{"id":7437,"date":"2025-10-05T10:03:27","date_gmt":"2025-10-05T10:03:27","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/10\/05\/new-wiretap-attack-break-server-sgx-to-exfiltrate-sensitive-data\/"},"modified":"2025-10-05T10:03:27","modified_gmt":"2025-10-05T10:03:27","slug":"new-wiretap-attack-break-server-sgx-to-exfiltrate-sensitive-data","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/10\/05\/new-wiretap-attack-break-server-sgx-to-exfiltrate-sensitive-data\/","title":{"rendered":"New WireTap Attack Break Server SGX To Exfiltrate Sensitive Data"},"content":{"rendered":"<p>    New WireTap Attack Break Server SGX To Exfiltrate Sensitive Data<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A newly disclosed vulnerability, named the WireTap attack, allows attackers with physical access to break the security of Intel\u2019s Software Guard eXtensions (SGX) on modern server processors and steal sensitive information.<\/p>\n<p>A research paper released in October 2025 details how this method can extract cryptographic keys from supposedly secure SGX enclaves using a low-cost setup, challenging the foundational trust placed in these hardware-based security environments.<\/p>\n<p>The attack undermines the confidentiality and integrity guarantees of SGX, a technology widely used to protect sensitive data and computation, even from privileged software. <\/p>\n<p>The researchers demonstrated that physical attacks, once believed to require expensive and specialized equipment, can now be executed by hobbyists on a budget of less than $1,000.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-wiretap-attack\"><strong>WireTap Attack<\/strong><\/h2>\n<p>The core of the WireTap attack is a custom-built memory interposition probe that physically taps into the DRAM bus, allowing the attacker to observe the data moving between the CPU and the system\u2019s memory. <\/p>\n<p>The researchers constructed <a href=\"https:\/\/wiretap.fail\/files\/wiretap.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">this tool<\/a> using readily available components from second-hand electronic marketplaces, including a simple DIMM riser board, tweezers, and a soldering iron.<\/p>\n<p>A key innovation was slowing down the system\u2019s high-speed DDR4 memory bus. By modifying the DIMM\u2019s metadata, the researchers forced the system to operate at a much lower frequency. <\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhNvbAPuIfTLviPCJ1G2kK4DfzBhsLYIpnPHAHtlZ-B-pnLOro2OWPkQMXQ8_S6tYHvhtxoHYCFRsnDPfRJ3M7rMX1hgwLovEOfOX8JudRB17AR3Lqn5_aMdWZBfIqQqFfCshCwY4diO50mbnUZpWYRrSO7fTMsRFELVQH9ApR34v3HZjF9QST4YoE39Wc-\/s16000\/DDR4%2520Raiser%2520board.png?ssl=1\" alt=\"\"><\/figure>\n<p>This crucial step made it possible to capture the data traffic using outdated and inexpensive logic analyzers not originally designed for modern hardware. <\/p>\n<p>This approach shatters the long-held assumption that physical memory attacks on server-grade systems were out of reach for all but the most well-funded adversaries.<\/p>\n<p>The attack specifically targets Scalable SGX, the version used in Intel\u2019s Xeon server processors, which relies on a deterministic memory encryption scheme called AES-XTS. <\/p>\n<p>Unlike older <a href=\"https:\/\/cybersecuritynews.com\/battering-ram-attack\/\">SGX implementations<\/a>, this scheme produces the same ciphertext whenever the same data is written to the same physical memory address.<\/p>\n<p>The WireTap setup allows attackers to observe these encrypted memory transactions in real-time. By carefully controlling an SGX enclave and forcing it to perform cryptographic operations, the researchers were able to mount a ciphertext side-channel attack.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj3a6Zb5raliXb6Ec8uqEhrDBHIXtiACFXH3rH5X2I9FdCT6UUMmFk6xiApi9sqPwdZ3N-BfEGCb_2nFgfJLLnnbQJfHHGuay9mBZFDgzMhkU_AWYXBdIfSdf7QC00aIpnspvK9rJJaJxVe9Sk-CbtooDr3y4s78HDYNTgWXKzMURiacov5oKtALffy5vwG\/s16000\/XTS%2520Encryption.png?ssl=1\" alt=\"\"><\/figure>\n<p>They observed the encrypted memory traffic during the generation of an ECDSA signature, a process used for SGX attestation. This allowed them to build a dictionary of ciphertexts and recover the secret nonce used in the signing operation.<\/p>\n<p>With the nonce and the public signature, they successfully extracted the machine\u2019s private DCAP attestation key from a fully trusted server in under 45 minutes.<\/p>\n<p>The consequences of extracting an SGX attestation key are severe, particularly for the blockchain and Web3 ecosystems that rely on SGX for security. <\/p>\n<p>Many decentralized networks, with market caps totaling hundreds of millions of dollars, use SGX to ensure confidential transactions and the integrity of computation.<\/p>\n<p>The researchers demonstrated end-to-end attacks on several real-world SGX deployments. For privacy-preserving smart contract networks like Phala and Secret, a compromised key would allow an attacker to forge quotes, run malicious enclaves, and extract master keys, enabling network-wide decryption of confidential transactions.<\/p>\n<p>On decentralized storage networks like Crust, an attacker could fake proofs of storage, allowing them to claim financial rewards without actually storing any data, thereby breaking the system\u2019s integrity guarantees. The researchers have disclosed their findings to Intel and the affected blockchain projects.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/new-wiretap-attack\/\">New WireTap Attack Break Server SGX To Exfiltrate Sensitive Data<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/new-wiretap-attack\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>New WireTap Attack Break Server SGX To Exfiltrate Sensitive Data A newly disclosed vulnerability, named the WireTap attack, allows attackers with physical access to break the security of Intel\u2019s Software Guard eXtensions (SGX) on modern server processors and steal sensitive information. A research paper released in October 2025 details how this method can extract cryptographic [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63],"tags":[130],"class_list":["post-7437","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7437"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7437"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7437\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7437"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7437"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7437"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}