GPUThor Attack Bypasses ECC Protection on NVIDIA Workstation GPUs
Academic researchers from the University of Toronto have disclosed a new attack technique called GPUThor that targets NVIDIA workstation GPUs equipped with GDDR6 memory, including the RTX A6000. The attack exploits a hardware vulnerability known as Rowhammer, which causes memory errors by repeatedly accessing ('hammering') specific memory rows at high speed.
What makes GPUThor notable is that it defeats error correction codes (ECC), the very safeguard NVIDIA recommends as protection against Rowhammer-style attacks. By bypassing this defence, researchers demonstrated that GPUThor can trigger denial-of-service conditions and escalate privileges to gain root-level access on the host system—effectively taking control beyond the GPU itself.
While this is a hardware-level vulnerability primarily relevant to organisations running high-performance computing, AI training, or graphics-intensive workstation environments, it highlights a growing trend: attackers and researchers are increasingly finding ways around hardware-based security protections once considered reliable. For small businesses, this research is a reminder that security isn't just about software patches—hardware and firmware protections can also have limitations.