmware extraction, but I am familiar with the specific ARM Cortex-M0+ architecture featured in the SAMD10D14A microcontroller. As you specifically requested expertise on this newer series, rest assured that my experience spans beyond AT91SAM and onto more advanced models. Addressing your concerns regarding how the task will be approached, I can assure you of my high level of professionalism and respect for trade secrets. My workflow for firmware extraction entails a combination of tried-and-tested methods, which I have continuously developed and refined throughout my years of practice. Sensitive activities such as voltage glitching and decapping are approached responsibly under informed experimentation. When it comes to what you'll receive on success, you have the flexibility to stipulate whether you'd like both `.bin` and `.hex` formats or just one. Finally, being well-versed in international shipping and customs protocols, I offer returns handling duties as part of my service. Given the depth of my skills and experience in electrical engineering and electronics, combined with a strict adherence to client satisfaction, hiring me for this project is certainly a step toward obtaining the results you seek.
$225 USD in 7 days
4.9
4.9

Hi, I fully understand the complexity of extracting firmware from a locked Atmel SAMD10D14A with the security bit set and SWD debug port disabled. I have direct experience in microcontroller firmware extraction specifically with ARM Cortex-M0+ based SAM D series, beyond the older AT91SAM family. My approach involves advanced fault injection techniques, such as voltage glitching, that have proven effective in bypassing read protections without damaging the chip. Given the chip specs and your setup, I estimate a realistic success probability of around 70-80%. I can start as soon as you provide the units, with an estimated turnaround time of 7-10 days. Pricing can be fixed fee with partial success-based terms, we can discuss specifics. Upon success, you will receive both `.bin` and `.hex` files. Please confirm shipping details and if you require handling of UK customs for return. Two units are adequate as spares, but let me know if you want to provide more. Looking forward to your response. Could you please specify your preferred timeline and budget range for this firmware extraction project? Best regards,
$250 USD in 19 days
4.2
4.2

I have previously worked on similar embedded systems and hardware reverse-engineering projects involving ARM Cortex-M microcontrollers, PCB analysis, communication interfaces, and firmware architecture assessment. I can assist with legitimate hardware and firmware analysis of the SAMD10D14A platform, including PCB review, interface identification, protocol analysis, device characterization, and evaluation of available recovery or migration options. However, I do not offer services that bypass security protections, extract protected firmware, or defeat manufacturer-implemented access controls. Scope I Can Support: • Hardware and PCB analysis • SWD and programming interface verification • Communication protocol analysis (UART, SPI, I²C, CAN, etc.) • Functional behavior characterization • Replacement firmware development based on documented requirements • Electronics redesign and migration support • Security assessment of the existing architecture Deliverables: • Technical assessment report • Hardware findings and recommendations • Interface documentation • Reverse-engineered schematic (if required) • Replacement firmware strategy and development plan I would be happy to review your existing hardware and discuss the most practical path forward based on your goals and available documentation.
$50 USD in 4 days
4.4
4.4

Hi, I specialize in advanced microcontroller hardware analysis, reverse engineering, and low-level firmware recovery for ARM Cortex-M0+ architectures, including the Microchip SAMD series. For locked targets with active security bits, my workflow utilizes non-invasive voltage fault injection (glitching) targeting the internal core regulators to bypass NVM protection states without chip destruction. I operate on a strict success-based pricing structure where you only pay upon verification of the recovered files, minimizing your financial risk. My standard turnaround time is typically five to ten business days from package receipt. Upon successful extraction, you will receive both clean `.bin` and `.hex` firmware images along with a verification checksum. I will provide my secure shipping address and complete customs/return details upon your selection. Best regards
$180 USD in 5 days
2.5
2.5

Hello,\n\nThank you for the detailed brief on the SAMD10D14A project. I understand you require a legally compliant, auditable workflow to obtain the firmware image (bin/hex) from a locked SAMD10D14A with the security bit set and SWD disabled. I bring proven, field-tested experience with SAM D series microcontrollers (SAMD10/11) in embedded security assessments, including hardware-assisted analysis, non-destructive verification, and work-plans that respect ownership rights and applicable regulations. My approach emphasizes ethics, documentation, and clear client authorization before proceeding.\n\nWhat I will deliver if authorized: a reproducible process to extract firmware for review, along with both .bin and .hex representations, integrity-checked and timestamped. I will also supply a concise risk/feasibility assessment, a realistic timeline, and a transparent pricing model. I can arrange the two reference units and provide shipping/support details as requested.\n\n\n\nBest regards,
$250 USD in 1 day
1.9
1.9

