Threat reportThreat IntelligenceTL-2026-1250

Hardware Trojan Backdoors in Chip Design Detected via AI-Assisted Verification (VeriChat)

MONITORING

Hardware Trojan Backdoors in Chip Design Detected via (TL-2026-1250), also tracked as VeriChat AES S-Box Hardware Trojan Demonstration, is a informational-severity tracked intrusion set, first published 2026-07-13. It has no confirmed attribution, affects Academic Research Demonstration Synthesizable AES S-Box RTL IP block, maps to 14 MITRE ATT&CK techniques (T1005, T1011, T1027), and is covered by 9 detection rules and 15 indicators of compromise.

Severity
INFORMATIONALAssessed severity
CVEs
0None referenced
Techniques
14MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
15Indicators of compromise

Key facts for TL-2026-1250

Threat ID
TL-2026-1250
Also known as
VeriChat AES S-Box Hardware Trojan Demonstration
Severity
INFORMATIONAL
Status
MONITORING
Category
THREAT_INTEL
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
semi-conductors, electronics manufacturing, defense industrial base, critical infrastructure, academia
Target regions
North America
Detection rules
9
Indicators of compromise
15

Malware and tooling in Hardware Trojan Backdoors in Chip Design Detected via

Malware and tooling: AES S-Box Hardware Trojan (research demonstration), Icarus Verilog, SymbiYosys, VeriChat, Yosys

How Hardware Trojan Backdoors in Chip Design Detected via works

University of Florida researchers demonstrated a hardware Trojan hidden in an AES S-Box IP block that activates on a specific 3-byte trigger sequence (0xDE, 0xAD, 0xBE) and leaks the AES secret key one bit at a time via a status-light side channel over eight clock cycles, with the trigger firing spuriously only about 6 times per 100 million cycles. The team built VeriChat, a retrieval-augmented, three-agent conversational AI assistant trained on a curated library of 28,221 hardware security papers and integrated with open-source EDA tools (Icarus Verilog, Yosys, SymbiYosys), to autonomously identify, simulate, and formally prove such covert key-leakage vulnerabilities, achieving 87.73% factual (faithfulness) accuracy and a 92% false-premise rejection rate.

This is an academic hardware-security research demonstration, not an in-the-wild exploited vulnerability. Researchers at the University of Florida (Dipayan Saha, Khan Thamid Hasan, Shams Tarek, Sujan Kumar Saha, Mark Tehranipoor, Farimah Farahmandi) published 'VeriChat: An Agentic Conversational AI Assistant for Hardware Security Verification' (arXiv:2607.01668, submitted 2026-07-02, accepted for presentation at IEEE COINS 2026). The paper's centerpiece case study is a hardware Trojan implanted in a synthesizable AES S-Box RTL IP block: a sequential trigger circuit continuously monitors an input/control bus for the exact 3-byte pattern 0xDE, 0xAD, 0xBE. Once that trigger sequence is observed, a payload state machine begins exfiltrating the AES round-key material one bit at a time by toggling an otherwise-benign status/diagnostic LED output over eight consecutive clock cycles, allowing a physically-proximate or optically-instrumented observer to reconstruct the secret key without any digital output path or overt communication channel. The trigger's false-activation rate on random/benign traffic is characterized as roughly 6 in 100,000,000 cycles, making it statistically invisible to conventional functional and random-pattern verification. To detect this class of Trojan, the researchers built VeriChat: a retrieval-first, three-agent LLM pipeline (question reformulation agent, evidence-gathering agent, answer-generation agent) grounded in a curated corpus of 28,221 hardware-security papers plus live web retrieval, explicitly designed to minimize hallucination and maintain traceable evidence citations. VeriChat is wired into a four-stage automated verification pipeline over the target RTL: (1) syntax verification (Verilog/RTL compiles cleanly via Icarus Verilog), (2) synthesis analysis (Yosys-based structural/memory-element counting to flag unexplained state), (3) simulation-based trigger-sequence testing (driving the exact suspected trigger inputs and observing payload behavior), and (4) formal verification (SymbiYosys-based mathematical proof that the key-bit leakage path exists and is reachable). Expert human review scored VeriChat's factual accuracy at 87.73%, and a false-claim/false-premise rejection test (probing the tool with invented, nonexistent hardware-security concepts such as 'Metamaterial Resonance Shielding') showed a 92% correct-refusal rate, both reported as outperforming leading proprietary general-purpose LLMs on the same evaluation. This threat is retained by the harness as a supply-chain/hardware-trust research signal: it has no CVE, no shipping commercial product, and no observed in-the-wild exploitation, but it is directly relevant to defenders and hardware security teams evaluating third-party silicon IP blocks, chip supply-chain integrity, and next-generation AI-assisted RTL/Trojan-detection tooling.

