Call us — 01865 593000
Mon–Fri · 9am–5:30pm · No fix, no fee
Start a free diagnostic →

Data Recovery Case File · Solid State & Flash · Poor Odds, for an Unexpected Reason

The Standard Was Written for a Different Kind of Storage

His enquiry describes doing deliberately the thing this archive spends its time preventing. Office files and personal photographs on a solid-state drive he "wrongly data wiped. I formatted the drive using a multi-pass overwrite method." That procedure exists to make recovery impossible and it generally succeeds. But it was designed for magnetic drives, and on flash storage it does something rather different from what its authors intended.

Media256GB solid-state drive subjected to a multi-pass overwrite procedure — logical addresses overwritten repeatedly; physical block state undetermined
Reported situationSolid-state drive holding documents and photographic content · multi-pass overwrite procedure executed in error · procedure completed · content required · drive since retained
Fault classDeliberate overwrite of logical addresses on mapped storage — original physical blocks potentially unaddressed but subject to controller housekeeping
Equipment usedDrive powered as little as possible to limit controller housekeeping · logical overwrite extent distinguished from physical block state · chip-level read past the controller with unmapped block enumeration · position stated honestly before any charge

The decode: why the same procedure behaves differently here

Being honest first: the odds are poor. A multi-pass overwrite is designed to defeat recovery, it was run deliberately, and it completed. The most likely outcome is that nothing comes back, and that should be said before anything else.

Now the wrinkle, and it is genuine. That procedure was written for magnetic drives, where a logical address corresponds to a fixed physical location — so writing to an address overwrites the exact patch of surface holding the old data, and doing it repeatedly is thorough by design.

Why flash storage does not work that way: a controller maintains a map between the addresses a computer uses and the physical blocks holding the data, and it deliberately writes new data to different blocks each time — spreading wear evenly across the memory. The old block is not overwritten; it is unmapped and queued for erasure later.

What follows, and it is counterintuitive: a multi-pass overwrite on a solid-state drive writes many passes to fresh blocks and may never touch the physical locations holding the original data. The procedure is less effective on flash than on the media it was written for — which is why properly erasing a solid-state drive uses a manufacturer command that instructs the controller directly, rather than writing over addresses.

So there may be something in the unmapped blocks. Not through the controller, which will not return data it no longer maps — but read at block level, past the controller, where unmapped content can sometimes still be enumerated.

Why time works against him, and this is the urgent part: the controller runs housekeeping continuously. Blocks marked for erasure are erased in the background, during idle periods, whenever the drive is powered. Every hour it spends switched on is another opportunity for it to finish the job the overwrite left incomplete.

So the instruction is simple: stop powering it. Not another attempt, not a scan, not plugging it in to check. The drive is completing its own erasure while it runs, and nothing about that is reversible.

What a free assessment can establish: whether unmapped blocks survive and what they contain. Where they do not, there is nothing to charge for and the answer is no.

On the bench

The drive was powered as little as possible to limit controller housekeeping — blocks marked for erasure being processed in the background whenever the device runs, so operating time actively completes what the overwrite left undone. Logical overwrite extent was distinguished from physical block state, a flash controller writing new data to fresh blocks and unmapping the old rather than overwriting in place, which makes a procedure designed for magnetic media less thorough here. Reading proceeded at chip level past the controller with unmapped block enumeration.

The outcome

The drive kept unpowered to limit housekeeping, physical block state assessed independently of logical overwrite, and the position stated before any charge. Free assessment, and no charge where nothing survives. The decode: the odds are poor and there is one reason they are not zero. That procedure assumes writing to an address overwrites a fixed physical location, which is true of magnetic drives — a flash controller writes to fresh blocks and unmaps the old ones instead, so the originals may not have been touched. But the drive erases them itself while running.

Secure wipe run on the wrong drive

Stop powering it — that's the whole of the advice and it is urgent. On a solid-state drive the controller processes blocks marked for erasure in the background whenever the device is running, so every hour switched on completes the erasure the overwrite may not have finished. Expect poor odds, and know the one reason they aren't zero: multi-pass overwrite procedures were written for magnetic drives, where writing to an address overwrites a fixed physical location. Flash controllers write new data to fresh blocks and unmap the old ones, so the originals may never have been touched — which makes the procedure less thorough here than on what it was designed for.

Wiped a drive you needed?
Stop powering it now — call Oxford Data Recovery on 01865 593000; free assessment, physical block state assessed independently of logical overwrite, and an honest answer where nothing survives.
Request a quote online →

Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.