The bench is open for new cases · Mon–Fri, 9am–5:30pm Need it fast? Ring 0800 6890668
EDR Exeter Data Recovery 0800 6890668 Start my case
EDR / Specialist / Synology NAS recovery

Specialist · Synology recovery

Synology recovery for Exeter. “Volume Crashed” is DSM giving up; the data beneath sits where it always did.

One red banner on an Exeter DiskStation, three different troubles underneath: RAID members gone missing, LVM metadata in a muddle, or a btrfs tree that no longer adds up. DSM shows them all identically, yet each needs its own treatment — and treating the wrong one makes things worse. Until somebody has read the disks properly, the safe course is simple: power the box down and leave the Repair button alone.

No result, no bill — most jobs Free diagnosis and a written quote Post it in from anywhere in Devon

Talk it over with an engineer
0800 6890668

What the symptoms on a Synology are telling you.

Not there? Head for the triage →
What's wrongWhat it usually meansStep one
DSM has flagged Volume CrashedA single message hiding three suspects — btrfs, LVM or the RAIDPower down; don't touch Repair
Storage Pool shown as DegradedOne member has gone — everything still works, minus the safety netThe clock is now against you
The DiskStation itself won't startNothing moved — the data lives on the disks, never in the boxOne of the kinder faults
A rebuild onto a new disk stopped partwayThe rebuild's heavy reading showed up a second tired diskHalt it; imaging comes first
A PC now offers to format the NAS disksExpected — the Linux layout means nothing to WindowsSay no, every time
Your shares replaced by a ransom noteA strain that hunts internet-facing NAS boxesSnap a photo, power off, then read the ransomware page
Posting it to us: send the device by a tracked, insured service to our intake lab — the return leg is on us — or ring first and an engineer talks you through the packing. Full posting instructions live on the contact page.

Inside SHR — and why generic tools come up empty.

Carved into slicesSHR divides every drive into portions sized against the smallest one, so mixed capacities waste nothing. Clever housekeeping — with the side effect that a single volume quietly spans several separate arrays.
Ordinary parts, unusual stackingEvery layer is stock Linux — mdadm across the slice sets, LVM binding them into one pool, ext4 or btrfs above. Recovery therefore needs no Synology box at all; it needs the stack dismantled in strict order.
Where one-array software gives upPut four unequal drives into SHR-1 and beneath the surface sit maybe three, maybe four mdadm arrays under one LVM pool. Software hunting for a lone flat array simply finds no pattern to lock onto.
The two 'fixes' we rule outDSM's Repair option, capable mid-failure of discarding sound members and trampling metadata; and the btrfs repair tool, whose own manual cautions it can destroy an already-injured tree. In this lab neither runs — everything is assembled read-only from the images.

The recovery, one stage at a time.

Read the latest cases →
01

Booked in, assessed for nothing Free

Your device is logged under its own case number the day it arrives. An engineer finds the fault, tells you plainly what stands a real chance of coming back, and writes you one fixed quote. Nothing is charged for that look, nothing obliges you, and paid work starts only when you say so.

The look is freeA single quote, in writingNo obligation
02

Image every member, touch nothing

Each drive gets a sector-mapped image before anything else happens. The box itself stays powered off, so no rebuild can restart and the older btrfs roots survive exactly as the failure left them.

Each drive imagedOld tree roots preserved
03

Unpick the stack, layer by layer

All of it on the images: partition slices identified, the mdadm arrays put back together, LVM decoded, and finally the btrfs or ext4 volume brought up read-only. Order matters here, and we keep to it.

Slices → arrays → filesystemNothing mounted writable
04

Treat the layer that broke

Whichever level failed — RAID, LVM or btrfs — the remedy goes onto the rebuilt copy, never the originals. Where the current btrfs tree is ruined, an earlier healthy generation is used instead, and every share is opened and checked.

The broken layer mendedEvery share verified
05

Watched back, verified, returned

Before any fee falls due you see a full listing of everything recovered and approve it. Your files travel back on brand-new media, return postage on us, and the case stays open until you've confirmed everything opens on your own machine.

You approve the file listReturned on new mediaWe pay return postage

Opening checks at the bench

  • The banner never names the culprit — Volume Crashed covers a torn btrfs tree, lost LVM metadata and a failed mdadm member alike. Only reading each layer from the disks says which one you have.
  • Copy-on-write leaves a trail home — btrfs never overwrites in place, so previous tree roots tend to survive on disk. Stepping back one generation often revives a volume the latest tree declared gone.
  • That Repair button has ruined jobs — used mid-failure it can eject healthy members and overwrite the clues recovery needs. Fine for a pool in decent shape; wrong for a crashed one.
  • Ransomware finds the reachable, not the unlucky — every major NAS campaign has hit the same target: boxes visible from the internet running stale firmware. Take yours off the open web, keep DSM current, and you've shut the main door.

The fact that decides these cases: mix drive sizes under SHR and you don't get one array at all — you get several mdadm arrays laid across slices of each disk, gathered into a single filesystem by LVM. Approach that stack in the wrong order and nothing appears; take it apart correctly and a 'crashed' volume usually proves to be all there.

Fresh from the casebook.

EX · EDR-2026-2857VERIFIED ✓

Four mismatched disks in a DS unit, undone by its own good intentions

Two 4TB disks, two 8TB, one failed member — and by morning the DSM rebuild had ended in Volume Crashed. Under the hood lay three separate mdadm arrays; two were sound, the third degraded yet still workable. We put them back together away from the box, stepped the btrfs tree back one generation, and every share returned.

All shares restored5 days in the lab

Before it leaves your hands.

Do

  • Cut the power as soon as Crashed or Degraded appears
  • Label which bay each drive came out of
  • Send the bare drives, bay-labelled, untouched — not the unit
  • Mention the layout if you know it — SHR or plain RAID

Steer clear

  • Press Repair while a volume is degraded or crashed
  • Aim any btrfs repair command at the original members
  • Accept a PC's offer to initialise the disks
  • Swap drives between bays to test which one failed

Straight answers from the bench.

DSM says 'Volume Crashed' — is the data gone?

Very rare. 'Crashed' only means DSM couldn't reassemble the stack: missing RAID members, broken LVM metadata or a corrupted btrfs tree. Three different faults, most of them fixable — and the message can't say which you've got. Keep the box switched off and every route stays open.

SHR — is it proprietary, and would I need another Synology to read it?

No. Strip the branding and SHR is standard Linux: mdadm software RAID built over partition slices, LVM pooling them, and btrfs or ext4 formatted on top. Given good images of the drives, it reassembles on an ordinary workstation — problems only arrive when a tool, or a person, expects one flat array.

Is letting DSM rebuild onto a new disk safe?

Only once each member disk is safely imaged. Rebuilding reads the worn survivors end to end — exactly the load that finishes off a second drive — and it may overwrite the older filesystem structures a recovery depends on. With images taken first, the rebuild can do no harm.

Ransomware got into the NAS — is anything left?

Some of it usually, occasionally all of it — the strain decides. Internet-facing NAS units have been targeted for years, so the hunt covers snapshots, replication copies and what's left in free space. Take a photo of the ransom note, power the box off, then follow the ransomware page's routes.

Whatever the fault, leave the power off.

Each power-up of a failing device takes more data with it. Open a case first — the look-over is free whichever way it goes.

0800 6890668