Security researchers have disclosed a new hardware-level attack dubbed DDRop that undermines the memory protection guarantees at the core of Intel Trust Domain Extensions (TDX) and AMD Secure Encrypted Virtualization Secure Nested Paging (SEV-SNP), two of the industry’s leading confidential computing technologies.
Confidential computing is designed to protect sensitive workloads, such as cloud-hosted databases or cryptographic key material, from a compromised hypervisor or malicious cloud administrator by encrypting memory contents and enforcing integrity checks. DDRop targets this model directly by manipulating how writes reach a server’s physical memory.
According to the researchers, the attack works by silently dropping writes destined for memory. Instead of updating the encrypted data as expected, the processor continues reading an older, previously valid version of that encrypted memory. Because the data was legitimately encrypted at an earlier point, standard integrity checks do not flag it as tampered, allowing an attacker to effectively roll back sensitive data without detection.
How the Attack Is Carried Out
Exploiting DDRop is not trivial. The attack requires an adversary who already has control over the software running on the target server, combined with brief physical or logically-privileged access to the machine. During that access window, the attacker inserts a small hardware circuit that interferes with the memory write path, enabling the write-dropping behavior that the attack depends on.
This combination of software compromise and hardware tampering places DDRop in a category of sophisticated, targeted attacks rather than a mass-exploitable remote vulnerability. It is most relevant to threat models involving insider access, supply chain tampering, or adversaries with physical proximity to data center hardware.
Why It Matters
Confidential computing is increasingly relied upon by cloud providers and enterprises to protect workloads even from privileged insiders and compromised host software. DDRop demonstrates that memory write-dropping at the hardware layer can bypass the encryption and integrity assurances that TDX and SEV-SNP are built to provide, effectively allowing stale, non-current data to be treated as trustworthy.
Organizations relying on Intel TDX or AMD SEV-SNP for sensitive workloads should watch for vendor guidance and mitigations, and reassess physical security controls around hardware hosting confidential computing environments, since the attack’s hardware insertion step depends on access to the physical machine.
