← Blog · · df00tech

DDRop Attack Demonstrates Physical Bypass of Intel TDX and AMD SEV-SNP Memory Protections

security-news technique

What happened

Researchers have disclosed a new hardware attack called DDRop that undermines the memory-integrity guarantees of Intel Trust Domain Extensions (TDX) and AMD Secure Encrypted Virtualization-Secure Nested Paging (SEV-SNP), the two dominant confidential computing technologies used to protect virtual machines running on shared cloud infrastructure. According to the report, the attack works by silently dropping writes to a server's memory, causing the processor to keep reading stale encrypted data as if it were current — effectively defeating the freshness protections these technologies rely on.

Notably, the attack requires an adversary who already has control over the server's software and can briefly gain physical access to the machine to insert a small circuit. This makes DDRop a hardware-level, physical-access attack rather than a purely remote software exploit.

Why it matters for defenders

Confidential computing (TDX/SEV-SNP) is increasingly relied upon by cloud providers and enterprises to isolate sensitive workloads — such as key management, multi-tenant SaaS, and regulated data processing — even from a compromised or malicious hypervisor/host. If memory-freshness guarantees can be undermined via physical tampering, organizations that treat these technologies as a hard trust boundary against insider threats or physically-adjacent attackers (e.g., in colocation or bare-metal cloud environments) should reassess that assumption. This is particularly relevant to cloud providers, colocation tenants, and anyone running confidential VMs on hardware they do not fully physically control.

What defenders should watch for now

  • Track vendor advisories from Intel and AMD for firmware/microcode guidance or mitigations related to TDX and SEV-SNP memory integrity.
  • Review physical security controls for bare-metal and colocation environments hosting confidential-computing workloads — this attack requires brief physical access to insert hardware.
  • Audit which workloads rely on confidential computing as a defense against a fully compromised host/hypervisor, and confirm that physical access controls are treated as part of that trust model, not a separate concern.
  • Monitor supply chain and hardware tamper-detection processes for servers running confidential computing, since the attack vector described involves inserting a small circuit into the system.
  • Watch for follow-on research or proof-of-concept releases that may clarify feasibility, required access level, and any detectable side effects.

Developing story

This is net-new intelligence based on an initial disclosure, and technical details such as full attack requirements, affected hardware generations, and vendor response are still emerging. Defenders should treat the specifics as preliminary until Intel, AMD, or the researchers publish further detail. Read the original report at The Hacker News.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.