Data Recovery on T2 and Apple Silicon MacBooks: Why Soldered SSDs Change Everything

Apple Silicon chip on a MacBook logic board, integrating the storage controller and Secure Enclave
On an Apple Silicon Mac, the SSD controller and encryption sit inside the chip – the data is bound to this exact board

Data recovery on a Mac used to be simple: remove the drive, connect it to an adapter, copy the data. On any MacBook with a T2 chip or Apple Silicon, that route no longer exists – not because the tools are missing, but because Apple's security architecture rules it out by design. This article explains what changed with T2 and Apple Silicon, what role FileVault plays, why classic data recovery methods lead nowhere here – and what is possible instead.

The old way: pull the drive, copy the data

Until around 2017, mass storage in a Mac was a separate component: a hard drive or a removable SSD. If the MacBook died, the storage usually survived – you removed it, connected it to an adapter and copied the data off. On those older models (MacBook Pro Retina up to 2015, MacBook Air up to 2017, many iMacs), this is still the fastest and cheapest data recovery route today.

Turning point one: the T2 chip (2018–2020)

Starting with the iMac Pro (2017) and from 2018 in the MacBook Pro, MacBook Air and Mac mini, Apple added the T2 security chip. Among other things, the T2 is the device's SSD controller: all data passes through it and is hardware-encrypted on the way – always, from the factory, even if you never enabled FileVault.

The key for this encryption lives in the T2's Secure Enclave – a walled-off area that exists exactly once: on this one chip, on this one board. The NAND packages that physically hold the data are still separate chips on the board – but without the Secure Enclave of that specific board, their contents are nothing but noise.

Turning point two: Apple Silicon (since 2020)

With the M1, Apple moved the T2's architecture straight into the main processor. On every MacBook with M1 through M5, the same principle applies, only more tightly integrated: the storage controller and Secure Enclave sit inside the SoC, the NAND chips are soldered to the logic board, and encryption is always on. There is no longer any "drive to remove" – the data and the board are a single, inseparable unit.

What FileVault changes – and what it doesn't

A common misconception: "I never turned on FileVault, so my data isn't encrypted." On T2 and Apple Silicon Macs, that isn't true – everything is always encrypted there. FileVault only changes what the key is bound to:

  • Without FileVault: The hardware decrypts the data as soon as the system starts. For data recovery this means: if the original board can be brought back to life, the data becomes accessible.
  • With FileVault: The key is additionally tied to your login password. Even after a successful repair, only someone who knows the password can reach the data – including us, only with you. That is by design, and it's why FileVault is effective protection against theft.

In practice this means: for FileVault-protected devices we need your login password (or the recovery key) to complete a data recovery. No workshop in the world can bypass a forgotten FileVault password – the architecture is built precisely for that.

Why classic data recovery doesn't work here

Professional data recovery labs traditionally rely on methods like reading out individual memory chips ("chip-off") or transplanting parts onto donor boards. On T2 and Apple Silicon Macs, exactly these routes fail:

  • Chip-off fails at the encryption: The desoldered NAND chips can be read out – but all you get is encrypted noise. The key sits in the Secure Enclave of the original board and never leaves it.
  • Donor boards don't help: Resoldering NAND chips onto an identical board achieves nothing – the donor board's Secure Enclave holds a different key. The pairing between storage and chip is unique per device.
  • Apple has no spare key either: There is no master key and no back door – not for workshops, and not for Apple itself. That is the whole point of this security architecture.

The only path to the data runs through the original board: it has to be repaired to the point where the Secure Enclave and storage controller work again. Data recovery on modern Macs is therefore not storage work but component-level logic board repair.

What is possible: repair instead of removal

The good news: in the vast majority of cases the storage itself is fine – what failed is a component around it. A charging IC, a voltage regulator, a short on a power rail, corrosion after liquid damage. Faults like these can be fixed precisely under the microscope. Once the board runs again, there are several ways to secure the data:

  • The device boots normally again: Data is backed up straight to an external SSD – and the repaired MacBook often simply carries on afterwards.
  • Share Disk / Target Disk Mode: If macOS itself won't boot cleanly, the storage can be read out via a second Mac – via Share Disk mode on Apple Silicon, via Target Disk Mode on Intel Macs with T2.
  • Firmware revive via DFU: If only the firmware is damaged (after an interrupted update, for instance), a "revive" via a second Mac can bring the device back – without erasing any data.

Where the limit lies: if the SoC, the Secure Enclave or the NAND chips themselves are physically destroyed, board repair can't help either. That is rare – but it happens, and honesty means saying so up front: there is no guarantee of success in data recovery.

What a data recovery typically costs and what real cases from our workshop look like is covered in MacBook data recovery: what can be saved – and what it costs; an overview of the service is on our MacBook & iMac data recovery page.

What you can do yourself – and what to avoid

When disaster strikes

  • Don't keep switching it on: Especially after liquid damage, every power-on attempt makes things worse – corrosion and shorts can destroy exactly the components needed for the recovery.
  • No experiments with heat or "tricks" from videos: What occasionally worked on old machines can seal a total loss on a densely packed modern board.
  • Back up half-alive devices immediately: If the MacBook only starts sporadically, use the next successful boot for a full backup – not for "later".

The best data recovery is the one you never need

Time Machine with an external drive is enough – set it up once and it backs up automatically. Precisely because data on modern Macs is inseparably tied to the board, a current backup matters more than ever. Also store your FileVault recovery key somewhere safe.

MacBook dead and no backup? We check free of charge whether your board can be repaired far enough to make the data accessible – you only pay if the recovery succeeds, Germany-wide with free DHL shipping. All details: MacBook data recovery on emonis.

Frequently asked questions

Which Macs have a T2 chip?

The T2 is in the iMac Pro (2017), the MacBook Pro (2018–2020), the MacBook Air (2018–2020), the Mac mini (2018) and the iMac (2020) – the final Intel generations. You can check yours in the System Report under "Controller" or "iBridge". All Macs with M1 through M5 have the T2's functions integrated directly into the main chip.

Can't you just desolder the SSD chips and read them out?

Desolder, yes – read, no. The NAND chips hold only encrypted data; the key lives in the original board's Secure Enclave and cannot be transferred. Desoldered chips or a donor board therefore yield nothing but unreadable noise. The only path to the data is repairing the original board.

My data was stored without FileVault – is it easier to recover?

On T2 and Apple Silicon Macs, data is hardware-encrypted even without FileVault. The difference: without FileVault, the repaired board decrypts the data on its own – with FileVault, your login password is needed as well. Recovery is feasible either way, as long as the board is repairable and you know your password.

I've forgotten my FileVault password. Is there a way out?

Only via the FileVault recovery key that macOS displayed when you enabled it, or – if set up – by unlocking with your iCloud account. Without the password and without the recovery key, FileVault data is irretrievably encrypted; no workshop can bypass that, and neither can Apple.

What are the odds of a successful recovery via board repair?

Good – as long as the SoC and the memory chips are intact. In roughly 90% of cases the data can be saved, because the fault sits in the board's periphery (power delivery, charging circuitry, corrosion). With us, you only pay if the recovery succeeds; the analysis is free.

Does all of this apply to the iMac and Mac mini too?

Yes, as soon as a T2 or Apple Silicon chip is inside – the architecture is identical. Older iMacs with a classic hard drive or removable SSD are the easy case by contrast: there, the storage can still be removed and read out directly.