AI Tools Let Anyone Rewrite DNA Evidence in 45 Minutes Through Crime-Lab Software Flaw

2 Sources

Share

A critical software vulnerability in Thermo Fisher Scientific's forensic tools allowed AI-powered tampering of DNA evidence files without leaving traces. Researchers used Anthropic's Claude to modify DNA profiles in just 45 minutes, exposing 30 years of casework to potential manipulation. The patch only protects future files.

AI Tools Expose Critical Flaw in Forensic Data Security

A software vulnerability in widely-used crime-lab equipment has exposed a disturbing reality: AI tools can rewrite DNA evidence in under an hour, leaving no detectable trace. Thermo Fisher Scientific, which supplies forensic analysis tools to most American crime labs, patched the flaw in July 2026 after researchers disclosed it in May. The weakness, identified as CVE-2026-17583 with a severity score of 8.2, affects several Applied Biosystems instruments that convert physical DNA samples into digital files

1

.

Nathan Adams, a systems engineer at Forensic Bioinformatics, demonstrated how Anthropic's Claude made exploitation trivial. He wrote working code in approximately 45 minutes that merged two people's DNA profiles into a single file. The manipulated file appeared untouched since 2015 and triggered no warnings in standard analysis software

1

. Adams even cracked files sealed with advanced encryption by finding a decryption key publicly available online

2

.

Undermining Decades of Casework Through Digital Manipulation

The scope unsettles forensic scientists. Researchers believe this crime-lab software flaw has existed in .fsa and .hid files since 1995, potentially compromising roughly 30 years of casework

1

. An attacker with insider access could modify DNA profiles to remove a suspect's genetic markers or add an innocent person's data to crime-scene evidence

2

.

Laura Gaydosh Combs, a University of New Haven forensic scientist involved in the research, framed the problem starkly: "Effectively, what we have are data files that are legitimately referred to as the gold standard of forensic science that lack the same level of tamper-evident safeguards that we require for a paper bag"

2

. The researchers found no method to detect whether past files had been altered, leaving three decades of digital records unverifiable

1

.

Thermo Fisher's Patch Protects Only Future Evidence

Thermo Fisher Scientific responded by implementing digital signatures across five supported product lines. These signatures allow labs to verify file integrity going forward. However, three older product lines past end-of-life receive no updates. For labs unable to upgrade, the company recommends basic cybersecurity practices: chain of custody documentation, encrypted storage, least privilege access controls, and limited network exposure

1

.

The fix carries a critical limitation expressed in two words: "moving forward." The company's security bulletin does not clarify whether labs can retroactively verify files created before the update. This draws a clear line protecting future evidence while leaving historical casework in limbo. Thermo Fisher Scientific stated it found no instances where anyone exploited the vulnerability, though researchers confirmed they could not detect such tampering if it occurred

1

2

.

Criminal Justice Systems Face Growing AI-Powered Threats

Executing this attack requires legitimate lab access, either locally or remotely, plus understanding of DNA testing workflows. This points to insider threats or sophisticated intruders rather than opportunistic hackers

1

. Sarah Chu, director of policy and reform at the Perlmutter Center for Legal Justice who contributed to the research, noted the systemic problem: "Lessons learned from other industries haven't been imported into forensic science in a serious way. We've been behind the ball for so long"

2

.

The lack of centralized regulation has left over 200 labs operating with inconsistent security measures

2

. DNA evidence remains the proof juries trust most. A digital file vulnerable to silent modification undermines that trust at its foundation. AI has accelerated both the speed and accessibility of such attacks, making what once required specialized expertise achievable in 45 minutes with a chatbot. Physical samples remain secure in lab freezers, but the digital files courts rely on now carry signatures only from today forward

1

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved