A flaw in crime-lab software let AI rewrite DNA evidence in 45 minutes, without a trace.

A newly patched flaw let someone with lab access rewrite digital DNA evidence without a trace, and AI-written code made it a 45-minute job. The fix only protects files created from now on.


A flaw in crime-lab software let AI rewrite DNA evidence in 45 minutes, without a trace.

The software most American crime labs use to read DNA evidence carried a flaw. It let someone with the right access quietly rewrite the results, and leave almost no trace. AI made the attack easy. Thermo Fisher Scientific has now patched it. But the fix only guards files created from here on.

The weakness sits in several Applied Biosystems tools that turn a DNA sample into a digital file. The company’s security bulletin says an attacker could alter the .fsa and .hid files those machines produce before analysis software loads them. That works only if someone first bypasses a lab’s controls. The flaw carries the identifier CVE-2026-17583 and a high severity score of 8.2.

What makes it striking is how little skill it now takes. Nathan Adams, an engineer at Forensic Bioinformatics, wrote his first working edit with Anthropic’s Claude in about 45 minutes. He told the Wall Street Journal how quickly it went. His code stitched two people’s DNA profiles into one file. It looked untouched since 2015, and raised no warning in software many labs rely on.

The scope is what unsettles forensic scientists. The researchers believe the weakness has sat in these files since 1995. That covers roughly 30 years of casework, The Hacker News reported. They also say they found no way to tell whether anyone altered a past file. The flaw hits the digital records, not the physical DNA samples.

What the patch fixes, and what it does not

Thermo Fisher’s answer is digital signatures. Five supported product lines now get updates that let labs verify a file has not changed. Three older lines, past end of life, get nothing. For labs that cannot update, the company falls back on basics: chain of custody, encrypted storage, least privilege and limited network access.

The catch sits in two words. The signatures help “moving forward.” The bulletin does not say whether labs can check files made before the update. So the fix draws a line under future evidence and leaves the years behind it unverifiable. Thermo Fisher says it has found no case where anyone exploited the flaw.

The paper trail is still thin. As of 3 August, the identifier had no entry in the national vulnerability database. It also did not appear in the US catalogue of actively exploited bugs. Nathan Adams and two colleagues found the issue and reported it with CISA, the US cyber-defence agency.

Why it matters

Pulling this off takes real access. An attacker would need to reach a lab’s servers, locally or remotely, and understand how DNA testing runs. That points to insiders or intruders, not anyone on the internet. The worry is not scale. It is what the evidence is.

DNA is the proof juries trust most. A digital file that someone can silently rewrite puts a question mark over that trust. It fits a wider pattern. AI has made breaking in faster and cheaper, and keeps drifting deeper into criminal justice. The samples in the freezer are safe. The files the court reads get a signature, and only from today.

Get the TNW newsletter

Get the most important tech news in your inbox each week.