Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

New Vulnerability in Cloud Infrastructure Could Allow for Grid Disruption Without Exploit




A recent paper has uncovered a previously unknown vulnerability in cloud infrastructure that could allow for grid disruption without an exploit. The "Bit2Watt" vulnerability exploits the tight coupling between volatile GPU load and an inverter-heavy grid, which is currently not monitored across different systems. This means that even standard telemetry barely catches it, making detection and mitigation challenging. The researchers developed two methods to exploit this vulnerability: SWMA and LTMA. The experiments conducted by the researchers show that both methods can produce significant power components in data centers, potentially destabilizing the grid. The study has significant implications for cloud security and critical infrastructure protection.

  • A previously unknown vulnerability, "Bit2Watt," has been discovered in cloud infrastructure that could potentially allow for grid disruption without an exploit.
  • The vulnerability exploits the tight coupling between volatile GPU load and an inverter-heavy grid, making detection and mitigation challenging.
  • A single-GPU figure can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no exploit or break-in required.
  • The vulnerability works by creating controllable power oscillations at the wall socket through saturating GPU tensor cores and toggling between idle and intense computing states.
  • Two methods to exploit this vulnerability have been developed: SWMA (Saturate-Workload-Modify-Accelerate) and LTMA (Lightweight Training Modulation Attack).
  • The experiments conducted by the researchers show that both methods can produce significant power components in data centers, potentially destabilizing the grid.
  • The study highlights the importance of monitoring tools and advanced detection mechanisms to mitigate this risk.



  • A recent paper published at the IACR's hardware-security conference, CHES 2026, has shed light on a previously unknown vulnerability in cloud infrastructure that could potentially allow for grid disruption without an exploit. The study, conducted by three researchers from Zhejiang University, has raised significant concerns about the potential risks and consequences of this newly discovered vulnerability.

    The vulnerability, dubbed "Bit2Watt," exploits the tight coupling between volatile GPU load and an inverter-heavy grid, which is currently not monitored across different systems. This means that even standard telemetry barely catches it, making detection and mitigation challenging. The researchers found that a single-GPU figure can push a data center's power draw up and down fast enough to threaten the grid it runs on, with no exploit or break-in required.

    The vulnerability works because a GPU's power draw follows whatever it is computing. By saturating the tensor cores and current spikes, dropping to idle, and then toggling between those states on a schedule, the researchers were able to create a controllable power oscillation at the wall socket. This technique can be executed as legitimate workloads, making it difficult to detect without sophisticated monitoring tools.

    The researchers developed two methods to exploit this vulnerability: SWMA (Saturate-Workload-Modify-Accelerate) and LTMA (Lightweight Training Modulation Attack). The first method involves uploading a purpose-built CUDA kernel that flips between high-intensity compute mode and near-idle mode, while the second method buries the modulation inside a real LLM training run.

    The experiments conducted by the researchers show that both methods can produce significant power components in data centers, potentially destabilizing the grid. The first method produced power components from about 1.5 kHz up to 6 kHz, peaking on an RTX 4090, while the second method reached larger amplitude and blended into normal training noise.

    The authors of the paper frame their work as a blunt question: can "purely computational actions, executed as legitimate workloads, be weaponized to destabilize power infrastructure?" Their answer is yes, and they provide evidence for this claim through measurement and simulation experiments.

    While the researchers acknowledge that the physical experiments were conducted in controlled testbeds, the grid-scale damage came from simulation. The paper also notes that a real attack would need several things to line up at once: enough physically clustered GPUs, tight synchronization across them, modulation that survives the data center's power-conditioning stages, and a grid whose resonances happen to amplify the chosen frequency.

    The study has significant implications for cloud security and critical infrastructure protection. The researchers offer defenses for both sides at once: batteries, supercapacitors, and harmonic filtering on the power side; anomaly detection on GPU utilization and training schedules on the compute side.

    In conclusion, the newly discovered vulnerability in cloud infrastructure raises significant concerns about the potential risks and consequences of grid disruption without an exploit. The study highlights the importance of monitoring tools and advanced detection mechanisms to mitigate this risk.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/New-Vulnerability-in-Cloud-Infrastructure-Could-Allow-for-Grid-Disruption-Without-Exploit-ehn.shtml

  • https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html

  • https://cyberpress.org/bit2watt-threatens-power-grids/

  • https://cyberinsider.com/new-bit2watt-attack-uses-ai-gpu-workloads-to-destabilize-power-grids/


  • Published: Tue Jul 21 08:07:08 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us