Threat reportThreat IntelligenceTL-2026-1250
Hardware Trojan Backdoors in Chip Design Detected via AI-Assisted Verification (VeriChat)
Hardware Trojan Backdoors in Chip Design Detected via (TL-2026-1250), also tracked as VeriChat AES S-Box Hardware Trojan Demonstration, is a informational-severity tracked intrusion set, first published 2026-07-13. It has no confirmed attribution, affects Academic Research Demonstration Synthesizable AES S-Box RTL IP block, maps to 14 MITRE ATT&CK techniques (T1005, T1011, T1027), and is covered by 9 detection rules and 15 indicators of compromise.
- Severity
- INFORMATIONALAssessed severity
- CVEs
- 0None referenced
- Techniques
- 14MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-1250
- Threat ID
- TL-2026-1250
- Also known as
- VeriChat AES S-Box Hardware Trojan Demonstration
- Severity
- INFORMATIONAL
- Status
- MONITORING
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- semi-conductors, electronics manufacturing, defense industrial base, critical infrastructure, academia
- Target regions
- North America
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in Hardware Trojan Backdoors in Chip Design Detected via
Malware and tooling: AES S-Box Hardware Trojan (research demonstration), Icarus Verilog, SymbiYosys, VeriChat, Yosys
How Hardware Trojan Backdoors in Chip Design Detected via works
University of Florida researchers demonstrated a hardware Trojan hidden in an AES S-Box IP block that activates on a specific 3-byte trigger sequence (0xDE, 0xAD, 0xBE) and leaks the AES secret key one bit at a time via a status-light side channel over eight clock cycles, with the trigger firing spuriously only about 6 times per 100 million cycles. The team built VeriChat, a retrieval-augmented, three-agent conversational AI assistant trained on a curated library of 28,221 hardware security papers and integrated with open-source EDA tools (Icarus Verilog, Yosys, SymbiYosys), to autonomously identify, simulate, and formally prove such covert key-leakage vulnerabilities, achieving 87.73% factual (faithfulness) accuracy and a 92% false-premise rejection rate.
This is an academic hardware-security research demonstration, not an in-the-wild exploited vulnerability. Researchers at the University of Florida (Dipayan Saha, Khan Thamid Hasan, Shams Tarek, Sujan Kumar Saha, Mark Tehranipoor, Farimah Farahmandi) published 'VeriChat: An Agentic Conversational AI Assistant for Hardware Security Verification' (arXiv:2607.01668, submitted 2026-07-02, accepted for presentation at IEEE COINS 2026). The paper's centerpiece case study is a hardware Trojan implanted in a synthesizable AES S-Box RTL IP block: a sequential trigger circuit continuously monitors an input/control bus for the exact 3-byte pattern 0xDE, 0xAD, 0xBE. Once that trigger sequence is observed, a payload state machine begins exfiltrating the AES round-key material one bit at a time by toggling an otherwise-benign status/diagnostic LED output over eight consecutive clock cycles, allowing a physically-proximate or optically-instrumented observer to reconstruct the secret key without any digital output path or overt communication channel. The trigger's false-activation rate on random/benign traffic is characterized as roughly 6 in 100,000,000 cycles, making it statistically invisible to conventional functional and random-pattern verification. To detect this class of Trojan, the researchers built VeriChat: a retrieval-first, three-agent LLM pipeline (question reformulation agent, evidence-gathering agent, answer-generation agent) grounded in a curated corpus of 28,221 hardware-security papers plus live web retrieval, explicitly designed to minimize hallucination and maintain traceable evidence citations. VeriChat is wired into a four-stage automated verification pipeline over the target RTL: (1) syntax verification (Verilog/RTL compiles cleanly via Icarus Verilog), (2) synthesis analysis (Yosys-based structural/memory-element counting to flag unexplained state), (3) simulation-based trigger-sequence testing (driving the exact suspected trigger inputs and observing payload behavior), and (4) formal verification (SymbiYosys-based mathematical proof that the key-bit leakage path exists and is reachable). Expert human review scored VeriChat's factual accuracy at 87.73%, and a false-claim/false-premise rejection test (probing the tool with invented, nonexistent hardware-security concepts such as 'Metamaterial Resonance Shielding') showed a 92% correct-refusal rate, both reported as outperforming leading proprietary general-purpose LLMs on the same evaluation. This threat is retained by the harness as a supply-chain/hardware-trust research signal: it has no CVE, no shipping commercial product, and no observed in-the-wild exploitation, but it is directly relevant to defenders and hardware security teams evaluating third-party silicon IP blocks, chip supply-chain integrity, and next-generation AI-assisted RTL/Trojan-detection tooling.
