Researchers: China's state-sponsored hackers stole source code, SDKs, and chip designs from at least seven Taiwanese chip companies over the past two years
Andy Greenberg / Wired : Tweets: @carlzha , @__winn , @hatr , @talbeerysec , @780thc , @heguisen , and @a_greenberg Tweets: Carl Zha / @carlzha : Idk if story is true but if US plan to starve China of tech, and they think China is bad at IP theft before, just wait til they see what China can do when it has *no* reason to respect tech business outside of mainland China https://www.wired.com/... Winnona / @__winn : These, combined with recent @WIRED reporting on Chinese espionage campaign Operation Skeleton Key targeting the Taiwan Semiconductor Industry (https://www.wired.com/...), suggests possibility of an explosion of new homegrown semiconductor companies in the mainland. https://twitter.com/... Hakan / @hatr : Very interesting CyCraft report about #Winnti operations (via @TalBeerySec) Of note: In our Winnti report one of the companies targeted was specialized in semiconductors: Sumitomo Electric. https://twitter.com/... Tal Be'ery / @talbeerysec : 1/ Skeleton Key attacks in the wild. See our (+@ItaiGrady) 2015 talk, explaining the attack and describing detection methods. CC: @PyroTek3 @gentilkiwi @JohnLaTwC @cyb3rops https://www.slideshare.net/... https://twitter.com/... https://twitter.com/... @780thc : Called Operation Skeleton Key, this Chinese state-sponsored hack appeared aimed at stealing as much intellectual property as possible, including source code, software development kits, and chip designs. @XHNews https://www.wired.com/... @heguisen : “If you have a really deep understanding of these chips at a schematic level, you can... find vulnerabilities before they even get released...By the time the devices hit the market, they're already compromised.” https://www.wired.com/... Andy Greenberg / @a_greenberg : Taiwanese security firm CyCraft are giving a #blackhat talk on a 2-year hacking campaign that hit at least 7 Taiwanese semiconductor firms, stealing chip designs and source code. New clues tie the campaign to mainland China, likely the Winnti hacker group. https://www.wired.com/...
Context & Ripple Effects
The attribution trail here runs through years of groundwork: after opsec errors let researchers collapse dozens of seemingly independent groups into the Winnti Umbrella in 2018, the same apparatus was documented running a years-long espionage campaign against German corporations, then against Dutch chipmaker NXP via the China-linked Chimera group. This report narrows the target list to the industry that matters most: at least seven Taiwanese chip companies, stripped of source code, SDKs, and chip designs over roughly two years, with evidence pointing back at Winnti.
First-order effects
- The seven affected Taiwanese chipmakers must now operate as if their source code, SDKs, and design files are in hostile hands, bearing remediation and redesign costs while researchers including Tal Be'ery and CyCraft publish the attribution.
- Naming Winnti as the likely operator gives Taiwan's semiconductor industry a specific adversary to defend against, extending the targeting pattern previously reported as Operation Skeleton Key against the island's chip sector.
Second-order effects
- Every tightening of formal transfer channels — the US entity list reaching newer Chinese chip firms among them — raises the market value of stolen designs, making espionage the substitute acquisition route when licensing and procurement close.
- Multinational chip customers who assumed the risk stopped at named victims like NXP must now treat long-dwell intrusion into any fab or design house as a baseline supply-chain assumption, shifting spend toward continuous detection services of the kind CyCraft sells.
Third-order effects
- If Winnti-linked collection persists across Taiwan, Germany, and the Netherlands, IP defense becomes a geopolitical layer of the semiconductor supply chain, pushing governments to treat fabs and design files as strategic assets warranting national-level cyber protection.
- The umbrella-attribution method — folding scattered groups into named state-linked programs once opsec slips accumulate — is maturing into standing public accountability, steadily eroding the deniability that has shielded state-sponsored hacking programs.
The trend: State-sponsored chip IP theft is hardening into a structural second channel of the US-China technology conflict, operating parallel to — and increasingly substituting for — restricted legal transfer routes.