Researcher: PCs with Thunderbolt ports have an unpatchable flaw letting hackers with physical access circumvent data safeguards; some new PCs are not affected
The so-called Thunderspy attack takes less than five minutes to pull off with physical access to a device, and affects any PC manufactured before 2019.
WiredAndy Greenberg
Context & Ripple Effects
Thunderspy is the third act in a decade-long Thunderbolt firmware saga. Back in 2015, a researcher showed he could rewrite Mac firmware over Thunderbolt, flagging most Intel Thunderbolt Macs as exposed, and by 2017 researchers found an alarming number of Macs still vulnerable to stealthy hacks because of outdated EFI firmware — with Windows and Linux machines likely at risk too.
What changed today is scope and finality: the flaw now named Thunderspy affects any PC manufactured before 2019, needs under five minutes of physical access, and cannot be patched — while some newer PCs ship unaffected. That turns a long-running research thread into a concrete procurement and device-retirement problem.
First-order effects
Owners and enterprises running pre-2019 Thunderbolt-equipped PCs have no patch to deploy; their only mitigations are physical-access controls and treating any device that leaves their sight as potentially compromised.
PC makers whose current models are unaffected gain an immediate security differentiator they can market against the installed base of vulnerable older machines.
Second-order effects
Corporate IT refresh cycles get a security justification: fleets bought before 2019 now carry a documented, unfixable exposure, pressuring buyers toward replacement rather than extended lifecycles.
Intel and the Thunderbolt ecosystem face renewed scrutiny over why the same port-to-firmware attack class has resurfaced since 2015, pushing demand for verifiable, signed firmware updates on future hardware.
Third-order effects
If the pattern holds — firmware flaws in peripheral ports disclosed in 2015, 2017, and now 2020 — hardware-level firmware verification and attestation stop being optional hardening and become a baseline procurement requirement for laptops.
Physical access moves up the threat-model hierarchy for enterprises: an unpatchable five-minute attack makes device custody policies, not just software patching, part of the security perimeter.
The trend: Peripheral-interface firmware is proving to be a persistent, decade-spanning attack surface that software patches cannot reach, shifting the security burden toward hardware-verified firmware in future PC designs.
This looks bad. An attacker could read your encrypted drive & contents of a RAM, even when the laptop is sleeping. All it takes is inserting a device into USB/Thunderbolt port. All macbooks are affected, even with Linuxes. Can't be fixed in software. https://thunderspy.io/
Intel says computers that have Kernel Direct Memory Access Protection enabled are safe, but that feature is only available in some PCs sold since 2019. @0Xiphorus has released a tool to see if your computer is vulnerable here: https://thunderspy.io/
The so-called Thunderspy attack takes less than five minutes to pull off with physical access to a device, and affects any PC manufactured before 2019. https://www.wired.com/...
Thunderspy works even if you follow best security practices by locking or suspending your computer when leaving briefly, and if your system administrator has set up the device with Secure Boot, strong BIOS and operating system account passwords, and enabled full disk encryption.
Say what you will about the VGA port but it had never let us down like this. Thunderbolt, more like Thunderdolt. via @Techmeme https://www.wired.com/...
This has been a long time coming. Today we release Thunderspy. Find full details at https://thunderspy.io/. Thanks to @a_greenberg for reporting. #Thunderspy #Intel #Thunderbolt https://twitter.com/...
“If your computer has a Thunderbolt port, an attacker who gets brief physical access to it can read and copy all your data, even if your drive is encrypted and your computer is locked or set to sleep.” tl;dr: stop using computers. ¯\_(ツ)_/¯ https://thunderspy.io/
“Thunderspy [Intel exploit] enables creating arbitrary Thunderbolt device identities and cloning user-authorized Thunderbolt devices, even in the presence of Security Levels pre-boot protection and cryptographic device authentication” https://twitter.com/...
@wdormann @a_greenberg Sadly, no. Intel's Kernel DMA protection requires hardware and BIOS support that weren't shipped prior to 2019. It also requires OS support but that is much easier to fix. See https://thunderspy.io/... for details.
“All the evil maid needs to do is unscrew the backplate, attach a device momentarily, reprogram the firmware, reattach the backplate, and the evil maid gets full access to the laptop,” https://www.wired.com/... via @wired
I don't understand how a person can find a vulnerability with Thunderbolt, go to the trouble of making a website about it, and NOT call it Thunderstruck. Once again they've really missed a trick here. https://thunderspy.io/
Thunderbolt Flaws Expose Millions of PCs to Hands-On Hacking https://www.wired.com/... @wired // Thunderbolt was always risky. Windows has 1st party thunderbolt because if Microsoft didn't do it then there would have been worse vulnerabilities due to uneven support by OEMs/Intel.
A newly-found vulnerability in thunderbolt ports could leave any PC built before 2019 open to hacking—even if the machine is asleep or locked. https://www.wired.com/...
Dutch researcher @0Xiphorushas has detailed a new physical access technique that could let hackers break into any of millions of PCs via their Thunderbolt ports. The good news is it requires unscrewing the case briefly. The bad news is it's unpatchable. https://www.wired.com/...