Lapsus$ says if Nvidia doesn't remove crypto mining limits on its graphic cards and open source its GPU drivers, the group will release the source code it stole
Chipmaker has until Friday to comply or see its crown-jewel source code released. — Data extortionists who stole up to 1 terabyte …
Context & Ripple Effects
Nvidia had already confirmed that employee data and proprietary information were leaked in the breach, while reporting also identified cracked and circulated staff credentials. The extortion demand turns that incident from a disclosure problem into an attempt to dictate Nvidia’s driver and mining-limit policy.
The demand also targets a control Nvidia had struggled to preserve: a developer driver previously unlocked RTX 3060 Ethereum-mining performance. That history gives the threatened driver-source release a concrete commercial and security dimension.
First-order effects
- Nvidia must manage a deadline-backed threat to publish stolen GPU source code while refusing or accepting demands that directly concern its graphics-card software controls.
- The breach already creates an immediate security burden beyond source-code confidentiality: researchers reported leaked Nvidia code-signing certificates being used to sign malware and hacking tools.
Second-order effects
- A public driver-code release would give miners and other third parties more material to examine Nvidia’s mining restrictions, increasing pressure on the company’s ability to enforce segmentation through drivers.
- Nvidia’s customers and Windows users may need to treat software signed with the exposed certificates as a higher-risk channel, shifting incident response from Nvidia’s internal breach containment to endpoint security teams.
Third-order effects
- The episode illustrates how data-extortion campaigns can target product-policy decisions, not solely payment, when stolen intellectual property and signing infrastructure can create leverage.
- If code-signing material becomes a recurring breach target, chip and software vendors will face stronger incentives to isolate signing systems from engineering repositories and staff credential exposure.
The trend: Cyber extortion is expanding from ransom demands into coercion over vendors’ software controls, using stolen code and trusted signing assets as leverage.