Last month, NVIDIA was summoned by Chinese authorities to explain the alleged backdoors carried by its H20 computing chips. The company was required to provide explanations and submit supporting materials. On August 6, NVIDIA’s Chief Security Officer, David Reber, issued a public statement asserting that all GPU chips under NVIDIA have no form of backdoor, kill switch, or surveillance software. Reber’s statement was emphatic, but not convincing. In practice, every chip has potential backdoors; the only difference is who controls them.
Common Types of Chip Backdoors
On July 21, 2025, China’s Ministry of State Security clarified backdoors into three categories:
“Malicious built-in” – Some foreign manufacturers implant backdoors during the chip or device design phase, which can remotely control the device. For example, a certain smartphone brand was found with a chip-level backdoor capable of activating the camera and uploading footage without the user’s knowledge.
“Post-production compromise” – IC design companies often leave backdoors for debugging and later maintenance. Vendors may provide remote access interfaces for repair, but poor management or third-party exploits can turn these backdoors into tools for espionage. In 2024, hackers used server maintenance ports to steal user data from a multinational enterprise.
“Supply chain insertion” – Malicious actors can contaminate open-source code repositories, tamper with software updates, or embed malicious code in supply chains, activating backdoors during device operation. In early 2025, a domestic smart TV brand using altered third-party components put millions of devices at risk of data leakage.
Besides these deliberately embedded backdoors, there are also unintentional technical backdoors. Once discovered by Western intelligence, these can become powerful tools for national-level attacks. Classic examples include the “Spectre” and “Meltdown” vulnerabilities discovered years ago.
Modern CPUs use techniques such as branch prediction, out-of-order execution, and caching to improve performance, but these can inadvertently expose sensitive data to side-channel attacks if hardware design does not strictly isolate it.
Thus, Western intelligence can gain backdoor access by embedding them during design and manufacturing, exploiting vendor debugging interfaces, tampering with software, or exploiting hardware design flaws.
Western IC Giants and Reported Backdoors
Historically, top Western IC design companies like Intel, AMD, ARM, and NVIDIA have all been exposed to serious vulnerabilities.
Intel: In 2017, Intel admitted that nearly a decade’s worth of CPUs had critical vulnerabilities in the Management Engine (ME). ME resides within the CPU, has its own processor and memory, operates independently of the OS, and has the highest privileges, capable of bypassing security and controlling hardware remotely. The Free Software Foundation called it an “unclosable hardware backdoor.” Semiaccurate claimed in 2017 to have reported the vulnerability to Intel as early as 2012, but Intel dismissed it.
AMD: Similar to Intel ME, AMD PSP also has high privileges and can execute tasks beyond user control.
Recent Intel vulnerabilities: In August 2023, the Downfall vulnerability exploited AVX2/AVX-512 instructions to extract sensitive data from specific vector registers, affecting 6th–11th gen Core and 1st–4th gen Xeon CPUs. Despite being reported in 2022, Intel continued selling vulnerable products until public exposure. Other vulnerabilities since 2024 include GhostRace, NativeBHI, and Indirector.
ARM CPUs: MIT researchers found design flaws in pointer authentication codes (PAC) exploitable via PacMan attacks combined with speculative execution and side-channel attacks. These vulnerabilities cannot be patched via software, only hardware upgrades (e.g., ARM v8 → ARM v9). All ARM v8-based devices—including phones, tablets, and Macs with Apple M1 chips—are affected.
NVIDIA GPUs: In 2016, kernel driver issues allowed untrusted pointer use, restricted function access, and memory privilege escalation. Recently, the GPUHammer vulnerability could reduce large model accuracy from 80% to 0.02%. Wiz Research exposed critical flaws in NVIDIA Triton inference servers, enabling remote code execution (RCE) and manipulation of model output.
Purchased Chips Are Never Truly Safe
Realistically, self-developed chips may have vulnerabilities, but purchased chips are certainly not safe.
Hardware level: Instruction sets, CPU cores, GPU cores, and other IP may have backdoors.
Software level: Drivers, firmware, and open-source code can carry embedded backdoors.
Information security is relative, not absolute.
Even ignoring malicious code or intentionally pre-set debugging interfaces, all human-written code has bugs, meaning vulnerabilities inevitably exist. The key to security is timely patching and dynamic updates.
Self-designed chips: Full control over source code allows immediate fixes once vulnerabilities are discovered.
Chips based on foreign IP: Instruction sets or source code are purchased; understanding and fixing vulnerabilities is challenging without full documentation. For example, ARM v8’s PacMan vulnerability affects all CPUs based on that instruction set, fixable only with an upgrade to ARM v9.
Fully purchased chips: These are a technical black box. Patching depends on foreign vendors’ discretion. Intel, for example, ignored critical vulnerabilities for a decade.
Considering Western tech companies’ history of cooperating with intelligence agencies, such long-unpatched vulnerabilities could serve as state-level backdoors.
In May 2025, U.S. Congressman Bill Foster publicly urged NVIDIA to embed tracking in chips, citing “anti-smuggling,” with Google data centers reportedly already using this. The “anti-smuggling” rationale is a cover for technological hegemony and intelligence surveillance. Chips with pre-installed tracking systems are essentially exposed in terms of information security.
Conclusion
NVIDIA CSO David Reber’s public statements are essentially self-promotion, aimed at expanding business in China. The Chinese market is huge: as of April next year, H20 chip orders have reached $18 billion, highlighting its strategic importance in China.
In fact, H20 Chinese-specific chips carry higher security risks than H100. H100 is used globally, exposed to global security researchers, so malicious or accidental high-risk vulnerabilities threaten NVIDIA’s worldwide reputation. H20 is exclusive to China, exposing only Chinese users, making it a precision target with minimal risk of collateral exposure.
Like cars, one shouldn’t buy a China-specific model when the global model is available. The same applies to chips: China-specific versions often mean performance reductions and more severe security issues.
Editor: Zhiyu Wang



