What an unexpected power cut does to SSDs, and why power-loss protection is hard to check from outside
Published 2026-10-10
Cutting power during writes damaged 13 of 15 SSDs in the best-known public test (Zheng et al., FAST 2013: more than 3,000 injected power faults, five failure types from bit corruption to a drive that vanished from the bus), and two of the four drives that had power-loss protection (PLP) were among the 13; the only public signal that warns before such a cut is a vendor-specific capacitor status that one vendor (ATP) says conventional drives do not provide, while the damage itself shows up only afterwards as data errors or, in Intel's 2011 SSD 320 case, as a drive reporting 8 MB with the serial field BAD_CTX 0000013x. Micron's white paper explains the mechanism (an interrupted program of a multi-level cell can corrupt a lower page written long before) and the limit of client-class protection (ceramic capacitors that hold up about 1 ms, protecting data already written, not data acknowledged but still in volatile memory). These are one academic test of drives from model years 2009 to 2012 and three vendor documents; none of the opened sources gives a field failure rate for PLP capacitors.
- Failure types seen
- Bit corruption (3 SSDs), shorn writes (3), unserializable writes (8 SSDs and 1 HDD), metadata corruption (1), dead device (1); flying writes were not seen (FAST '13).
- Protected drives
- 4 of 15 SSDs were marked as having power-loss protection; 2 of those 4 still showed data damage.
- Detection before the cut
- A vendor-specific SMART PLP status exists on ATP drives; ATP says conventional drives give no sign of a failed capacitor.
- Not covered
- Field failure rates of PLP capacitors, drives made after 2013, other vendors' own tests, and the cause inside each tested drive.
Power-fault test of 15 SSDs and 2 HDDs
| Failure type | SSDs showing it (count of 15) | Device IDs in the paper | Extra numbers (unit) | Source |
|---|---|---|---|---|
| Bit corruption | 3 | SSD#11, #12, #15 | Two of the three used ECC per their datasheets | FAST '13 paper |
| Shorn writes | 3 | SSD#5, #14, #15 | 72 shorn writes in 441 test iterations on those 3 drives; new part always a multiple of 512 B within a 4 KiB record | FAST '13 paper |
| Unserializable writes | 8 (plus 1 HDD) | SSD#2, #4, #7, #8, #9, #11, #12, #13; HDD#1 | SSD#2 and #4 had hundreds of serialization errors per fault | FAST '13 paper |
| Metadata corruption | 1 | SSD#3 | About 1/3 of the data lost after 8 faults | FAST '13 paper |
| Dead device | 1 | SSD#1 | No longer on the SAS bus after 136 faults | FAST '13 paper |
| No failure observed | 2 (plus 1 HDD) | SSD#6, #10; HDD#2 | 13 of 15 SSDs failed in at least one way | FAST '13 paper |
The four SSDs marked as having power-loss protection
| Device | Marked PLP in Table 3 | Faults applied (count) | Failure observed | Source |
|---|---|---|---|---|
| SSD#6 | Yes | 105 | None | FAST '13 paper |
| SSD#7 | Yes | 250 | Unserializable writes | FAST '13 paper |
| SSD#10 | Yes | 100 | None | FAST '13 paper |
| SSD#15 | Yes | 103 | Bit corruption and shorn writes | FAST '13 paper |
Intel SSD 320, 2011: a power-loss failure that looked like a tiny drive
| Date | Statement | Value (unit) | Cross-check (second outlet) | Source |
|---|---|---|---|---|
| 2011-07 | Tom's Hardware reported a firmware bug that could reduce a 320 SSD of any size to 8 MB | 8 MB reported capacity | HotHardware quotes the same Intel text | Tom's Hardware, 18 Aug 2011 |
| Symptom | After an unexpected power loss under specific conditions the drive reports 8 MB and a serial-number field reading BAD_CTX 0000013x; no data can be read or written | 8 MB; serial string BAD_CTX 0000013x | Identical wording in both outlets | HotHardware, 18 Aug 2011 |
| 2011-08-18 | Intel released firmware 4PC10362 and recommended it even for drives without the problem | 1 firmware version | Both outlets are dated 18 August 2011 | Tom's Hardware, 18 Aug 2011 |
| 2011-08-18 | For an affected drive Intel offered replacement through support, or a secure erase followed by the firmware update | 2 options | Tom's Hardware gives only the update advice | HotHardware, 18 Aug 2011 |
Why an interrupted write can damage old data, and what the protection holds up
| Item | What the document says | Value (unit) | Cross-check | Source |
|---|---|---|---|---|
| Interrupted upper-page program (2 bits per cell) | Can leave the cell level wrong or between levels, or corrupt an adjacent lower page programmed long before | 2 bits per cell | The FAST paper says power loss during programming leaves cells outside specification | Micron white paper |
| Client-class hold-up | Ceramic capacitors give only about 1 ms, enough to return a lower-page program to its original level | about 1 ms | Protects data at rest only | Micron white paper |
| Enterprise-class hold-up | Larger tantalum capacitors discharge over a longer time to finish writes, flush buffered writes and save the mapping table | time not stated | ATP also names tantalum capacitors flushing DRAM cache | Micron white paper |
| Capacitor ageing causes | Dielectric breakdown, cracking, high or fluctuating temperature, out-of-spec voltage or current, repeated charge and discharge | 5 causes | Vendor claim, not measured | ATP, 2026-07-27 |
| Detecting a dead capacitor | On ATP drives with PLP Diag a SMART command reports PLP status; ATP says on a drive without it you generally cannot tell | 1 vendor-specific status | No opened source shows a standard attribute | ATP, 2026-07-27 |
Reading the numbers
Damage after a power cut is invisible beforehand. The FAST '13 authors cut power to each device while it was being written, then read everything back; 13 of 15 SSDs lost data they were expected to keep. Nothing in the paper suggests a pre-fault health signal that predicted which drives would fail, and the two protected drives that failed are reported without any capacitor reading. The detection is the read-back check itself, which is why it needs a known-pattern workload and cannot be done on a drive that holds data nobody can re-verify.
