University of Toronto researchers described GPUThor, a Rowhammer-class attack targeting GDDR6 memory in NVIDIA Ampere GPU accelerators. The technique characterizes the platform’s Targeted Refresh Rate (TRR) behavior and uses non-uniform memory-access patterns to induce substantially more bit flips than earlier GPU Rowhammer methods, extending the DRAM disturbance-error threat first established by Rowhammer research.
GPUThor generated double- and triple-bit memory corruptions, which can exceed ECC’s single-bit correction capability. Researchers demonstrated a denial-of-service outcome: a GPU reset accompanied by data loss and a hardware-replacement warning. They did not demonstrate arbitrary code execution or compromise newer GPU generations; ECC bypass leading to code execution remains theoretical.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Three studies published in spring 2026 demonstrated Rowhammer attacks against NVIDIA GPUs using GDDR6 memory. Their results were more limited on the NVIDIA A6000 than on consumer GPUs, and the attacks did not work with ECC enabled.
University of Toronto researchers described GPUThor, a Rowhammer-class technique for GDDR6 memory in NVIDIA Ampere accelerators. By exploiting Ampere TRR behavior with non-uniform access patterns, they reported double- and triple-bit corruptions and demonstrated denial of service causing a GPU reset, data loss, and a hardware-replacement warning; arbitrary code execution was not demonstrated.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
kaspersky.com
Open sourcekaspersky.ru
Open sourcegputhor.com
Open sourcegpubreach.ca
Open sourceusers.ece.cmu.edu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.