2026-10-23 –, Redbud C
Firmware extraction is a critical first step in hardware security assessments, and eMMC storage is one of the most commonly encountered targets across "higher-end" embedded AI and IoT devices. This talk covers two practical approaches to extracting firmware from eMMC chips: in-circuit lead tapping and full chip-off removal. We walk through identifying eMMC pinouts, soldering to exposed test points, and interfacing with affordable readers for in-circuit extraction, then cover hot air desoldering, BGA reballing, and reading bare chips via socket adapters for chip-off. For each method, we discuss tooling, trade-offs, failure modes, and when to choose one approach over the other based on board layout, risk tolerance, and common obstacles like epoxy potting and locked partitions.
Overview and Motivation
Embedded devices increasingly rely on eMMC (embedded MultiMediaCard) for onboard storage, making it a common target during hardware security engagements. This talk is about eMMC extraction and how it should be a primary tool in every hardware researcher's workflow.
Talk Structure (40 Minutes)
Part 1: eMMC Fundamentals (5 minutes)
The talk opens with a concise primer on eMMC architecture relevant to extraction. We cover the MMC protocol basics (CMD, DAT0-DAT7, CLK), the standard JEDEC pinouts for common BGA-153 and BGA-169 packages, and how eMMC differs from other flash targets like raw NAND and NOR. We also discuss the eMMC partition structure, including the boot partitions (BOOT0/BOOT1), RPMB, and the user data area, since understanding partition layout directly affects what data you actually recover.
Part 2: In-Circuit Lead Tapping (15 minutes)
This section covers non-destructive, in-circuit extraction. We walk through:
- Identifying eMMC chips on a target board using package markings, datasheets, and visual inspection.
- Locating accessible signal points. Many manufacturers expose CMD, CLK, and DAT0 lines on test pads, vias, or breakout headers. We cover techniques for tracing signals from the eMMC BGA to accessible points on the PCB, including the use of board schematics when available and visual/multimeter tracing when they are not.
- Soldering fine-gauge wire (typically 30-36 AWG) to test points and connecting to a reader. We discuss specific tools: the Exploitee.rs eMMC adapter, the Easy JTAG box, SD card readers with CMD line access, and low-cost FPGA-based alternatives.
- Performing the actual read using standard tools (e.g., dd over a block device, or vendor-specific software), including dealing with bus width negotiation and clock speed tuning for stability.
- Troubleshooting common issues: cold solder joints on fine-pitch pads, signal integrity problems from long leads, and VCC supply considerations when the device is partially powered.
Part 3: Chip-Off Extraction (15 minutes)
This section covers destructive chip removal for cases where in-circuit access is not feasible. We cover:
- When chip-off is the right (or only) choice: epoxy-potted assemblies, boards with no accessible test points, multi-layer PCBs with buried traces, or situations where the host SoC locks the eMMC bus during normal operation.
- Hot air rework station setup and technique for BGA removal. We discuss temperature profiles, appropriate nozzle selection, use of low-temperature solder paste or alloy to lower reflow temps, and board preheating to reduce thermal shock.
- Post-removal chip preparation: cleaning residual solder from BGA pads, inspection under magnification for lifted or damaged pads, and reballing with stencils and solder spheres when the chip will be placed in a socket adapter.
- Reading the bare chip using BGA socket adapters (such as the Allsocket or generic BGA-153/169 pogo pin sockets) connected to an SD-to-eMMC reader or a dedicated programmer.
- Failure modes and recovery: dealing with chips that refuse to enumerate after removal, identifying heat damage versus connection issues, and retry strategies.
Photos and video of actual chip-off procedures on real target hardware will be shown throughout.
Part 4: Decision Framework and Practical Considerations (5 minutes)
The final section provides a decision framework for choosing between the two methods. Key factors include:
- Is the engagement non-destructive (e.g., must the device be returned functional)?
- Are test points or signal traces accessible on the board?
- Is the eMMC bus locked or restricted by the host processor during runtime?
- Time and equipment constraints in the field versus a lab environment.
We also cover initial triage of extracted images (partition table identification, filesystem mounting, binwalk analysis).
What the Audience Will Take Away
Attendees will leave with a practical, repeatable methodology for eMMC firmware extraction.
I'm Isaiah, a hardware security researcher with six years of experience breaking things for fun and occasionally for work. I specialize in tearing apart white-labeled IoT devices, firmware extraction, and lock picking/bypassing. When I'm not desoldering eMMC chips or tracing wires, I'm writing Bash scripts that probably shouldn't exist and automating things in ways no one asked for. I also love cats. You can find me as codeneko or netcode in most places.