Researchers disclosed a hardware attack that can bypass Microsoft BitLocker protections by intercepting communications with the Trusted Platform Module (TPM) during the boot process. The technique, demonstrated by Guillaume Quéré, targets devices protected with BitLocker and a PIN by probing motherboard traces and using a logic analyzer to capture key material exchanged at startup, including an encrypted intermediate key that can be used to recover the Volume Master Key and decrypt the drive.
The attack requires physical access to the device and the ability to disassemble it, rather than any remote code execution or software exploit. Microsoft documents BitLocker as a data-at-rest protection feature for Windows, but the reported bypass highlights that its security can be undermined when attackers can access hardware signals directly. Reported mitigations focus on operational controls rather than a Windows patch, including strong physical security, secure storage of devices, and proper wiping or destruction of drives and systems at end of life.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
The same report states there is no current Windows mitigation for this specific physical attack path and recommends physical security controls, secure device storage, and proper drive wiping or destruction at retirement.
A weekly summary reports research by Guillaume Quéré showing a hardware-based technique to bypass BitLocker PIN protection by intercepting TPM communications during boot. The attack requires physical access and device disassembly to capture key material that can ultimately be used to decrypt the drive.
Microsoft published documentation describing BitLocker as a Windows data protection feature for encrypting operating system drives, fixed drives, and removable drives. The reference provides product background but does not anchor a publication date for this documentation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.