# Hardware Trojan Backdoors in Chip Design Detected via AI-Assisted Verification (VeriChat)

> University of Florida researchers demonstrated a hardware Trojan hidden in an AES S-Box IP block that activates on a specific 3-byte trigger sequence (0xDE, 0xAD, 0xBE) and leaks the AES secret key one bit at a time via a status-light side channel over eight clock cycles, with the trigger firing spuriously only about 6 times per 100 million cycles. The team built VeriChat, a retrieval-augmented, three-agent conversational AI assistant trained on a curated library of 28,221 hardware security papers and integrated with open-source EDA tools (Icarus Verilog, Yosys, SymbiYosys), to autonomously identify, simulate, and formally prove such covert key-leakage vulnerabilities, achieving 87.73% factual (faithfulness) accuracy and a 92% false-premise rejection rate.

- **Published:** 2026-07-13T00:00:00Z
- **Last reviewed:** 2026-07-13T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1250
- **ID:** TL-2026-1250
- **Severity:** INFORMATIONAL
- **Category:** THREAT_INTEL
- **Status:** MONITORING
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)

## Description

This is an academic hardware-security research demonstration, not an in-the-wild exploited vulnerability. Researchers at the University of Florida (Dipayan Saha, Khan Thamid Hasan, Shams Tarek, Sujan Kumar Saha, Mark Tehranipoor, Farimah Farahmandi) published 'VeriChat: An Agentic Conversational AI Assistant for Hardware Security Verification' (arXiv:2607.01668, submitted 2026-07-02, accepted for presentation at IEEE COINS 2026). The paper's centerpiece case study is a hardware Trojan implanted in a synthesizable AES S-Box RTL IP block: a sequential trigger circuit continuously monitors an input/control bus for the exact 3-byte pattern 0xDE, 0xAD, 0xBE. Once that trigger sequence is observed, a payload state machine begins exfiltrating the AES round-key material one bit at a time by toggling an otherwise-benign status/diagnostic LED output over eight consecutive clock cycles, allowing a physically-proximate or optically-instrumented observer to reconstruct the secret key without any digital output path or overt communication channel. The trigger's false-activation rate on random/benign traffic is characterized as roughly 6 in 100,000,000 cycles, making it statistically invisible to conventional functional and random-pattern verification. To detect this class of Trojan, the researchers built VeriChat: a retrieval-first, three-agent LLM pipeline (question reformulation agent, evidence-gathering agent, answer-generation agent) grounded in a curated corpus of 28,221 hardware-security papers plus live web retrieval, explicitly designed to minimize hallucination and maintain traceable evidence citations. VeriChat is wired into a four-stage automated verification pipeline over the target RTL: (1) syntax verification (Verilog/RTL compiles cleanly via Icarus Verilog), (2) synthesis analysis (Yosys-based structural/memory-element counting to flag unexplained state), (3) simulation-based trigger-sequence testing (driving the exact suspected trigger inputs and observing payload behavior), and (4) formal verification (SymbiYosys-based mathematical proof that the key-bit leakage path exists and is reachable). Expert human review scored VeriChat's factual accuracy at 87.73%, and a false-claim/false-premise rejection test (probing the tool with invented, nonexistent hardware-security concepts such as 'Metamaterial Resonance Shielding') showed a 92% correct-refusal rate, both reported as outperforming leading proprietary general-purpose LLMs on the same evaluation. This threat is retained by the harness as a supply-chain/hardware-trust research signal: it has no CVE, no shipping commercial product, and no observed in-the-wild exploitation, but it is directly relevant to defenders and hardware security teams evaluating third-party silicon IP blocks, chip supply-chain integrity, and next-generation AI-assisted RTL/Trojan-detection tooling.

## MITRE ATT&CK

- T1195 Supply Chain Compromise
- T1195.003 Compromise Hardware Supply Chain
- T1195 Supply Chain Compromise
- T1200 Hardware Additions
- T1601 Modify System Image
- T1601.001 Patch System Image
- T1528 Steal Application Access Token
- T1005 Data from Local System
- T1119 Automated Collection
- T1052 Exfiltration Over Physical Medium
- T1011 Exfiltration Over Other Network Medium
- T1199 Trusted Relationship
- T1027 Obfuscated Files or Information
- T1205 Traffic Signaling
- T1495 Firmware Corruption

## Sources

- [Hardware security AI assistant flags hidden backdoors](https://www.helpnetsecurity.com/2026/07/13/hardware-security-ai-assistant-hidden-backdoors/)
- [VeriChat: An Agentic Conversational AI Assistant for Hardware Security Verification (arXiv:2607.01668)](https://arxiv.org/abs/2607.01668)
- [CWE-507: Trojan Horse](https://cwe.mitre.org/data/definitions/507.html)
- [CWE-1234: Hardware Internal or Debug Modes Allow Override of Locks](https://cwe.mitre.org/data/definitions/1234.html)
- [MITRE ATT&CK for ICS — Supply Chain Compromise (T0862)](https://attack.mitre.org/techniques/T0862/)
- [MITRE ATT&CK Enterprise — Supply Chain Compromise: Compromise Hardware Supply Chain (T1195.003)](https://attack.mitre.org/techniques/T1195/003/)
- [MITRE ATT&CK for ICS — System Firmware (T0857)](https://attack.mitre.org/techniques/T0857/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1250
