DDRop attack drops DDR5 writes to break Intel TDX and AMD SEV-SNP confidential VMs
matthew_d_green · x · 2026-09-17
Researchers have disclosed DDRop, a low-cost hardware memory interposer attack coordinated with Intel and AMD that makes writes to server memory silently disappear, causing confidential VMs to read stale data as if freshly written.
- The gap: Memory encryption in Intel TDX, Scalable SGX, and AMD SEV-SNP provides confidentiality but not freshness — the CPU can verify data is encrypted but not that it is current, so dropped writes leave perfectly decryptable stale contents.
- Impact: The attack can tamper with protected VMs on both Intel and AMD platforms, and on Intel TDX can even forge the attestation evidence used to prove a VM is trusted.
- The paper appears at ACM CCS 2026.
Another reminder that hardware-level trust assumptions underpinning confidential computing in shared clouds can fail.
Related event: DDRop attack silently drops DDR5 writes to break confidential VMs(2 posts)→
More from Infra
- VC-Attention: training-free low-bit attention hits 1.9x on B200, beating FlashAttention-4 — xiuyu_l · 2026-09-17
- mlx.fast fixes speed-display bug: MLX kernels hit 80.6 tps, nearing 100% speedup milestone — HankYeomans · 2026-09-17
- Memory shortage hits checkout: Xiaomi raises phone prices 200-1,000 yuan as DRAM stock dips under 10 days — tengyanAI · 2026-09-17
- Burkov Slams OpenRouter Reliability: Fallback Models Fail Together — burkov · 2026-09-17
- Common Crawl puts crawl archives on Hugging Face Storage Bucket, with a getting-started guide — vanstriendaniel · 2026-09-17
- Anthropic Signs A$32B Queensland Data Center Deal, Claude's First Australian Footprint — ocean_protocol · 2026-09-17