DDRop: ~$159 DDR5 Interposer Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
Researchers will present DDRop at ACM CCS 2026 — a sub-$200 (about $159) DDR5 RDIMM interposer that silently drops memory writes, defeating confidentiality and integrity guarantees in Intel TDX, Intel Scalable SGX, and AMD SEV-SNP.
Researchers from KU Leuven, ETH Zurich, Durham University, and Google will present DDRop at ACM CCS 2026, described as the first active interposer attack on DDR5. Built from roughly $159 in parts (The Hacker News reported it as sub-$200), the custom DDR5 RDIMM interposer sits on the memory bus and injects parity errors to silently discard selected cache-line writebacks at native speed. Because Intel TDX, Intel Scalable SGX, and AMD SEV-SNP lack per-line cryptographic freshness, the processor keeps reading stale encrypted data and accepts it as valid state. On Intel TDX's default logical integrity mode, the researchers demonstrated reading victim VM memory, forcing trust domains into debug mode, injecting malicious Secure EPT entries, and forging remote attestation; on AMD SEV-SNP the attack was limited to copying pages between VMs. TDX's stronger cryptographic integrity mode blocks cross-VM attacks but likely not attestation forgery. The affected technologies are used by AWS, Azure, and Google Cloud. The attack requires privileged host (software) control plus brief physical access to the server, making cloud and colocation hosts the relevant targets. The researchers say no simple software patch exists and a durable fix needs hardware integrity plus freshness checks; they plan to release board designs, firmware, and attack code on GitHub. There is no evidence of real-world exploitation.
- Device: custom DDR5 RDIMM interposer built from ~$159 in parts (reported as sub-$200 by The Hacker News)
- Mechanism: injects parity errors to silently drop selected cache-line writebacks at native memory speed, so the processor reads stale encrypted data undetected
- Root cause: Intel TDX, Intel Scalable SGX, and AMD SEV-SNP lack per-line cryptographic freshness and accept stale encrypted data as valid
- First active interposer attack on DDR5; to be presented at ACM CCS 2026
- Intel TDX default logical integrity mode: victim VM memory reads, debug-mode forcing, malicious Secure EPT entry injection, forged remote attestation
- AMD SEV-SNP impact limited to copying pages between VMs; TDX cryptographic integrity mode blocks cross-VM attacks but likely not attestation forgery
- Affected technologies are deployed by AWS, Azure, and Google Cloud
- Prerequisites: privileged host control plus brief physical access to the server
Coverage timelineoldest first · each row is one article
- · 1d agoNew DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
The Hacker News· 55
DDRop uses a sub-$200 DDR5 interposer to drop memory writes, breaking Intel TDX and AMD SEV-SNP confidentiality guarantees.
- · 12h agoNew DDRop Attack Breaks Intel TDX and AMD SEV-SNP With $159 DDR5 Device
Cyber Security News· 65
DDRop uses a $159 DDR5 RDIMM interposer to silently drop memory writes and break Intel TDX and AMD SEV-SNP confidential VMs.