A failed S9 firmware upgrade almost never means a dead miner. The Antminer S9 runs on a Xilinx Zynq-7010 control board (dual Cortex-A9 @ 667 MHz, 256 MB NAND and 256 MB DDR3 on most boards — some revisions ship 512 MB), and an interrupted flash usually leaves only the firmware partition half-written — the boot loader and recovery paths are intact. This guide walks the exact recovery sequence: reload the official repair package, re-flash clean, and get the unit back on your pool.
Why an S9 firmware upgrade fails
The upgrade writes a new root filesystem into the NAND. If that write is cut short or the image is wrong for your board, the miner boots into a broken state (no web UI, no IP, or a hung LED pattern). The usual causes:
- Power or browser interrupted mid-flash. Closing the upgrade tab, a dropped link between your PC and the miner, or a power blip during the write truncates the image.
- Wrong or corrupt image. The S9 shipped with several control-board revisions. An image built for a different board — or a partial/corrupt download — will flash but not boot.
- “Keep settings” carried across a major version. Jumping several firmware versions while preserving config can leave incompatible settings behind.
- Worn NAND on a high-hour unit. Older S9s accumulate bad blocks; a write that lands on a failing block corrupts the filesystem.
None of these brick the hardware. The Zynq boot ROM still runs, which is what makes recovery possible.
Before you touch the miner
- Do not keep power-cycling. Repeated hard reboots on a half-written NAND make things worse. Power down once, cleanly, and work the recovery steps in order.
- Wire it directly. Put your PC and the miner on the same switch with a known-good Ethernet cable. Recovery uploads fail silently over congested or wireless links.
- Mind the PSU, not the DC side. The S9’s APW3++ or APW7 supply holds a mains-voltage charge (~410–420 V) on its internal capacitors after unplugging — keep out of the PSU. The per-board 12 V connectors feeding the boards are not a shock hazard. Both the APW3++ and APW7 run on 110/120 V at reduced output, so a partially-flashed unit on a 120 V circuit still has enough power to recover.
Step 1 — Reload the official repair package
Bitmain distributes a “package to fix upgrade failure” (a recovery firmware) for the S9 through its official support portal. Download only the S9 recovery package that matches your board — never a random third-party image or an invented download link. Verify the file size looks complete before flashing; a truncated file is the most common re-fail.
- Power the miner, wait ~2 minutes, and find its IP with the IP Reporter button on the control board or a network scan.
- Open the web UI and go to System → Upgrade (the exact label varies by firmware). Select “Do NOT keep settings” so old config can’t poison the flash.
- Upload the recovery package and let it complete. Do not close the tab or cut power until it reports success and reboots on its own.
Step 2 — If the web UI is unreachable: microSD recovery
When the miner won’t serve a web page at all, recover through the control board’s microSD slot. The Zynq doesn’t automatically fall back to SD — its boot source is latched at reset by the J3 jumper (open = NAND, the default; shorted = SD). Shorting J3 forces the board to boot a good SD image and bypass the broken NAND partition entirely.
- Write the official S9 SD recovery image to a microSD card (4 GB+) with a disk-imaging tool.
- Power off, insert the card into the control board’s microSD slot, and short the J3 jumper to select SD boot — this is required to boot from SD on the S9 control board, not an optional per-revision step.
- Power on. The board boots from SD and re-flashes the NAND. When the status LEDs settle, power off, remove the card, return J3 to its default (open) position, and boot normally from NAND.
If you don’t have the right image or the board revision fights you, this is the point to hand it to a repair bench rather than guess.
Step 3 — Re-flash the current firmware
Once the miner boots clean off the recovery package, upgrade again to the current stable S9 firmware from the official source, still with settings not kept. Re-flashing on a healthy filesystem is what the failed attempt was trying to do — it should now complete normally.
Step 4 — Reset, rediscover, and let it settle
- Reset if there’s no IP. If the unit won’t pull an address after the upgrade, hold the reset button (~5 seconds) to clear network and config back to factory. The DHCP-assigned IP can change after a reset — your router’s ARP/lease table resolves the new IP to the miner’s MAC.
- Re-enter your pool. A no-keep-settings flash wipes your pool URL, worker name, and password — add them back under Miner Configuration.
- Let it run 20+ minutes. After recovery the S9 needs time to bring all three hash boards online and stabilize. Confirm every board reports its full chip count (63 per board, 189 total) and the SHA-256 hashrate climbs to the expected rate before you call it fixed.
Common mistakes that cause a second failure
- Re-uploading over Wi-Fi or a busy switch — use a direct wired link.
- Flashing a truncated download — re-download and confirm the file completed.
- Keeping settings across the flash — leave them off during recovery.
- Using an image meant for a different S9 board revision — match the board.
- Panic power-cycling mid-write — every interruption is a fresh corruption.
When it still won’t recover
If the board won’t boot from SD, the NAND is worn past re-flashing, or a hash board stays dark after a clean firmware load, the fault is hardware, not firmware — a failing control board, PSU, or hash board. That’s a bench repair, not a re-flash.
Related: Diagnose a board that still won’t come up with the ASIC fault finder, source a replacement control board or PSU from ASIC repair parts, pull the correct S9 documentation from the miner manuals library, or hand it to the bench via start a repair.