MITRE ATT&CK techniques used in TL-2026-1250
Collection
T1005 Data from Local System; T1119 Automated Collection
Exfiltration
T1011 Exfiltration Over Other Network Medium; T1052 Exfiltration Over Physical Medium
Defense Evasion
T1027 Obfuscated Files or Information
initial-access
T1195 Supply Chain Compromise; T1195.003 Compromise Hardware Supply Chain
Initial Access
T1195 Supply Chain Compromise; T1199 Trusted Relationship; T1200 Hardware Additions
Command and Control
Impact
Credential Access
T1528 Steal Application Access Token
defense-impairment
Affected products and versions in Hardware Trojan Backdoors in Chip Design Detected via
- Academic Research Demonstration — Synthesizable AES S-Box RTL IP block (research testbed)
Vulnerable versions: Trojan-implanted research IP used as VeriChat case study
Fixed in: N/A — proof-of-concept research artifact, not a shipping product
Remediation for Hardware Trojan Backdoors in Chip Design Detected via
Immediate actions
- Treat third-party/vendor RTL and hard IP blocks (especially crypto cores like AES S-Box implementations) as untrusted supply-chain artifacts requiring independent verification before tapeout or FPGA deployment
- Run suspicious sequential triggers against known 'magic byte' patterns (e.g. 0xDEADBEEF-style constants) during pre-silicon security review
- Audit any 'diagnostic', 'status', or 'debug' output pins (LEDs, GPIOs, JTAG) on cryptographic IP for unexpected data-dependent toggling behavior
Workarounds
- Where third-party IP cannot be independently verified, physically isolate or shield diagnostic/status output pins on cryptographic modules from external observation
Longer-term hardening
- Integrate AI-assisted retrieval-augmented verification tools (e.g. VeriChat-style syntax/synthesis/simulation/formal-verification pipelines) into standard pre-tapeout hardware security sign-off
- Adopt formal verification (e.g. SymbiYosys) as a mandatory gate for licensed third-party crypto IP, not just functional simulation
- Establish an internal curated corpus of hardware-Trojan case studies (e.g. Trust-Hub benchmark suite) to train/validate in-house detection tooling
- Require IP vendors to provide golden netlists and formal non-interference proofs for security-critical blocks
Weaknesses (CWE) in Hardware Trojan Backdoors in Chip Design Detected via
Timeline of Hardware Trojan Backdoors in Chip Design Detected via
- University of Florida research team submits 'VeriChat: An Agentic Conversational AI Assistant for Hardware Security Verification' to arXiv (2607.01668).
- MITRE ATT&CK mapping expanded across Resource Development, Initial Access, Persistence, Defense Evasion, Credential Access, Collection, Exfiltration, Command and Control, and Impact tactics to comprehensively model the hardware-Trojan supply-chain threat, including the T1199 trusted-relationship IP-licensing vector, T1027 trigger-logic obfuscation, and T1205 traffic-signaling-style covert activation.
- Threat mapped to CWE-507 (Trojan Horse) and CWE-1234/1244/1245/1300 (hardware debug/lock-override and side-channel exposure weaknesses) based on the trigger-and-exfiltration mechanism described in arXiv:2607.01668.
- VeriChat's four-stage pipeline (syntax verification via Icarus Verilog, synthesis analysis via Yosys, simulation-based trigger testing, and formal verification via SymbiYosys) is documented, alongside its 87.73% factual accuracy and 92% false-premise rejection rate.
- Analysis confirms the AES S-Box Trojan uses a 3-byte (0xDE, 0xAD, 0xBE) sequential trigger and an 8-cycle status-light bit-serial key exfiltration payload, with a ~6-in-100,000,000-cycle false trigger rate.
- TL-Intel Harness RESEARCH phase begins deep-dive analysis of the arXiv paper, CWE mappings, and MITRE ATT&CK context.
- TL-Intel Harness HUNT phase ingests the Help Net Security article via RSS feed monitoring and creates threat skeleton TL-2026-1250.
- Help Net Security publishes coverage of the VeriChat research and its AES S-Box hardware Trojan case study.
Sources cited for Hardware Trojan Backdoors in Chip Design Detected via
- Hardware security AI assistant flags hidden backdoors
- VeriChat: An Agentic Conversational AI Assistant for Hardware Security Verification (arXiv:2607.01668)
- CWE-507: Trojan Horse
- CWE-1234: Hardware Internal or Debug Modes Allow Override of Locks
- MITRE ATT&CK for ICS — Supply Chain Compromise (T0862)
- MITRE ATT&CK Enterprise — Supply Chain Compromise: Compromise Hardware Supply Chain (T1195.003)
- MITRE ATT&CK for ICS — System Firmware (T0857)
- IEEE International Conference on Omni-layer Intelligent Systems (COINS 2026)
Detection coverage for TL-2026-1250
As of 2026-07-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1250 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.