Researchers have revealed a new hardware attack known as DDRop, which exploits confidential computing on Intel and AMD servers by silently erasing writes to the memory, causing the processor to continue reading outdated encrypted data. This vulnerability necessitates an attacker who already has control over the server's software and can briefly access the machine by inserting a small circuit board called an interposer between the processor and a memory module. This is DDRop's first active interposer attack that targets DDR5 memory in contemporary cloud servers, marking it as the first to breach the integrity of a fully updated Intel TDX system, rather than merely reading data from it.

Active attacks that altered what the memory saw, such as Battering RAM, worked only on older DDR4 and DDR5’s redesigned command format, which blocks the address-swapping trick they used. The patch is not straightforward. It has also described this research area as "out of scope, but not out of mind."

Intel offers an optional cryptographic-integrity mode on some current Xeon processors, which already blocks part of DDRop, and Intel is working on stronger memory-encryption designs for future chips. Since it only requires a brief visit to the machine, the researchers suggest the access it needs can be obtained through a rogue data-center employee, hardware tampering in the supply chain, or legal seizure.