← How-Tos
flipper-zero Jul 3, 2026 ◑ 4 views ◯ 2 min read

GPIO to External SPI Flash/EEPROM: Read/Write

flipper zerogpiospieepromflash memory

The Use Case

Flipper's GPIO header exposes SPI, making it a genuinely useful bench tool for reading/writing/dumping external SPI flash or EEPROM chips — useful for firmware extraction/backup on other devices you're working on, or just general electronics bench work without needing a dedicated SPI programmer.

Hardware Connection

Standard SPI wiring, matching the target chip's pinout to Flipper's GPIO header:

Common Chip Families

Using an SPI Flash App

Several community-developed FAP apps specifically target SPI flash read/write (search the Flipper app catalog for current options — this space evolves, so check what's actively maintained rather than relying on a specific app name that might be outdated). General workflow within these apps:

  1. Connect chip per the wiring above, with the target device powered off if you're reading a chip in-circuit (in-circuit reads risk bus contention from other chips sharing the SPI lines — desoldering for a clean out-of-circuit read is more reliable when precision matters).
  2. Select the app's Detect/Identify function first — reads the chip's JEDEC ID to confirm correct wiring and chip family before attempting a full read.
  3. Run a full dump to Flipper's SD card once identification succeeds.

In-Circuit vs Out-of-Circuit Reading

In-circuit (chip still soldered to its host board) works for many simple cases but risks bus contention if other components are also driving the same SPI lines — you'll sometimes need to hold the host device's own microcontroller in reset (grounding its reset pin) during the read to keep it from interfering with the bus while Flipper is trying to talk to the flash chip directly.

Verifying a Dump

Compare a checksum (MD5/SHA) of your dump against a known-good reference if one's available for your target device/chip — a corrupted or partial read due to wiring issues can look superficially complete without careful verification, and re-flashing a bad dump back to a device can brick it.