Data Recovery Case File · Formatted & Logical Faults · The Format That Hit the Wrong Disk
Wrong target, right instincts: the cancelled format decoded layer by layer — encrypted-volume metadata, the relabel that couldn't work, the I/O error that meant more than corruption — and the recovery run on images, unlocked with his own passphrase
His enquiry opened "I recently made a silly mistake!" and then described handling it better than almost anyone. On his ThinkPad running OpenBSD, a format intended for an SD card "was accidentally done on my laptop's SSD… I immediately cancelled the operation and imagine most of the data will be intact." The aftermath: the laptop won't boot — the firmware falls through to the encrypted-volume prompt, "which asks for the drive's encryption password, which when unlocked, cannot find anything else to boot." And then the two moves that define the case: "after backing up the corrupted drive" — he imaged it first, unprompted, the exact discipline this archive preaches — he attempted a fix at the filesystem layer: relabelling the disk from the mistaken format's type back to its native filesystem so he could run a repair pass. That attempt "returned a low-level input/output error," and he stopped, stuck, and asked. This page meets him at his level: what the seconds of formatting actually destroyed on an encrypted-volume disk, why the relabel-and-repair plan was aimed at the wrong layer, what the I/O error genuinely signifies — and the reconstruction that ran, as all of it should, on images, opened with his own passphrase.
| Media | Laptop SSD (ThinkPad, OpenBSD) — encrypted system volume; start-of-disk structures overwritten by seconds of a wrong-target format, cancelled by the owner; drive imaged by the owner before any repair attempt |
| Reported situation | Format aimed at an SD card executed against the SSD; cancelled immediately · boot falls to the encryption prompt; passphrase accepted but nothing bootable found · owner's relabel-and-repair attempt blocked by a low-level input/output error |
| Fault class | Partial overwrite of on-disk encrypted-volume metadata and disk label — layered reconstruction case; owner's passphrase the legitimate key; I/O error demanding drive-health verification before all else |
| Equipment used | Owner's image preserved; independent write-blocked image taken (Atola TaskForce 2, NVMe-native) · drive health verified against the I/O error's two readings · encrypted-volume metadata reconstructed on the image; volume unlocked with the owner's own passphrase · native filesystem repaired within; data verified and delivered |
The decode: three layers, one mistake, and the error that changed the checklist
What seconds of formatting destroy on a disk like his: his "most of the data will be intact" is almost certainly right — a cancelled format writes fresh structures at the start of its target and dies before touching the bulk. But the start of his disk is expensive territory, because an encrypted-system laptop stacks its layers there: the disk label (the map of the disk's areas), and the encrypted volume's metadata — the small structures that define the protected volume and govern how his passphrase unlocks it. The boot behaviour he describes reads exactly like a partial strike on that stack: the encryption layer survives well enough to prompt and accept his passphrase, but what stands behind the unlock no longer describes a bootable world — the map torn, the interior intact but unaddressed. Seconds of format; surgical damage; bulk untouched. His instinct was sound to the percentage point.
Why the relabel worked at the wrong layer: his repair plan — set the disk's filesystem label back from the mistaken format's type to the native one, then run the filesystem checker — was logical and one storey too high. On an encrypted-volume disk, the native filesystem doesn't live on the disk; it lives inside the decrypted volume. The raw disk's surface, to any filesystem tool, is ciphertext behind a metadata door — so relabelling the outside and pointing a repair tool at it asks the checker to repair a filesystem that isn't there at that layer. The correct order runs inward: reconstruct the encryption metadata first, unlock with the passphrase, and only then repair the native filesystem found inside. His plan wasn't wrong technique; it was right technique addressed to the wrong storey of the building.
The I/O error — the twist that reorders everything: and the detail that stopped him is the one a careful bench refuses to wave past. A low-level input/output error has two readings: the benign (tooling declining to operate across a layer mismatch) and the serious (the SSD itself failing reads — hardware trouble arriving coincidentally or contributing all along). The distinction changes the checklist's first line: before any reconstruction, the drive's own health is verified directly — because metadata surgery on failing media is exactly the kind of second mistake one-mistake cases can't afford. His self-taken image, meanwhile, quietly earns its keep either way: whatever the drive's condition today, a copy of it exists from the earliest possible moment — the single most professional act in the whole story, performed at his own kitchen table.
On the bench
His image was received and preserved as the earliest witness, and an independent write-blocked image was taken on the Atola TaskForce 2's native NVMe ports — during which the I/O question answered itself under measurement: the drive's true read health established, and the error's reading settled before a byte of surgery. The reconstruction then ran inward, on images: the overwritten start-of-disk survey mapping exactly what the seconds of format had replaced; the encrypted volume's metadata rebuilt from its surviving structures; the volume unlocked with his own passphrase — the legitimate key, the only kind this archive ever turns; and the native filesystem inside repaired at last at its actual storey, the checker finally aimed at a filesystem that existed. His data stood up, was verified by opening, and was delivered — the silly mistake outlived by every good decision he'd made after it.
The outcome
The encrypted volume reconstructed on images, unlocked with the owner's passphrase, its filesystem repaired within, and the data verified and delivered. Free assessment, one fixed written figure including VAT, no recovery, no fee. For every technical user holding a wrong-target format: your image-first instinct is the professional standard — perform it and preserve it; know the layer order on encrypted disks (metadata, then unlock, then filesystem — repairs aimed at the raw disk address ciphertext); and treat any low-level I/O error as a fork, not a nuisance: verify the drive's health before surgery, because the second mistake is the one these cases can't survive. Fluency got him nearly all the way here. The rest was just the right storey.
Formatted the wrong disk — and it's an encrypted system drive
Cancel, stop, and image the disk before anything else — exactly as this owner did; that copy is the case's foundation whatever follows. Then respect the layer order: on an encrypted drive the real filesystem lives inside the unlocked volume, so relabelling the raw disk and running repair tools against it can't work and risks writes where the surviving metadata lives — reconstruction goes metadata first, passphrase second, filesystem last, all on images. Keep your passphrase safe; it's the legitimate key the whole recovery turns on. And if any step throws a low-level I/O error, halt: that's either tooling refusing a layer mismatch or the drive itself failing — and only direct health verification can tell you which before surgery proceeds.
Right instincts, wrong storey — call Edinburgh Data Recovery on 0131 202 0491; imaged, metadata rebuilt, unlocked with your passphrase, repaired inside — one written figure, no recovery, no fee.
Request a quote online →
Our case files are drawn from genuine enquiries received by our laboratory over the past ten years, anonymised to protect client confidentiality. Each one describes the diagnostic and recovery procedure our engineers apply to that fault, using the equipment listed.