If you are reading this, you have probably just looked at a SMART report and found a line that says something like Reallocated_Sector_Ct 100 100 036 Pre-fail Always - 0, and you are trying to work out which of those numbers is the bad news.
The honest answer is that only one of them counts sectors, and it is not the one most people look at.
Four numbers, four different meanings
A standard SMART attribute line carries several columns, and they are not variations of the same measurement.
VALUE is the normalized current reading. It is a health score, not a quantity, and higher is better. On a healthy attribute it usually sits at 100 or 200 depending on the vendor's scale.
WORST is the lowest normalized value the drive has ever logged for that attribute. It is a memory. If it matches VALUE, the attribute has never dipped.
THRESH is the normalized value at which the manufacturer declares this attribute failed. It is set per model by the vendor, which is exactly why one drive shows 36 and another shows 10.
RAW_VALUE is the actual count. For attribute 5, this is the number of sectors the firmware has retired and replaced with spares.
The number people search for is the raw value. The number they usually read is VALUE. They are not the same measurement, and on a drive that has begun to reallocate they frequently disagree.
Why 100 is not, on its own, reassuring
Here is the trap. The mapping from raw count to normalized value is decided by the manufacturer and not published. A drive can retire several sectors while its normalized value is still reported at 100, because the vendor's scale has not yet moved.
So a report showing 100 100 036 with a raw value of 0 means one thing, and a report showing 100 100 036 with a raw value of 8 means something quite different, even though the first three numbers are identical.
Read the raw value first. Then read VALUE against THRESH for the margin. In that order, not the reverse.
There is a second reason to distrust a comfortable normalized reading, and it is not about this attribute at all: a meaningful share of drives fail without ever raising a SMART warning. Our page on what smartctl actually tells you covers the published fleet statistics on that, and they are worth knowing before you rely on a clean report.

The raw count only goes one way
A reallocated sector is a sector the firmware has decided it can no longer trust. It maps a spare in its place, from a reserve pool set aside when the drive was manufactured, and it records the swap.
That record is permanent. The count does not decrease, because decreasing it would mean putting a sector the firmware rejected back into service. This is why searches for a way to fix or reset the count lead nowhere useful: there is no operation that undoes the decision, and a tool claiming otherwise is either writing over the sectors or misdescribing itself.
What matters is therefore not the number itself but its trajectory. A drive that reported 8 reallocations a year ago and still reports 8 today has a scar. A drive that reported 8 last month and reports 40 today is consuming its spare pool, and the interesting question is how fast.
Record the number and the date. One reading is a fact with no direction. Two readings a week apart are a trend, and the trend is the thing you can actually act on.
Attribute 5 is the record. Attribute 197 is the alarm.
This is the distinction that changes what you do today.
Attribute 5, Reallocated Sectors Count, logs what has already been retired. Whatever those sectors held is generally gone, because the firmware could not read it well enough to copy it.
Attribute 197, Current Pending Sector Count, is different. Those are sectors the drive could not read and has not yet remapped. They are unstable, not condemned. The data in them may still come back, and a successful write to that location can either clear the sector or push it into reallocation.
A rising pending count is the more urgent signal, because it is the only one of the two where your data is still on the table. It is a reason to stop writing to the drive now, not a reason to schedule something.
Attribute 198, Offline Uncorrectable, is worth reading in the same glance. Together the three tell a coherent story: what failed and was replaced, what is failing now, and what could not be read at all.
What to do, in order
Stop writing to the drive. Every write is a chance for the firmware to convert a pending sector into a permanent reallocation. If the data matters, this is the first move and it costs nothing.
Make an image before you diagnose. Work on a copy, not on the failing device. Reading a struggling drive repeatedly is itself a stress, and cloning with ddrescue is designed for exactly this case: it takes the easy sectors first and comes back for the difficult ones, rather than stalling on the first unreadable block.
Then read the numbers again on the copy's source, once, and write them down with the date. That is your second data point.
Decide about the drive separately from deciding about the data. A drive with a small, stable count that holds nothing irreplaceable can reasonably stay in service. The same drive holding the only copy of something cannot, regardless of how small the count is.
Reading files back from an image or a still-responsive drive
Applies after you have made a copy, or while the drive still reads. It does not lower the reallocated count and nothing does, because the firmware's retirement of a sector is not reversible.
What does not help
Running a repair utility to bring the count down. There is no such operation. What these tools can do is force writes that convert pending sectors into reallocated ones, which makes the number worse and destroys what was in them.
Reformatting. A format writes a new filesystem. It does not un-retire sectors, and on a drive holding data you want, it removes your remaining path to it.
Waiting for the drive to fail its own health check. The -H health status flips when the vendor's threshold is crossed, and that threshold is set for the vendor's purposes, not yours. Plenty of drives lose data long before their normalized value reaches 36.
The short version
- Only the raw value counts sectors. VALUE, WORST and THRESH are a normalized health score, its historical low, and the vendor's failure line.
- 100 with a raw value of 0 and 100 with a raw value of 8 are different situations that look identical in the first three columns.
- Thresholds differ by model, so 36 and 10 are both normal. Compare your value to your own threshold, not to someone else's.
- The count never goes down, so what matters is its trajectory. Record the number and the date, twice.
- Attribute 197 is the urgent one. Pending sectors may still be readable; reallocated ones usually are not.
- Stop writing, image the drive, then decide. In that order.
Attribute semantics follow the standard SMART reporting model as exposed by smartctl. Normalized-to-raw mappings and failure thresholds are vendor-defined per model and are not published, which is why this page gives no universal number for either. Commercial links carry the rel="sponsored nofollow" attribute; an affiliate commission may apply at no extra cost to you.
Recover the data from your hard drive → EaseUS
Free scan · deleted, formatted & lost files · Windows & Mac



