← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

GPUThor Rowhammer Attack Bypasses NVIDIA ECC on Ampere GPUs for Root Access

🔄 Updated 2h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • GPUThor bypasses NVIDIA ECC on Ampere GPUs.
  • It achieves high bit-flip rates, enabling DoS and root access.
  • Attack demonstrated on RTX A4000, A4500, A5000, and A6000 GPUs.
  • Exploitable bit flips are possible in approximately 1.1 minutes.

New Rowhammer Attack Targets NVIDIA GPUs

A new Rowhammer attack, named GPUThor, has been disclosed by researchers at the University of Toronto. This attack is capable of bypassing error-correcting code (ECC) protections on NVIDIA GPUs, leading to denial-of-service (DoS) and root-level privilege escalation. The findings were detailed in a paper published by the university.

Improved Bit-Flip Rates

GPUThor achieves significantly higher bit-flip rates compared to earlier Rowhammer concepts like GPUHammer and GPUBreach, which became less effective after ECC was introduced. The attack was successfully demonstrated against NVIDIA Ampere-class workstation GPUs with GDDR6 memory, including the RTX A4000, RTX A4500, RTX A5000, and RTX A6000, which are commonly used in AI and cloud infrastructure.

The researchers adjusted GPUThor to use a non-uniform hammering pattern that avoids activating GDDR6’s Target Row Refresh (TRR) mitigations. This was achieved by accounting for undocumented GPU behaviors related to memory request coalescing and TRR activation frequency. This adjustment resulted in 6.6 times more aggressor-row activations and between 72,000 and 377,000 flips per GB on tested GPUs without ECC, which is thousands of times higher than GPUHammer.

Bypassing ECC and Practical Exploitation

With ECC enabled, GPUThor generated 387 double-bit errors that ECC detected but could not correct, and two triple-bit errors that ECC incorrectly repaired, leading to data corruption. The increased bit-flip rates make finding an exploitable bit flip practical within approximately 1.1 minutes, a significant reduction from the 21.9 hours required by GPUHammer.

The University of Toronto researchers demonstrated that GPUThor can induce a DoS state on an ECC-enabled RTX A6000.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~10 min · 8 stories · Aug 26

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Researchers at the University of Toronto developed GPUThor, a new Rowhammer attack that bypasses NVIDIA's ECC protections on Ampere-class GPUs, enabling denial-of-service and root-level privilege escalation. This attack significantly increases bit-flip rates compared to previous methods, making exploitation practical within minutes.