<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/gputhor-hardware-attack-can-root-nvidia-gpu-systems-utdoxclks" -->

---
title: GPUThor hardware attack can root Nvidia GPU systems
description: Researchers from the University of Toronto have developed GPUThor, a new Rowhammer-style attack that breaks through the ECC protection on Nvidia GPUs,...
canonical: https://daily.dev/posts/gputhor-hardware-attack-can-root-nvidia-gpu-systems-utdoxclks
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: GPUThor hardware attack can root Nvidia GPU systems | daily.dev
og:description: Researchers from the University of Toronto have developed GPUThor, a new Rowhammer-style attack that breaks through the ECC protection on Nvidia GPUs,...
og:url: https://daily.dev/posts/gputhor-hardware-attack-can-root-nvidia-gpu-systems-utdoxclks
og:image: https://api.daily.dev/og/posts/UTdOxCLKS.png
og:image:alt: GPUThor hardware attack can root Nvidia GPU systems
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# GPUThor hardware attack can root Nvidia GPU systems

**[CSO Online](https://daily.dev/sources/csoonline)** · 5 min read · 0 upvotes · 0 comments

## Summary

Researchers from the University of Toronto have developed GPUThor, a new Rowhammer-style attack that breaks through the ECC protection on Nvidia GPUs, something all prior GPU attacks (GPUHammer, GPUBreach) could not do. By using non-uniform row hammering, it produces double- and triple-bit errors that ECC was never designed to handle, hammering memory 6.6 times harder and generating 500 to 23,500 times more bit flips, cutting exploit-discovery time from 21.9 hours to just 1.1 minutes on an RTX A6000. Confirmed on Ampere GPUs with GDDR6 memory (RTX A4000, A4500, A5000, A6000), it can crash shared GPUs or escalate an unprivileged process to root. Newer Blackwell cards and server GPUs like A100/H100 using HBM, GDDR6X, or GDDR7 were not affected in testing. Nvidia issued a new security advisory recommending IOMMU/DMA isolation and ECC telemetry monitoring.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.csoonline.com/article/4215392/gputhor-hardware-attack-can-root-nvidia-gpu-systems.html>

## Questions this post answers

### What is the GPUThor attack and which Nvidia GPUs are affected?

GPUThor is a Rowhammer-style attack developed by University of Toronto researchers that breaks through ECC protection on Nvidia GPUs, something no prior GPU Rowhammer attack achieved. It was confirmed on four Ampere-architecture GPUs with GDDR6 memory: the RTX A4000, A4500, A5000, and A6000, and can escalate an unprivileged process to root-level privileges on the host system.

_Teams running shared GPU workloads track hardware exploits like GPUThor to know when patching or isolation is needed, a topic daily.dev surfaces for security engineers._

### Are Nvidia H100 and A100 GPUs vulnerable to the GPUThor Rowhammer attack?

No, testing showed the GPUThor attack did not produce bit flips on Nvidia server GPUs such as A100 and H100, nor on newer Blackwell-based cards like the RTX 5090 or RTX 6000. This is because those GPUs use different memory types, including HBM, GDDR6X, and GDDR7, which have different defenses than the GDDR6 memory used in the affected Ampere cards.

_Engineers choosing GPU hardware for sensitive workloads follow security research like this on daily.dev to weigh memory-type risk._

### How does GPUThor bypass ECC protection compared to previous GPU Rowhammer attacks like GPUHammer?

GPUThor uses non-uniform row hammering instead of the uniform hammering used by GPUHammer and GPUBreach, producing double- and triple-bit errors that ECC was not designed to correct. It hammers memory 6.6 times harder and produces 500 to 23,500 times more bit flips, cutting the time to find an exploitable flip from 21.9 hours to 1.1 minutes on an Nvidia RTX A6000.

