3 Sources
[1]
Malicious cloud customers can bring down the power grid
AI datacenters wreak havoc on the power grid under normal circumstances, so what happens if a bad actor controls all the GPUs and wants to cause harm? Cybersecurity researchers in China have devised a way for malicious tenants to attack their infrastructure provider, potentially causing blackouts
[2]
Bit2Watt: a cloud tenant could destabilise the power grid
Chinese researchers say a cloud customer needs no hack, no malware, and no stolen password to put a power grid under strain. Just a rented GPU and a workload built to misbehave. The catch is that the scariest numbers come from a simulation, not a real attack. AI data centres already strain the
[3]
Experts warn hackers could shut down entire power grids by hijacking cloud accounts
* Zhejiang University researchers warned GPU workloads could destabilize local grids and cause blackouts * Attackers could exploit ~1,000 GPUs to drain current and generate excess heat in systems * Theoretical attack dubbed Bit2Watt; mitigations include detecting malicious patterns and energy
Share
Copy Link
Chinese researchers at Zhejiang University have revealed a cyber-physical vulnerability called Bit2Watt that allows malicious cloud tenants to weaponize GPU workloads and potentially cause widespread blackouts. The theoretical attack exploits the power consumption patterns of AI datacenters, demonstrating how approximately 1,000 GPUs could create cascading failures affecting over 80% of large-scale power systems.
Researchers from Zhejiang University have uncovered a disturbing cyber-physical vulnerability that shows how malicious cloud tenants could weaponize GPU workloads to attack power infrastructure without needing hacks, malware, or stolen credentials. The theoretical attack, dubbed Bit2Watt, demonstrates how adversaries masquerading as legitimate cloud customers could launch specially crafted AI datacenter workloads designed to destabilize power grids and potentially cause widespread damage
1
.
Source: TechRadar
The research team—Zhouhao Ji, Kaikai Pan, and Wenyuan Xu—published their findings in a preprint paper titled "Bit2Watt: A Cyber-Physical Vulnerability Exploiting GPU Workloads Across Power and Computing Infrastructures," which has been accepted to a leading hardware-security conference. Their work builds on documented concerns from industry leaders about AI training's impact on electrical systems
1
.The attack exploits a fundamental characteristic of GPU computing: power consumption directly follows computational activity. When GPUs flip rapidly between intensive computation and idle states, they create controllable power oscillations at unprecedented speeds. The researchers demonstrated that GPU loads can reach modulation frequencies exceeding 6,000 Hz, dramatically higher than the few hertz observed in conventional household loads like air conditioners
1
.These high-frequency modulations can induce voltage excursions, harmonic distortion, and damping degradation in electrical infrastructure. The researchers showed two implementation methods: a purpose-built malicious workload and a more covert approach that hides the attack pattern inside legitimate AI training runs, making it harder for cloud providers to detect
2
.In their worst-case simulation, the researchers modeled an attack using approximately 1,000 GPUs pulsing in perfect synchronization against a 1-MW local power grid consisting mainly of distributed energy resources like photovoltaics. The results were alarming: the attack created a total harmonic distortion of 46.8 percent, wasting nearly half the electrical current on non-productive work while generating about 20 percent more heat than normal
1
.The simulation produced a negative damping ratio of -0.27, introducing instability into the system. When protective mechanisms trigger and computing loads are shed, the researchers warn this could initiate cascading failures, potentially leading to blackouts exceeding 80 percent in large-scale power systems
3
. However, as reporting on cloud attacks must stress, these figures come from simulations with worst-case assumptions rather than real-world attacks2
.The Bit2Watt research isn't based on pure theory—the underlying physics has already been documented by major industry players. Microsoft, Nvidia, and OpenAI noted in a 2025 research paper that power swings from GPU computation to data synchronization can cause physical damage to power grid infrastructure when their frequency spectrum harmonizes with critical utility frequencies
1
.Meta's paper on Llama 3 training similarly highlighted how tens of thousands of GPUs increasing or decreasing power consumption simultaneously can result in instant fluctuations of tens of megawatts, stretching the limits of the power grid
1
. Real-world incidents underscore these concerns: in July 2024, a fault near data-center-heavy Northern Virginia knocked approximately 1,500 megawatts of load off the grid at once, prompting regulators to establish a task force2
.Related Stories
Beyond threatening power infrastructure, the researchers identified a feedback mechanism they call Watt2Bit—a side-channel attack that exploits the electrical and thermal stress created by malicious workloads. The same power fluctuations that threaten to destabilize power grids can overheat servers, triggering denial of service events while enabling covert data exfiltration via power modulation
1
.As proof of concept, the team successfully recovered a 50-bit test sequence using frequency-shift keying (FSK) encoding, demonstrating that a power problem could simultaneously become both a denial of service and a data breach vector
1
.The attack is relatively covert because it operates within authorized workload execution paths and would likely evade standard cloud-provider monitoring frameworks, which sample power far too slowly to detect rapid flickering
1
2
.The researchers propose that infrastructure providers implement coordinated cyber-physical defenses that monitor for malicious computation patterns across both cyber and physical layers. They emphasize the urgent need for local energy buffering systems capable of handling power demand spikes
1
3
.
Source: The Register
The fundamental challenge is that there's no single bug to patch. As power and computing infrastructures converge, they remain operated by different organizations using separate monitoring tools. This gap between domains has no clear owner, even as the AI build-out accelerates. The researchers conclude that security must now address workload behavior, power electronics, and grid dynamics simultaneously—a fundamental shift for an industry where these systems have traditionally operated independently
1
2
.Summarized by
Navi
[1]
[2]
27 Jun 2025•Technology
30 Dec 2024•Technology

15 Aug 2025•Business and Economy

1
Policy and Regulation

2
Technology

3
Policy and Regulation
