New “Bit2Watt” Attack Lets Cloud Tenants Modulate Data‑Center Power Draw, Threatening Grid Stability
What Happened — Researchers from Zhejiang University demonstrated a novel side‑channel attack, dubbed Bit2Watt, in which a cloud tenant can use ordinary GPU workloads to rapidly increase and decrease a data‑center’s power consumption. The technique requires no software exploit or privileged access; it leverages the physical characteristics of GPU power draw to create grid‑level disturbances.
Why It Matters for Compliance & Audit Readiness
- Demonstrates a control‑gap where cloud‑provider resource‑usage policies do not capture abnormal power‑fluctuation behavior, a scenario SOC 2 expects organizations to monitor under the System Operations and Change Management criteria.
- Provides a concrete example of why continuous evidence collection (e.g., power‑usage logs, GPU utilization metrics) is essential to prove that controls are operating effectively and to satisfy audit‑ready documentation.
- Highlights the need for control mapping that ties low‑level infrastructure metrics to high‑level SOC 2 trust‑service principles, enabling a defensible audit trail if a disruption occurs.
Who Is Affected
- Cloud service providers (IaaS, PaaS) that expose GPU resources to multi‑tenant customers.
- Energy‑utility operators that rely on data‑center power stability for grid reliability.
- Enterprises running GPU‑intensive workloads (AI/ML, rendering, scientific computing).
Recommended Actions
- Map existing GPU‑usage monitoring controls to SOC 2 System Operations and Change Management criteria.
- Implement continuous collection and retention of power‑draw telemetry as audit evidence.
- Define thresholds for abnormal power‑fluctuation events and integrate them into incident‑response playbooks.
- Conduct a risk assessment of tenant‑level resource abuse and update vendor‑risk questionnaires accordingly.
Source: The Hacker News
Technical Notes
- Attack vector: legitimate GPU compute jobs that cause rapid power‑draw changes; no CVE or software exploit required.
- Measured impact: power spikes sufficient to stress data‑center UPS systems and potentially cascade to the external grid.
- Research presented at CHES 2026 (IACR hardware‑security conference).
Source: The Hacker News