# Bit2Watt: Synchronized GPU Power-Oscillation Attack Could Let Cloud Tenants Destabilize Power Grids

> Researchers Zhouhao Ji, Kaikai Pan, and Wenyuan Xu (Zhejiang University) disclosed 'Bit2Watt' (CHES 2026), a cyber-physical technique in which a malicious cloud tenant modulates ordinary GPU compute load — via a custom CUDA kernel (SWMA) or manipulated LLM training hyperparameters (LTMA) — to create 1.2-6 kHz power-draw oscillations that evade 1 Hz PDU and 450 Hz NVML telemetry. Simulated at 1,000 synchronized GPUs on a 1 MW, 90%-DER-penetration grid, the attack drove current THD to 46.8% (vs. the 13% IEC 61000-3-12 guideline) and pushed the damping ratio negative (-0.27), risking oscillatory instability and up to 81% cascading load-shed blackouts; a reverse 'Watt2Bit' path also enables EMI-based covert data exfiltration.

- **Published:** 2026-07-21T00:00:00Z
- **Last reviewed:** 2026-07-21T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1598
- **ID:** TL-2026-1598
- **Severity:** HIGH
- **Category:** THREAT_INTEL
- **Status:** TRACKING
- **Detections:** 9 · **IOCs:** 17 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Bit2Watt is a cyber-physical vulnerability, not a software exploit or CVE-bearing bug: it requires only legitimate, unprivileged GPU compute access inside a multi-tenant cloud or colocation environment. The adversary needs no malware, no stolen credentials, and no vendor-specific flaw — the attack surface is the physical coupling between GPU power draw and the electrical grid supplying the data center.

Two delivery methods are documented. The Synthetic Workload Modulation Attack (SWMA) uploads a custom CUDA kernel that toggles the GPU between high-intensity compute and near-idle states on a host-controlled schedule (using a `cudaMallocManaged` unified-memory flag as the switching signal), achieving power-modulation frequencies from roughly 1.5 kHz up to 6 kHz, peaking on an RTX 4090. The LLM Training Modulation Attack (LTMA) is the more dangerous variant: it embeds the same modulation logic inside an otherwise-legitimate LLM training job by adjusting batch size, auxiliary operations, or hyperparameters, producing lower-frequency (approximately 1.2-3 kHz) but higher-amplitude oscillations that closely resemble normal training noise and are far harder to flag as anomalous.

Standard data-center telemetry cannot see this signal: rack PDU counters sample once per second and NVIDIA's NVML telemetry samples at roughly 450 Hz, both far below the kHz-range modulation frequencies used by the attack. When many GPUs across a shared power domain are synchronized, the aggregate load behaves as a constant-power load with negative incremental resistance, exciting resonant modes in distributed-energy-resource (DER) inverter control loops rather than relying on classical synchronous-generator inertia (converter-dominated grid). In the researchers' simulated worst case — 1,000 synchronized GPUs on a 1 MW local grid at 90% DER penetration — current THD reached 46.8% (versus the 13% IEC 61000-3-12 stability guideline) and the system damping ratio went negative (-0.27), signaling onset of oscillatory instability; a companion wide-area/European grid simulation showed cascading protection trips producing up to 81% load shedding across 13 stages. Locally, the induced harmonics also stress voltage-regulator modules, UPS units, PDUs, and switching power supplies inside the data center itself, wasting substantial current as non-productive heat (~20% excess) and creating a feedback denial-of-service risk (over-temperature/over-current protection trips) back onto the AI cluster — termed the 'Watt2Bit' feedback path.

The same physical channel runs in reverse as a covert side channel: encoding a logical '1' as a 2 kHz power tone and a '0' as 200 Hz, the researchers used a near-field EMI antenna to recover a 50-bit test sequence with zero errors, demonstrating that GPU power modulation can be used for both cyber-physical disruption and covert exfiltration from air-gapped or isolated compute environments.

The attack's principal real-world constraint is tight timing synchronization across many independently scheduled, physically distributed GPUs/tenants — the paper itself concedes this remains 'an open problem,' and introducing 100 microsecond (SD) timing jitter reduced achieved modulation amplitude by roughly 20%. No CVE has been assigned and no vendor patch is applicable; this is an architectural exposure from coupling volatile, unauthenticated multi-tenant GPU compute loads to inverter-heavy, low-inertia electrical grids, not a fixable code defect. It follows a related August 2025 Microsoft/OpenAI/NVIDIA paper that warned synchronized AI training power swings could physically damage grid equipment when their frequency aligns with utility critical frequencies.

## MITRE ATT&CK

- T1592 Gather Victim Host Information
- T1587 Develop Capabilities
- T1583 Acquire Infrastructure
- T1078 Valid Accounts
- T1204 User Execution
- T1129 Shared Modules
- T1685 Disable or Modify Tools
- T1036 Masquerading
- T1082 System Information Discovery
- T1526 Cloud Service Discovery
- T1119 Automated Collection
- T1005 Data from Local System
- T1571 Non-Standard Port
- T1052 Exfiltration Over Physical Medium
- T1020 Automated Exfiltration
- T1496 Resource Hijacking
- T1499 Endpoint Denial of Service
- T1489 Service Stop
- T1529 System Shutdown/Reboot
- T1495 Firmware Corruption

## Sources

- [New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit](https://thehackernews.com/2026/07/new-bit2watt-attack-could-let-cloud.html)
- [Bit2Watt: A Cyber-Physical Vulnerability Exploiting GPU Workloads Across Power and Computing Infrastructures](https://arxiv.org/abs/2607.05993)
- [Bit2Watt: A Cyber-Physical Vulnerability Exploiting GPU Workloads Across Power and Computing Infrastructures (HTML)](https://arxiv.org/html/2607.05993)
- [Malicious cloud customers can bring down the power grid](https://www.theregister.com/ai-and-ml/2026/07/20/malicious-cloud-customers-can-bring-down-the-power-grid/5275193)
- [Bit2Watt Attack Turns AI Data Centers Into Cyber-Physical Threats to Local Power Grids](https://gbhackers.com/bit2watt-attack-turns-ai-data-centers/)
- [Experts warn hackers could shut down entire power grids by hijacking cloud accounts](https://www.techradar.com/pro/security/experts-warn-hackers-could-shut-down-entire-power-grids-by-hijacking-cloud-accounts)
- [Bit2Watt frames GPU workloads as a grid attack surface](https://news-pravda.com/ukraine/2026/07/21/2456848.html)
- [New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit](https://www.guardianmssp.com/2026/07/21/new-bit2watt-attack-could-let-cloud-tenants-disrupt-power-grids-without-an-exploit/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1598
