Researchers disclosed Chypothermia, a cryogenic physical attack that disrupts on-chip mixed-signal circuitry—including clock, clock-generation, and voltage-sensing components—to halt device clocks while evading defenses intended to detect abnormal clock stoppage. Combined with the Chypnosis static side-channel technique, it can leave registers and SRAM retaining secrets after digital protection logic and zeroization state machines stop operating; tests reportedly prevented key zeroization in platforms including the OpenTitan root-of-trust alert handler.
The attack requires physical access, controlled cooling or power manipulation, and specialized static readout methods such as laser logic-state imaging or impedance analysis. AMD advisory AMD-SB-8018 identifies Artix-7 and Kintex-7 FPGA exposure to this class of clock-freezing attacks and recommends programmable-logic clock monitoring paired with asynchronous reset. Researchers also proposed an FPGA-compatible self-heating sensor to help detect cryogenic conditions; organizations should assess devices holding bitstream-encryption or root-of-trust keys for asynchronous brownout, clock-loss, and temperature-response controls.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Researchers submitted the Chypothermia paper, describing a cryogenic physical attack that disrupts on-chip clock-generation and sensing circuitry, including voltage sensors, without electrical tampering. Tests on multiple FPGA/SoC platforms reportedly disabled soft-IP and hard-IP sensors and, when applied to OpenTitan's alert handler, prevented key zeroization; the authors also implemented a self-heating sensor countermeasure reported to resist the attack.
Mitard and colleagues presented Chypnosis at IEEE SP 2026, using rapid voltage reduction to halt clock and protection logic while registers and SRAM retain data. The researchers reported extracting a secret key from an OpenTitan cryptographic module implemented on an FPGA in a single static side-channel trace, and reported bypassing a Microchip Flash-FPGA anti-tamper response.
AMD released security bulletin AMD-SB-8018 addressing this class of brownout-based static side-channel attacks. The bulletin confirmed that Artix 7-Series and Kintex 7-Series FPGAs were affected and recommended programmable-logic clock monitoring with an asynchronous reset mechanism.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.