/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers: China's state-sponsored hackers stole source code, SDKs, and chip designs from at least seven Taiwanese chip companies over the past two years

Andy Greenberg / Wired : Tweets: @carlzha , @__winn , @hatr , @talbeerysec , @780thc , @heguisen , and @a_greenberg Tweets: Carl Zha / @carlzha : Idk if story is true but if US plan to starve China of tech, and they think China is bad at IP theft before, just wait til they see what China can do when it has *no* reason to respect tech business outside of mainland China https://www.wired.com/... Winnona / @__winn : These, combined with recent @WIRED reporting on Chinese espionage campaign Operation Skeleton Key targeting the Taiwan Semiconductor Industry (https://www.wired.com/...), suggests possibility of an explosion of new homegrown semiconductor companies in the mainland. https://twitter.com/... Hakan / @hatr : Very interesting CyCraft report about #Winnti operations (via @TalBeerySec) Of note: In our Winnti report one of the companies targeted was specialized in semiconductors: Sumitomo Electric. https://twitter.com/... Tal Be'ery / @talbeerysec : 1/ Skeleton Key attacks in the wild. See our (+@ItaiGrady) 2015 talk, explaining the attack and describing detection methods. CC: @PyroTek3 @gentilkiwi @JohnLaTwC @cyb3rops https://www.slideshare.net/... https://twitter.com/... https://twitter.com/... @780thc : Called Operation Skeleton Key, this Chinese state-sponsored hack appeared aimed at stealing as much intellectual property as possible, including source code, software development kits, and chip designs. @XHNews https://www.wired.com/... @heguisen : “If you have a really deep understanding of these chips at a schematic level, you can... find vulnerabilities before they even get released...By the time the devices hit the market, they're already compromised.” https://www.wired.com/... Andy Greenberg / @a_greenberg : Taiwanese security firm CyCraft are giving a #blackhat talk on a 2-year hacking campaign that hit at least 7 Taiwanese semiconductor firms, stealing chip designs and source code. New clues tie the campaign to mainland China, likely the Winnti hacker group. https://www.wired.com/...

Wired Andy Greenberg

Context & Ripple Effects

The attribution trail here runs through years of groundwork: after opsec errors let researchers collapse dozens of seemingly independent groups into the Winnti Umbrella in 2018, the same apparatus was documented running a years-long espionage campaign against German corporations, then against Dutch chipmaker NXP via the China-linked Chimera group. This report narrows the target list to the industry that matters most: at least seven Taiwanese chip companies, stripped of source code, SDKs, and chip designs over roughly two years, with evidence pointing back at Winnti.

First-order effects

  • The seven affected Taiwanese chipmakers must now operate as if their source code, SDKs, and design files are in hostile hands, bearing remediation and redesign costs while researchers including Tal Be'ery and CyCraft publish the attribution.
  • Naming Winnti as the likely operator gives Taiwan's semiconductor industry a specific adversary to defend against, extending the targeting pattern previously reported as Operation Skeleton Key against the island's chip sector.

Second-order effects

  • Every tightening of formal transfer channels — the US entity list reaching newer Chinese chip firms among them — raises the market value of stolen designs, making espionage the substitute acquisition route when licensing and procurement close.
  • Multinational chip customers who assumed the risk stopped at named victims like NXP must now treat long-dwell intrusion into any fab or design house as a baseline supply-chain assumption, shifting spend toward continuous detection services of the kind CyCraft sells.

Third-order effects

  • If Winnti-linked collection persists across Taiwan, Germany, and the Netherlands, IP defense becomes a geopolitical layer of the semiconductor supply chain, pushing governments to treat fabs and design files as strategic assets warranting national-level cyber protection.
  • The umbrella-attribution method — folding scattered groups into named state-linked programs once opsec slips accumulate — is maturing into standing public accountability, steadily eroding the deniability that has shielded state-sponsored hacking programs.

The trend: State-sponsored chip IP theft is hardening into a structural second channel of the US-China technology conflict, operating parallel to — and increasingly substituting for — restricted legal transfer routes.

Discussion

  • @carlzha Carl Zha on x
    Idk if story is true but if US plan to starve China of tech, and they think China is bad at IP theft before, just wait til they see what China can do when it has *no* reason to respect tech business outside of mainland China https://www.wired.com/...
  • @__winn Winnona on x
    These, combined with recent @WIRED reporting on Chinese espionage campaign Operation Skeleton Key targeting the Taiwan Semiconductor Industry (https://www.wired.com/...), suggests possibility of an explosion of new homegrown semiconductor companies in the mainland. https://twitte…
  • @hatr Hakan on x
    Very interesting CyCraft report about #Winnti operations (via @TalBeerySec) Of note: In our Winnti report one of the companies targeted was specialized in semiconductors: Sumitomo Electric. https://twitter.com/...
  • @talbeerysec Tal Be'ery on x
    1/ Skeleton Key attacks in the wild. See our (+@ItaiGrady) 2015 talk, explaining the attack and describing detection methods. CC: @PyroTek3 @gentilkiwi @JohnLaTwC @cyb3rops https://www.slideshare.net/... https://twitter.com/... https://twitter.com/...
  • @780thc @780thc on x
    Called Operation Skeleton Key, this Chinese state-sponsored hack appeared aimed at stealing as much intellectual property as possible, including source code, software development kits, and chip designs. @XHNews https://www.wired.com/...
  • @heguisen @heguisen on x
    “If you have a really deep understanding of these chips at a schematic level, you can... find vulnerabilities before they even get released...By the time the devices hit the market, they're already compromised.” https://www.wired.com/...
  • @a_greenberg Andy Greenberg on x
    Taiwanese security firm CyCraft are giving a #blackhat talk on a 2-year hacking campaign that hit at least 7 Taiwanese semiconductor firms, stealing chip designs and source code. New clues tie the campaign to mainland China, likely the Winnti hacker group. https://www.wired.com/.…