Protection that exists is not the same as protection that works. Four drives were marked as having PLP; two of them (SSD#7 and SSD#15) still showed damage, and two (SSD#6 and SSD#10) showed none. Because the paper does not report each capacitor's state, the right reading is that a PLP label did not guarantee a clean result in this test, not that capacitors are unreliable. Micron's paper adds a reason the label alone is thin: client-class PLP covers data already written, not data acknowledged but still buffered.
The Intel SSD 320 case shows a different failure shape: not corrupted blocks but a drive whose own state became unusable after a power loss, advertising 8 MB and a BAD_CTX serial string. The visible signal is in the identity fields the drive reports, and Intel's remedy for an affected drive was replacement or an erase and firmware update, according to HotHardware. Neither outlet gives how many drives were affected.
What can be checked from outside is narrow. ATP says capacitors in conventional drives age silently and shows a SMART status that exists on its own drives; no opened source shows that SMART or the NVMe health log has a standard field for this. Counts of unclean shutdowns are a different thing (see the NVMe health-log note) and tell how often protection was exercised, not whether it still works.
Related: fixed-hour SSD firmware failures, the NVMe health-log note, what fails most often on HDDs, SSDs and links and the SMART failure-signal note.
Method
Everything here was read on 2026-10-10 from documents opened that day: the FAST '13 paper PDF and its USENIX abstract page; a Micron white paper (copyright 2014) on unexpected power loss; ATP's article on capacitor health checks (dated 2026-07-27); and two news reports (Tom's Hardware and HotHardware, both 18 August 2011) that quote Intel's notice about the SSD 320 8 MB failure. Counts are copied from the paper's Tables 3 to 5 and text. Values marked 'computed' are derived on this page: the sum of faults over the 15 SSDs in Table 4 of the paper. The vendor documents and the two news items are one vendor statement each, so the Intel notice is counted as one source seen in two outlets, not two independent measurements.
Limits
The test SSDs are model years 2009 to 2012 per the paper's Table 3 (the paper appeared in 2013); current firmware and NAND differ, so the counts show which failure types exist, not how often a drive made today fails. Vendors are blinded in the paper. The paper does not say whether a protected drive's capacitor was healthy, so the page does not claim that a PLP mechanism failed in the two protected drives that showed damage; it only reports that damage occurred on drives marked as having PLP. Table 3 marks two drives (SSD#4 and SSD#13) with a dash, and the paper's text says four drives have PLP, which matches the four marked Y. No opened source gives a field failure rate for PLP capacitors, or the number of Intel 320 drives affected. ATP and Micron sell SSDs and Intel made the 320, so their statements are vendor claims; the ATP statement that conventional drives give no sign of a dead capacitor is not tested by any opened measurement. The ATP SMART status is described for ATP drives only, and the page does not show that any standard attribute or NVMe log field carries PLP health. The HPE-style fixed-hour failures are on a separate page. The page covers public failure analysis only; nothing here concerns encryption, drive security features, or recovering anyone else's media.
Sources
- 01Zheng, Tucek, Qin, Lillibridge: Understanding the Robustness of SSDs under Power Fault, FAST '13 (paper PDF) · accessed 2026-10-10
- 02USENIX FAST '13 presentation page for the same paper (abstract, thirteen of fifteen) · accessed 2026-10-10
- 03Micron white paper: How Micron SSDs Handle Unexpected Power Loss (2014) · accessed 2026-10-10
- 04ATP, 2026-07-27: Why Power Capacitors is critical for SSDs Power Loss Protection · accessed 2026-10-10
- 05Tom's Hardware, 18 Aug 2011: Intel Releases New SSD Firmware to Fix 8 MB Bug · accessed 2026-10-10
- 06HotHardware, 18 Aug 2011: Intel Pushes Out Firmware Update For 320 Series SSDs · accessed 2026-10-10