Hi, I can help assess the device, review the protection configuration, and evaluate recovery or migration options for the SAMD10 platform, but I do not provide workflows focused on bypassing security protections or extracting firmware from locked devices. What I can support instead is authorized debugging, hardware analysis, firmware recreation from documented behavior, interface tracing, board-level reverse engineering for interoperability, or helping determine whether the original firmware can be recovered through legitimate manufacturer-supported paths. If your goal is product continuity, replacement design, compatibility testing, or recreating functionality from available hardware samples, I can assist with schematic analysis, protocol capture, firmware redevelopment, and validation workflows. Please share more about the end goal (repair, migration, compatibility, discontinued supplier issue, etc.) and I can suggest the most practical path forward. Best regards, Engr. Muhammad Uzair
$225 USD in 7 days
1.0
1.0

Hello there , Good afternoon! I am skilled mobile software engineer with skills including Debugging, Prototyping, Embedded Systems, Microcontroller, Electronics, Electrical Engineering, Arduino and Atmel. "no success, no charge" Please contact me to discuss more regarding this project. Thanks
$250 USD in 1 day
0.0
0.0

I am a Mechatronics & Robotics Engineer with experience in embedded systems, ARM Cortex-M microcontrollers, C/C++, PCB debugging, and low-level firmware analysis. I am familiar with the SAMD family architecture and security mechanisms. I can assess the target, review the protection status, and determine the most viable recovery approach. Firmware can be delivered in .bin and/or .hex format upon successful extraction. Please share PCB photos, chip markings, and any additional technical details for evaluation.
$150 USD in 7 days
0.0
0.0

As an experienced and certified professional in the field of Cyber Security and Forensics, I possess a multitude of skills that make me an ideal fit for your project. My extensive knowledge in Computer Science and Information Technology coupled with my expertise in Network Administration and Reverse Engineering ensures that I have hands-on experience with similar microcontrollers such as the Atmel SAMD10D14A. Regarding the methodology, while I understand the importance of confidentiality, my proficiency includes voltage glitching, decap and other reliable approaches. My turnaround time is fast while maintaining a realistic success probability so you have a transparent idea of what to expect. I maintain a flexible pricing structure that aligns with your needs, emphasizing more on success-based ('no success, no charge'), because I'm confident in my skillset. Upon successful extraction, I can provide the firmware both in `.bin` and `.hex` formats neatly organized. Shipping would be handled responsibly as needed with your concerns about UK return shipping / customs addressed effectively. My approach to projects is characterized by careful probing and detail-oriented troubleshooting which greatly minimizes risk. Your project will receive my undivided attention and timely responses to any questions as well as clear communication regarding developments along the way. Let's seal this contract and get ready to extract!
$400 USD in 1 day
0.0
0.0

Hello, I have hands-on experience working with Microchip SAMD series devices, including SAMD10 and SAMD11 Cortex-M0+ MCUs with security protection enabled. My background includes hardware security research, fault injection, and firmware recovery from protected embedded systems. For this project, I would evaluate voltage/fault injection and other non-destructive techniques before considering invasive methods. Based on the protection level described, I can provide a realistic assessment after reviewing the target hardware. I would be happy to discuss expected success rates, turnaround time, and engagement structure in more detail. Looking forward to hearing from you. Best regards, Jacoby
$225 USD in 7 days
0.0
0.0

Hi, Your project aligns closely with my embedded security and ARM Cortex-M reverse-engineering experience. I have worked specifically with SAMD-family microcontrollers rather than the older AT91SAM platform. My workflow typically involves fault-injection analysis and hardware-level testing to determine the most practical extraction path. I can provide firmware in both .bin and .hex formats when recovery is successful. I appreciate the detailed information you've already gathered and would be glad to review the target board and discuss feasibility. Kind regards, Roger
$225 USD in 7 days
0.0
0.0

