LIVE · cybersecurity feed
Live wire
cloud

Malicious cloud customers can bring down the power grid

Datacenters tax utilities normally, so just imagine what they could do if workloads were designed to destroy

zeroday.news · 12d ago

Researchers in China have identified a novel cyber-physical vulnerability, dubbed Bit2Watt, that could allow malicious cloud tenants to destabilize data centers and the broader electrical grid by manipulating GPU workloads. The attack, detailed in a preprint paper by Zhouhao Ji, Kaikai Pan, and Wenyuan Xu from Zhejiang University, highlights a potential pathway for adversaries to cause blackouts or damage equipment by exploiting the power demands of artificial intelligence (AI) training.

The core of the Bit2Watt attack involves a malicious actor masquerading as a legitimate cloud customer to launch specially crafted GPU workloads. These workloads are designed to induce rapid and significant power fluctuations within data centers. While AI training workloads are known to cause power swings, the researchers demonstrated that malicious GPU loads can achieve modulation frequencies exceeding 6,000 Hz, significantly higher than the few hertz observed in typical household loads. Such high-frequency modulations can lead to substantial voltage excursions, harmonic distortion, and damping degradation in the power system.

The researchers claim that an attack employing 1,000 GPUs on a 1-megawatt local power grid, particularly one reliant on distributed energy resources like photovoltaics, could generate a total harmonic distortion of 46.8 percent. This level of distortion would result in nearly half the electrical current being wasted on non-productive work and an approximate 20 percent increase in heat generation. Furthermore, the attack could produce a negative damping ratio of -0.27, introducing instability into the system. The authors warn that if protective measures are triggered and computing loads are shed, it could initiate cascading failures, potentially leading to blackouts affecting over 80 percent of large-scale power systems.

The attack is described as covert because it operates within authorized workload execution paths, making it difficult for current cloud provider monitoring frameworks to detect. The researchers emphasize the need for infrastructure providers to implement coordinated defenses across both cyber and physical layers, specifically looking for malicious computation patterns. They also recommend the use of local energy buffering systems to manage power demand spikes.

The findings align with observations from major technology companies regarding the power challenges posed by AI training. Microsoft, Nvidia, and OpenAI noted in a 2025 research paper that the transition between GPU computation and data synchronization causes large power swings. They cautioned that if the frequency spectrum of these swings harmonizes with critical utility frequencies, it could physically damage power grid infrastructure. Similarly, Meta's paper on training Llama 3 cited the risk of tens of thousands of GPUs simultaneously increasing or decreasing power consumption, leading to instantaneous fluctuations of tens of megawatts that can strain the power grid.

Beyond causing direct grid instability, the Bit2Watt research also points to a potential side-channel attack called Watt2Bit. The electrical and thermal stress induced by malicious workloads could create denial-of-service events and enable the covert exfiltration of data through power modulation. As a proof of concept, the researchers demonstrated the recovery of a 50-bit test sequence using frequency-shift keying (FSK) encoding.

The researchers conclude that the convergence of power and computing infrastructures necessitates a fundamental shift in security approaches. They advocate for coordinated defenses that comprehensively consider workload behavior, power electronics, and grid dynamics to address these emerging threats.

cloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.