9 Sources
[1]
Nvidia chips become the first GPUs to fall to Rowhammer bit-flip attacks
Nvidia is recommending a mitigation for customers of one of its GPU product lines that will degrade performance by up to 10 percent in a bid to protect users from exploits that could let hackers sabotage work projects and possibly cause other compromises. The move comes in response to an attack a
[2]
New Rowhammer attack silently corrupts AI models on GDDR6 Nvidia cards -- 'GPUHammer' attack drops AI accuracy from 80% to 0.1% on RTX A6000
A group of researchers has discovered a new attack called GPUHammer that can flip bits in the memory of NVIDIA GPUs, quietly corrupting AI models and causing serious damage, without ever touching the actual code or data input. Fortunately, Nvidia is already ahead of the bad actors and has put out
[3]
Nvidia A6000 GPUs flip memory bits if beaten by GPUHammer
The Rowhammer attack on computer memory is back, and for the first time, it's able to mess with bits in Nvidia GPUs, despite defenses designed to protect against this kind of hacking. Last week, Nvidia issued a security advisory, telling customers about the possible threat, which was disclosed to
[4]
NVIDIA shares guidance to defend GDDR6 GPUs against Rowhammer attacks
NVIDIA is warning users to activate System Level Error-Correcting Code mitigation to protect against Rowhammer attacks on graphical processors with GDDR6 memory. The company is reinforcing the recommendation as new research demonstrates a Rowhammer attack against an NVIDIA A6000 GPU (graphical
[5]
GPUHammer: New RowHammer Attack Variant Degrades AI Models on NVIDIA GPUs
NVIDIA is urging customers to enable System-level Error Correction Codes (ECC) as a defense against a variant of a RowHammer attack demonstrated against its graphics processing units (GPUs). "Risk of successful exploitation from RowHammer attacks varies based on DRAM device, platform, design
[6]
GPUHammer Attack on NVIDIA GDDR6: Corrupts AI Models
Graphics cards are no longer just about rendering games; they're core to today's AI workloads. That's why the newly discovered GPUHammer attack is grabbing attention. Developed by researchers at the University of Toronto, GPUHammer silently flips bits in GDDR6 memory on NVIDIA GPUs. Even a single
[7]
What is Rowhammer bit-flip attack which forced Nvidia to issue security alert
Researchers discovered that Nvidia's A6000 GPUs are prone to Rowhammer attacks. This allows hackers to tamper with user data on shared GPUs. Nvidia has issued an alert, advising users to enable Error Correction Code. Newer GPUs with GDDR7 or HBM3 memory have built-in protection. This vulnerability
[8]
Nvidia chips hacked, fall victim to Rowhammer bit-flip attacks; here's how to secure the AI GPUs
Canadian researchers have discovered a vulnerability, named GPU Hammer, in Nvidia A6000 GPUs, enabling Rowhammer bit-flip attacks. This attack allows malicious users to sabotage AI models by tampering with data, potentially degrading model accuracy significantly. Nvidia suggests enabling
[9]
Research Reveals GPUHammer's Capability To Destroy AI Model Accuracy On GDDR6 Memory GPUs From 80% To Just 0.1%
With just single-bit flips in DRAM banks, the GPUHammer can easily bring the GPU accuracy to less than 1% on high-end GPUs equipped GDDR6 VRAM. The researchers at the University of Toronto demonstrated how RowHammer attacks can easily bring down the AI Model accuracy of GPUs by inducing bit flips
Share
Copy Link
Researchers demonstrate the first Rowhammer attack on NVIDIA GPUs, potentially compromising AI model accuracy. NVIDIA recommends enabling ECC as a mitigation, despite performance trade-offs.
Researchers from the University of Toronto have unveiled GPUHammer, the first successful Rowhammer attack targeting NVIDIA GPUs with GDDR6 memory. This groundbreaking discovery extends the reach of Rowhammer vulnerabilities beyond traditional CPU memory, posing significant threats to AI model integrity and cloud computing environments
1
.
Source: Guru3D
GPUHammer exploits physical weaknesses in GDDR6 memory chips, allowing attackers to induce bit flips by repeatedly accessing specific memory rows. This technique can corrupt data stored in GPU memory without directly altering code or input data
2
.The researchers demonstrated the attack on an NVIDIA RTX A6000 GPU, a widely used model in high-performance computing and cloud services. By flipping a single bit in the exponent of a model weight, they were able to degrade AI model accuracy from 80% to 0.1%, effectively rendering the model useless
1
.
Source: Ars Technica
The potential impact of GPUHammer on AI applications is severe. Gururaj Saileshwar, an assistant professor at the University of Toronto and co-author of the study, likened the effect to "inducing catastrophic brain damage in the model" . This could lead to critical failures in various domains:
The attack is particularly concerning in shared GPU environments, such as cloud servers, where multiple users run workloads on the same hardware
2
.Related Stories
In response to the GPUHammer threat, NVIDIA has issued a security advisory recommending the activation of System-Level Error-Correcting Code (ECC) for affected GPU models
3
. ECC adds redundancy to memory, allowing for the detection and correction of bit flips4
.To enable ECC, users can use the NVIDIA command-line tool:
nvidia-smi -e 1
However, this mitigation comes with trade-offs:
2

Source: ET
The GPUHammer attack potentially affects a wide range of NVIDIA GPUs with GDDR6 memory, including models from the Ampere, Ada, Hopper, and Turing architectures
2
. However, newer GPUs like the RTX 5090 and H100 have built-in on-die ECC, providing inherent protection against this type of attack5
.As GPUs continue to evolve beyond gaming into AI, creative work, and productivity, the discovery of GPUHammer serves as a wake-up call for the industry. It highlights the need for ongoing research into hardware vulnerabilities and the development of robust security measures to protect the integrity of AI models and other critical applications relying on GPU acceleration.
Summarized by
Navi
[2]
[3]
[4]
05 Aug 2025•Technology

08 Sept 2025•Technology

21 Jul 2026•Technology

1
Technology

2
Policy and Regulation

3
Technology
