Vulnerabilities · 2h ago
Researchers at KU Leuven, ETH Zurich, Durham University, and Google disclosed DDRop, a hardware attack that breaks Intel TDX, Intel Scalable SGX, and AMD SEV-SNP by dropping writes to DDR5 memory. The setup uses a sub-$200 interposer and server software control, and it is the first active interposer attack shown against DDR5 cloud servers.
The trick is simple: interrupt a write so the new value never lands, but the old encrypted value still decrypts correctly later. Because the platform can verify that memory is encrypted but not that it is fresh, the protected VM keeps running on stale data. On Intel TDX, the researchers say that can push a VM into debug mode or produce forged attestation reports, so a backdoored guest can still look trusted.
For cloud operators and tenants relying on confidential VMs or enclave-style systems, the exposure sits at the freshness layer, not just confidentiality. If a host or physical attacker can briefly touch the server and already has software control, encrypted-in-use memory may still be rolled back to attacker-chosen state even after the data is encrypted.
2 sources covering this story
New hardware device can RAM into encrypted memory, expose your data
Attackers would need physical access to the server to pull off the DDR5 trick
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
DDRop uses server control and a DDR5 interposer to replay stale encrypted data in Intel TDX, Scalable SGX, and AMD SEV-SNP.
Part of the PlainSec briefing for 2026-09-14