_Developers securing multi-tenant GPU workloads monitor emerging hardware exploits like this via daily.dev._

## Similar posts on daily.dev

- [New GPUBreach attack enables system takeover via GPU rowhammer](https://daily.dev/posts/new-gpubreach-attack-enables-system-takeover-via-gpu-rowhammer-op8ygz9ex) · BleepingComputer · 0 upvotes · 0 comments
- [Schneier on Security](https://daily.dev/posts/schneier-on-security-koiwbolx4) · Schneier on Security · 0 upvotes · 0 comments
- [New Rowhammer attacks give complete control of machines running Nvidia GPUs](https://daily.dev/posts/new-rowhammer-attacks-give-complete-control-of-machines-running-nvidia-gpus-870gt3du3) · Hacker News · 0 upvotes · 1 comments

---

Tags: [#security](https://daily.dev/tags/security), [#nvidia](https://daily.dev/tags/nvidia)

[View this post on daily.dev](https://daily.dev/posts/gputhor-hardware-attack-can-root-nvidia-gpu-systems-utdoxclks)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"GPUThor hardware attack can root Nvidia GPU systems","url":"https://daily.dev/posts/gputhor-hardware-attack-can-root-nvidia-gpu-systems-utdoxclks","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/gputhor-hardware-attack-can-root-nvidia-gpu-systems-utdoxclks"},"datePublished":"2026-08-28T18:47:27.828Z","dateModified":"2026-08-28T19:28:52.962Z","description":"Researchers from the University of Toronto have developed GPUThor, a new Rowhammer-style attack that breaks through the ECC protection on Nvidia GPUs,...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/aac61dee118d3f9098bec354fb5ac3f7?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/aac61dee118d3f9098bec354fb5ac3f7?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"CSO Online","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"CSO Online","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/98667e4b5cac46cf9c470819c6cf71cd","url":"https://daily.dev/sources/csoonline"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/gputhor-hardware-attack-can-root-nvidia-gpu-systems-utdoxclks","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,nvidia","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"CSO Online","item":"https://daily.dev/sources/csoonline"},{"@type":"ListItem","position":3,"name":"GPUThor hardware attack can root Nvidia GPU systems"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/gputhor-hardware-attack-can-root-nvidia-gpu-systems-utdoxclks#faq","mainEntity":[{"@type":"Question","name":"What is the GPUThor attack and which Nvidia GPUs are affected?","acceptedAnswer":{"@type":"Answer","text":"GPUThor is a Rowhammer-style attack developed by University of Toronto researchers that breaks through ECC protection on Nvidia GPUs, something no prior GPU Rowhammer attack achieved. It was confirmed on four Ampere-architecture GPUs with GDDR6 memory: the RTX A4000, A4500, A5000, and A6000, and can escalate an unprivileged process to root-level privileges on the host system. Teams running shared GPU workloads track hardware exploits like GPUThor to know when patching or isolation is needed, a topic daily.dev surfaces for security engineers."}},{"@type":"Question","name":"Are Nvidia H100 and A100 GPUs vulnerable to the GPUThor Rowhammer attack?","acceptedAnswer":{"@type":"Answer","text":"No, testing showed the GPUThor attack did not produce bit flips on Nvidia server GPUs such as A100 and H100, nor on newer Blackwell-based cards like the RTX 5090 or RTX 6000. This is because those GPUs use different memory types, including HBM, GDDR6X, and GDDR7, which have different defenses than the GDDR6 memory used in the affected Ampere cards. Engineers choosing GPU hardware for sensitive workloads follow security research like this on daily.dev to weigh memory-type risk."}},{"@type":"Question","name":"How does GPUThor bypass ECC protection compared to previous GPU Rowhammer attacks like GPUHammer?","acceptedAnswer":{"@type":"Answer","text":"GPUThor uses non-uniform row hammering instead of the uniform hammering used by GPUHammer and GPUBreach, producing double- and triple-bit errors that ECC was not designed to correct. It hammers memory 6.6 times harder and produces 500 to 23,500 times more bit flips, cutting the time to find an exploitable flip from 21.9 hours to 1.1 minutes on an Nvidia RTX A6000. Developers securing multi-tenant GPU workloads monitor emerging hardware exploits like this via daily.dev."}}]}
```

