---
title: "Bit2Watt shows an attacker can destabilize a data center's local power grid purely by scheduling GPU workloads, with no physical or electrical access"
type: "claim"
status: "seedling"
writer_model: "claude-sonnet-5"
source_url: "https://arxiv.org/abs/2607.05993"
source_title: "Bit2Watt: A Cyber-Physical Vulnerability Exploiting GPU Workloads Across Power and Computing Infrastructures"
source_author: "Zhouhao Ji, Kaikai Pan, Wenyuan Xu"
source_date: "2026-07-05T00:00:00.000Z"
source_quote: "Bit2Watt operates entirely within the cyber layer as a legal tenant, which could amplify fluctuations, harmonic distortion, and damping degradation... manipulating 1,000 GPUs in a 1-MW local power system with 90% DERs raises current THD to 46.8% and results in a damping ratio of -0.27."
source_tier: 1
audit_status: "verified-verbatim"
provenance: "Promotion from 10-inbox/raw/2026-07-09-hop-bit2watt-power-sidechannel.md, 2026-07-11. arXiv:2607.05993 abstract independently re-fetched 2026-07-11 and the quoted figures (1,000 GPUs, 1-MW, 90% DERs, THD 46.8%, damping ratio -0.27) confirmed verbatim."
origin: "batch"
derived_from: "10-inbox/raw/2026-07-09-hop-bit2watt-power-sidechannel.md"
date_created: "2026-07-11T00:00:00.000Z"
tags: ["distributed-computing","hardware-security","side-channel","power-grid","ai-infrastructure","cyber-physical-systems"]
related_notes: ["claim-us-interconnection-queue-exceeds-installed-capacity","claim-microsoft-constellation-tmi-restart-crane-clean-energy-center","claim-kairos-kp-fhr-molten-salt-triso-reactor"]
audits: ["2026-07-12 claude-opus-4-8"]
drafted_in: ["2026-07-13-you-had-to-touch-it","you-had-to-touch-it"]
---


Ji, Pan & Xu's "Bit2Watt" (accepted CHES 2026) describes a cyber-physical attack in which an adversary who is nothing more than an ordinary, legitimate cloud tenant induces high-frequency power fluctuations by scheduling GPU compute in patterns timed against the facility's power infrastructure. No malware, privilege escalation, or physical/electrical access to the hardware is required — the attacker "operates entirely within the cyber layer as a legal tenant." The paper validates the mechanism on real GPUs and grid-connected PV inverters, and in a modeled 1,000-GPU, 1-MW local power system with 90% distributed energy resources (DERs), reports that the attack "raises current THD to 46.8% and results in a damping ratio of -0.27" — degradation severe enough to risk triggering protective disconnects and, per the paper's simulations, cascading toward transmission-scale failure.

This reframes a problem the vault has so far treated as a *sourcing* constraint — can enough power be built or contracted to meet AI compute demand, as in [[claim-microsoft-constellation-tmi-restart-crane-clean-energy-center]] and [[claim-kairos-kp-fhr-molten-salt-triso-reactor]], against a transmission bottleneck already running at roughly [[claim-us-interconnection-queue-exceeds-installed-capacity|twice installed capacity]] — into a *security* problem: the same tight coupling between compute load and grid stability that makes power scarce also makes it manipulable. Bit2Watt's attacker doesn't compete for power; it weaponizes the demand signal itself.

Bit2Watt's own physical premise — that computation's power draw carries exploitable information/leverage — did not originate with this paper; see [[claim-power-side-channel-attacks-scaled-chip-to-grid-1999-2026]] for the lineage back to 1999 chip-level side-channel analysis.

> [!note] Seek's commentary:
> The number that stuck with me: 90% DERs. This attack needs a grid already leaning on distributed renewables to work at this severity — which is exactly the grid AI data centers are being built next to. The vulnerability and the buildout may be growing together. — Seek
