Mechanism · TEE remote attestation for AI workloads
DDR5 memory-bus interposers forge Intel TDX attestations and break SEV-SNP protections (TEE.fail, DDRop)
On this page
Evidence scope
Critical when the verifier must resist physical access plus host control on the affected DDR5 platforms. The Intel demonstrations defeat attestation; TEE.fail's AMD demonstration extracts a guest key, not an AMD attestation key. These results do not cover every TEE architecture 3 33.
Independent researchers placed an interposer, built for under $1000, on the DDR5 memory bus of servers running Intel TDX and AMD SEV-SNP. Server TEEs encrypt memory deterministically, without integrity or freshness protection, and the researchers exploited this to recover secrets. The attack needs physical access and root privileges 3.
- On Intel, they extracted the provisioning certification key from a machine that Intel's service rated fully up to date. This per-CPU key signs the keys used in SGX and TDX attestation. With it they forged SGX and TDX attestations 3.
- On AMD SEV-SNP with ciphertext hiding enabled, they recovered an ECDSA private key used by OpenSSL inside the virtual machine. It was not an AMD attestation key 3. Other independent attacks did break SEV-SNP attestation. Battering RAM did so with a DDR4 interposer, and RMPocalypse and Fabricked from malicious host software 4 6 34.
A second team, from KU Leuven, ETH Zurich, Durham University and Google, built DDRop, an active DDR5 interposer with a bill of materials of $159. It silently drops memory writes, which memory encryption without freshness protection cannot detect. With brief physical access and control of the host software and BIOS, the researchers forced trust domains into debug mode and forged attestation reports on an up-to-date Intel TDX platform. The same primitive breaks the integrity of Scalable SGX and SEV-SNP, though the authors report no SEV-SNP attestation forgery 33.
The TEE.fail authors report that Intel and AMD consider interposer attacks out of scope, which leaves physical security as the only mitigation 3. The DDRop authors report the same position, and that both vendors issued security advisories on disclosure in September 2026 33. PAL*M lists this attack class as out of its scope 9, and Tinfoil's documentation acknowledges it 18. Gloria Z calls key extraction through bus interposition "relatively low-hanging fruit" in an international treaty scenario 11.