A cloud tenant could rattle the power grid with nothing but a rented GPU, researchers say

Chinese researchers say a cloud customer needs no hack, no malware, and no stolen password to put a power grid under strain. Just a rented GPU and a workload built to misbehave. The catch is that the scariest numbers come from a simulation, not a real attack.


A cloud tenant could rattle the power grid with nothing but a rented GPU, researchers say Image by: Shutterstock

AI data centres already strain the grid just by running. A new paper asks a darker question: what if a tenant tried to break it on purpose?

Three researchers at Zhejiang University set out the idea in a preprint called Bit2Watt, accepted to a leading hardware-security conference. As The Register reported, it imagines a paying customer as the attacker.

How it works

The trick rests on a simple fact. A GPU’s power draw follows whatever it is computing. Load it hard and the current spikes. Let it idle and the current drops.

Flip between those states on a schedule and you get a controllable power wobble at the wall socket. The researchers pushed it past 6,000 times a second, far faster than the gentle sway of a household load like an air conditioner.

They show two ways to do it. One uses a purpose-built workload that a provider might learn to spot. The other, harder to catch, hides the pattern inside a real AI training run, where it blends into normal noise. Neither needs special access, because a tenant already controls its own jobs.

The scary number, and the asterisk

Alone, one GPU does little. The danger, the paper argues, is in bulk. It models 1,000 GPUs pulsing in perfect lockstep on a small grid mostly fed by solar and batteries.

In that worst case, the simulated grid turns unstable, wasting nearly half its current and running hot. Pushed onto a model of the European transmission network, a small local disturbance cascades until it sheds about 81% of the load.

Here is the asterisk. As reporting on cloud attacks often has to stress, that figure is a property of one simulation stacked with worst-case assumptions, not a forecast. The whole attack hinges on getting a real fleet of cloud GPUs to pulse in perfect sync, which the authors admit is still unsolved. No live system was attacked.

Grounded in real physics

What keeps this from being pure theory is that the physics is on record. In 2025, Microsoft, OpenAI, and Nvidia warned that the synchronised power swings of large training jobs can damage grid infrastructure when their rhythm lines up with a utility’s. Meta flagged the same risk while training Llama 3.

The grid has already had a fright by accident. In July 2024, a fault near data-centre-heavy Northern Virginia knocked about 1,500 megawatts of load off the grid at once. Regulators said there was no crisis, then set up a task force to study the danger as these power-hungry sites multiply.

The loop back, and no bug to patch

The researchers also sketch a feedback attack they call Watt2Bit. The same electrical stress that rattles the grid can overheat the servers, tripping their protection and knocking them offline. A power problem becomes a denial of service.

The awkward part is that there is no bug to patch. Standard monitoring samples power far too slowly to catch the fast flicker. The deeper issue is the design itself. Volatile GPU loads now sit on a grid full of solar inverters, and nothing watches across the two.

As the data centre and the grid it leans on grow more entangled, they stay run by different firms, watched by different tools. That seam, the paper implies, has no clear owner. Fixes exist on each side, but tying them together is still to come, even as the AI build-out races ahead.

Get the TNW newsletter

Get the most important tech news in your inbox each week.