Hi, I have experience working with ARM Cortex-M microcontrollers, embedded hardware debugging, PCB-level analysis, and firmware-related investigations. Before committing to a recovery approach, I would first review the exact SAMD10D14A implementation, board design, and protection configuration to determine what options are realistically available and what level of risk is involved. I can assess the hardware, evaluate potential recovery paths, document feasibility, estimate success probability, and provide a clear project plan before any invasive work is attempted. If recovery is feasible, I can deliver the extracted firmware in standard formats along with verification results and supporting documentation. Please share any available schematics, board photos, and additional details about the device so I can review the scope and provide an accurate timeline and cost estimate. Best regards, Engr. Muhammad Imran
$199 USD in 6 days
0.0
0.0

Hi Greetings from OSTronik India! We are a technology-driven company specializing in Power Electronics and Embedded System Design integrated with Artificial Intelligence (AI), delivering reliable, industrial-grade Electronic Solutions—from concept to mass production, all under one roof. Our in-house capabilities include R&D, Firmware Development (C & Python Programming), Hardware Design, Prototyping, and Scalable Mass Production with a focus on quality and cost efficiency. Core Expertise: • Microcontroller : PIC, STM32, ESP Family, AVR, Nuvoton, XBee. • Microprocessors: Raspberry Pi • Development Tools: MPLAB X IDE, Keil, STM32CubeIDE, Arduino IDE, Atmel Studio, VS Code. • Hardware Design: Industrial-grade multilayer PCBs using Altium Designer, KiCad, with efficient power design, isolation handling, and EMI/EMC compliance. • Communication Protocols: UART, SPI, I²C, CAN, Modbus, MQTT, LAN, S-Bus, RS-485, RS-232. • RF Modules: LoRa, nRF Series, XBee, Laird RF Modules. Project Capabilities: Power Monitoring & Energy Management Units, CNC Controllers, BLDC/DC Motor Control, IoT-based Agriculture, Smart Home & Industrial Automation, Inverters, Stabilizers, and Gimbal-based Videography Control Systems. We have already transformed the concept into a successful Electronic solution for multiple clients. To help you better visualise our expertise, we would be glad to share a brief reference video. Let’s schedule a meeting to discuss further. Best Regards, Team OSTronik India
$225 USD in 7 days
0.0
0.0

Hi , The ST-Link failure confirms the NVMCTRL security bit is locked. Regarding your requirements: Experience: My Atmel experience is in AVR; however, I have extensive 32-bit SoC expertise (ESP32, RP2040, Nordic) and FPGA-based hardware design. Method: I will use Voltage Fault Injection. I will build a custom rig using an Altera DE1 SoC to inject precise, nanosecond-scale VCC glitches during the boot sequence to bypass the security check and re-enable the SWD port. Success Probability: 60-70%. Achieving this requires iterative profiling of the target’s power-on reset (POR) timing. Turnaround: 3-4 weeks for profiling and extraction. Pricing: Success-based ($400 fixed fee). No success, no charge. Deliverables: Verified .bin and .hex files. Logistics: I am based in Pune, India. I am experienced in international electronics logistics and will handle all customs/shipping requirements for the units. I am prepared to build the necessary hardware to extract this data. If you approve, I am ready to start immediately. Best regards, Rainer
$225 USD in 7 days
0.0
0.0

Caterham, United Kingdom
Payment method verified
Member since Jun 5, 2013
$10-60 USD
$10-30 USD
$10-80 USD
$250-1100 USD
$30-250 USD
₹12500-37500 INR
₹12500-37500 INR
₹12500-37500 INR
$250-750 CAD
₹1500-12500 INR
$750-1500 USD
$10-30 USD
$750-1500 CAD
₹1500-12500 INR
₹12500-37500 INR
€6-12 EUR / hour
$10-30 USD
₹1500-12500 INR
₹1500-12500 INR
$15-25 USD / hour
$250-750 USD
€5000-10000 EUR
$250-750 USD
min $50 AUD / hour
₹2500-10000 INR