MITRE ATT&CK techniques used in TL-2026-1250

Collection

T1005 Data from Local System; T1119 Automated Collection

Exfiltration

T1011 Exfiltration Over Other Network Medium; T1052 Exfiltration Over Physical Medium

Defense Evasion

T1027 Obfuscated Files or Information

initial-access

T1195 Supply Chain Compromise; T1195.003 Compromise Hardware Supply Chain

Initial Access

T1195 Supply Chain Compromise; T1199 Trusted Relationship; T1200 Hardware Additions

Command and Control

T1205 Traffic Signaling

Impact

T1495 Firmware Corruption

Credential Access

T1528 Steal Application Access Token

defense-impairment

T1601 Modify System Image; T1601.001 Patch System Image

Affected products and versions in Hardware Trojan Backdoors in Chip Design Detected via

  • Academic Research Demonstration — Synthesizable AES S-Box RTL IP block (research testbed)
    Vulnerable versions: Trojan-implanted research IP used as VeriChat case study
    Fixed in: N/A — proof-of-concept research artifact, not a shipping product

Remediation for Hardware Trojan Backdoors in Chip Design Detected via

Immediate actions

  • Treat third-party/vendor RTL and hard IP blocks (especially crypto cores like AES S-Box implementations) as untrusted supply-chain artifacts requiring independent verification before tapeout or FPGA deployment
  • Run suspicious sequential triggers against known 'magic byte' patterns (e.g. 0xDEADBEEF-style constants) during pre-silicon security review
  • Audit any 'diagnostic', 'status', or 'debug' output pins (LEDs, GPIOs, JTAG) on cryptographic IP for unexpected data-dependent toggling behavior

Workarounds

  • Where third-party IP cannot be independently verified, physically isolate or shield diagnostic/status output pins on cryptographic modules from external observation

Longer-term hardening

  • Integrate AI-assisted retrieval-augmented verification tools (e.g. VeriChat-style syntax/synthesis/simulation/formal-verification pipelines) into standard pre-tapeout hardware security sign-off
  • Adopt formal verification (e.g. SymbiYosys) as a mandatory gate for licensed third-party crypto IP, not just functional simulation
  • Establish an internal curated corpus of hardware-Trojan case studies (e.g. Trust-Hub benchmark suite) to train/validate in-house detection tooling
  • Require IP vendors to provide golden netlists and formal non-interference proofs for security-critical blocks

Weaknesses (CWE) in Hardware Trojan Backdoors in Chip Design Detected via

CWE-507, CWE-1234, CWE-1244, CWE-1245, CWE-1300

Timeline of Hardware Trojan Backdoors in Chip Design Detected via

  • University of Florida research team submits 'VeriChat: An Agentic Conversational AI Assistant for Hardware Security Verification' to arXiv (2607.01668).
  • MITRE ATT&CK mapping expanded across Resource Development, Initial Access, Persistence, Defense Evasion, Credential Access, Collection, Exfiltration, Command and Control, and Impact tactics to comprehensively model the hardware-Trojan supply-chain threat, including the T1199 trusted-relationship IP-licensing vector, T1027 trigger-logic obfuscation, and T1205 traffic-signaling-style covert activation.
  • Threat mapped to CWE-507 (Trojan Horse) and CWE-1234/1244/1245/1300 (hardware debug/lock-override and side-channel exposure weaknesses) based on the trigger-and-exfiltration mechanism described in arXiv:2607.01668.
  • VeriChat's four-stage pipeline (syntax verification via Icarus Verilog, synthesis analysis via Yosys, simulation-based trigger testing, and formal verification via SymbiYosys) is documented, alongside its 87.73% factual accuracy and 92% false-premise rejection rate.
  • Analysis confirms the AES S-Box Trojan uses a 3-byte (0xDE, 0xAD, 0xBE) sequential trigger and an 8-cycle status-light bit-serial key exfiltration payload, with a ~6-in-100,000,000-cycle false trigger rate.
  • TL-Intel Harness RESEARCH phase begins deep-dive analysis of the arXiv paper, CWE mappings, and MITRE ATT&CK context.
  • TL-Intel Harness HUNT phase ingests the Help Net Security article via RSS feed monitoring and creates threat skeleton TL-2026-1250.
  • Help Net Security publishes coverage of the VeriChat research and its AES S-Box hardware Trojan case study.

Sources cited for Hardware Trojan Backdoors in Chip Design Detected via

Detection coverage for TL-2026-1250

As of 2026-07-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1250 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
15 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats