In-depth technology research: finding new ways to recover data, accessing firmware, writing programs, reading bits off the platter, recovering data from dust.
Forum rules
Please
do not post questions about data recovery cases here (use
this forum instead). This forum is for topics on finding new ways to recover data. Accessing firmware, writing programs, reading bits off the platter, recovering data from dust...
September 11th, 2025, 9:06
It's been sometime since i posted something new here.. Anyway...
Group of Researchers (proud to be part of it)
found a way to extract the unique key from those WD MCU PCBs (charger, SpyGlass ...etc)
This means you don`t need to move/solder MCU from pcb to another.
Instead you can READ the key from the original PCB (even when its DEAD

) and write it back to DONOR PCB which is really Amazing..
I would like to Thank Mr. Leo Again for being part of this...
In 2026 will released.For now, the plan is the Commercial ver. of the Solution which i think MRT will lead...
September 11th, 2025, 9:24
Excellent work -well done.
September 11th, 2025, 10:16
Congrats!!!
I have one WD i need get one file, but all companies said me is unrecovery, let's hope some day can get it.
September 11th, 2025, 10:49
Very good news.
I just got a Charger WD drive that has bad patient pcb, with sata donor i was able to access to SA but user area resulted encrypted.
But fortunately this time i was able to repair patient usb pcb, so all data was recovered.
Is good to know that now there is someone here that is able to extract the key from MCU from this encrypted pcb, may be useful in future.
What can you say about cases where the MCU is damaged/lost?
It will be possible to hack encryption algorithm to generate the decryption key for each case if mcu is lost??
September 12th, 2025, 5:25
einstein9 wrote:It's been sometime since i posted something new here.. Anyway...
Group of Researchers (proud to be part of it)
found a way to extract the unique key from those WD MCU PCBs (charger, SpyGlass ...etc)
This means you don`t need to move/solder MCU from pcb to another.
Instead you can READ the key from the original PCB (even when its DEAD

) and write it back to DONOR PCB which is really Amazing..
I would like to Thank Mr. Leo Again for being part of this...
In 2026 will released.For now, the plan is the Commercial ver. of the Solution which i think MRT will lead...

well done,
Charger drives had no solution when it comes to encryption
for Spyglass i think encryption key can be extracted from SA as well.
September 13th, 2025, 2:07
Thank you guys...
wish you all the best
April 1st, 2026, 3:23
Is there any update ?
April 1st, 2026, 4:06
samstown wrote:Is there any update ?
Of course there is..
here is how the MCU unique code looks like..
close to figure out the equation with a shortcut to bypass
- Attachments
-

August 26th, 2026, 5:20
Hello Guys..
Finally WD MCU is really no more... we proudly announce that we are able to bypass WD MCU locked pcbs.
It took me some time to understand the MCU pinout but once you discover one the rest would be much easier to guess.
here is the breakdown results:
1st. there are many ways to bypass the MCU which are:
1- Move MCU from PCb to another --->> which is really not easy.
2- Thanks to my dear friend Mr. Leo Group who discovered a unique way to read he Unique Key and write it back to another PCB --->> not as easy as it looks but can be done
3- My Research which is based on the Chinese PCBs which converts USB to SATA. we have to remove few caps and jump wire few pins from patient to donor pcb
process takes few min. and you are set & ready to go. (probably will be released next year as a commercial bridge pcb by our Team)
The same concept works for 3.5" new WD PCBs which am still working on. WD 2.5" PCB are almost ready.
I advise you guys to think about
AI. and try to ask the right questions such as: "
inactive mcu pins"
All the best
Kuwait Data Recovery - Anwer Alkandri
- Attachments
-

August 26th, 2026, 7:35
Nice One!!
August 26th, 2026, 10:08
i might be dumber than average today, but i don't get the purpose behind all this... If you can make an arbitrary pcb decrypt the data only the native MCU could, what's the point in wiring the 2 pcbs together? How is this any easier than converting the orig pcb to sata?
August 26th, 2026, 11:43
pepe wrote:i might be dumber than average today, but i don't get the purpose behind all this... If you can make an arbitrary pcb decrypt the data only the native MCU could, what's the point in wiring the 2 pcbs together? How is this any easier than converting the orig pcb to sata?
If you have a Passport or a My Book, are there cases where the bridge IC or its firmware is unique?
If you convert the drive to SATA, the last 65536 sectors will be invisible. That's where the "SmartWare key" lives. Is it OK to use SA module 0x25 in such cases? That said, I have encountered several threads where module 0x25 is damaged and unreadable.
August 26th, 2026, 12:08
The above is for new SED drives, with encryption locked to MCU if i got it right. This is entierely different from USB bridge encryptions.
BTW, i never met the issue you described, accessing the drive through native sata intf gave access to the raw data area consisting of the encrypted user area, the VCD image and the key blob near the end of the LBA area. I cannot link your statements anywhere in my expertise, remember however, this might be my dumb day and i might also haven't seen everything on the planet yet...
August 26th, 2026, 12:47
There was a thread where someone (DR_Kiev?) stated that some drives have both levels of encryption, ie MCU key plus USB key.
As for reduced capacity, I have seen at least 3 cases.
I have described the issue here, with reference to an MRT video:
https://forum.hddguru.com/viewtopic.php?f=3&t=46244In this thread the SATA-connected My Book drive is reporting 65535 sectors less than its full IDEMA capacity:
https://forum.hddguru.com/viewtopic.php?p=274808#p274808
August 26th, 2026, 17:44
I hope this explains it better, although I don't know if it has any relevance to the present case.
https://forum.hddguru.com/viewtopic.php?f=11&t=388947814037168 -- full IDEMA capacity stored in all 5 capacity parameters in SA module 0x02
7813971633 -- IDEMA - 65535, capacity reported via SATA in Identify Device
7813969920 -- IDEMA - 67248, capacity reported by USB bridge, also in key sector in SA module 0x25
August 27th, 2026, 0:07
i start to see the problem i think, however, let's not hijack this thread coz it is about a different issue. Let's move back to the orig thread you created.
August 27th, 2026, 2:24
1st of all
@pclab Thank you
@pepe
Since you are an expert DR here.. what would you do when you face faulty/broken pcb beyond repair from those locked MCU drives?
"MCU locked means if you write native ROM to donor usb pcb data would be encrypted such as new charger/SpyG2 for example" ---->>@fzabkar
The point of what i did is simply
using Native MCU in donor PCB
without moving it
August 27th, 2026, 3:01
i would move it of course (as i already did). Not any more difficult than doing other smd work. There are a few things to pay attention to.
definitely not worth a single hour of researching how to wire these together and get them work that way. Just my thoughts.
i really hoped your work was about extracting the keys and methods from the crypto core...
pepe
August 27th, 2026, 3:17
Well for you moving is easier probably because your are highly skilled but when am talk about myself (and probably most of the people here) not easy
about your Question of extracting keys from MCU, Yes possible and i can do it but again Not as easy as 1,2,3 takes longer time if compared with my modest soldering skills
August 27th, 2026, 4:10
once you know how to do it, it should be simple like 1,2,3, write a little tool to extract and write back, this takes time but after that it is a few clicks... making such tool is a lot simpler than do this soldering every time... Moving the MCU is even more simple
Powered by phpBB © phpBB Group.