Skip to content

Security

The attacks we defeat, and the ones we name plainly.

Most abuse runs on software-only attacks that cost cents. Those stop outright. Everything above that tier gets more expensive than what it steals — and where hardware can't help at all, we say so.

Coverage

What we stop, and where it works.

Every attack we defend against, grouped by what it costs the attacker to run — and which of your platforms it's covered on.

stopped~ partly — some checks don't exist here not claimed — needs another layer can't happen on this platform
AttackCosts themWindowsTPM 2.0LinuxTPM 2.0macOSSecure EnclaveAndroidKey AttestationiOSApp Attest
Software-onlycents per fake

Cloud VMs, virtual TPMs and software emulators. Where essentially all real-world abuse volume lives — and where a hardware check stops it outright.

VM-spawn-and-discard account farming$0.01–$0.10
Cloud-vTPM account farming (NitroTPM / Azure / GCP)$0.01–$0.50
swtpm emulator account farming~$0
CAPTCHA solver-farm bot signup$0.001–$0.005
Anti-detect browser + residential proxy$0.20–$1
Email/phone churn signup$0.05–$0.50
Firmware exploitshours of work

Known flaws in a chip's firmware, limited to the shrinking pool of unpatched machines.

TPM-Fail timing side-channel~$0
ROCA on Infineon RSAcompute only
faulTPM voltage glitching$200 rig + hours
CVE-2025-2884 OOB read (Pluton/fTPM)~$0
TPM-Genie hardware interposer$30 + skill
Real device farms$30–$200 each

The honest cost floor. The chips are genuine, so the attacker buys hardware — and buying in bulk leaves a cluster you can see.

Refurb device farm$30–$200
Burner-phone-service farm$40–$100
Physical tampering$200+ and hands on the machine

Only possible where the chip is a separate, removable part.

TPM chip swap (discrete TPM only)$40–$200
Header-pin TPM module replacement$20–$40
Silicon extractionsix figures per device

Nation-state lab work. Off the table for commercial abuse.

Decapping / electron microscopy$50K–$200K
Replay & relayfree, if it works

Reusing a genuine device's proof somewhere else.

Cloud-cuckoo relay~$0
Physical-cuckoo relay~$0
Quote replay$0
Session-binding bypass$0
Not solvable by hardware

Named plainly because pretending otherwise is worse than saying it. These need layered defenses, not attestation.

Compensated real users ('device mercenaries')$1–$50
Account-takeover post-enrollmentvariable
Device theft / borrowed devicevaries
Supply-chain compromise of manufacturer CAnation-state
Insider threat (Root Herald operator)n/a

Coverage is derived, not asserted per cell: each of our ten checks either exists on a platform or doesn't, and an attack counts as stopped where every check that defeats it is available. Windows and Linux run full TPM 2.0 attestation; macOS, Android and iOS use their platform's own hardware attestation, which has no boot-measurement log — that gap is what most of the ~ marks are.

Explicitly out of scope

What we don't claim to solve

  • One-human-one-device with bad intent. We bind devices to identities; identity behaviour is your policy call.
  • In-person social engineering. A real user, a real attestation, attacker-coached.
  • Account takeover after enrollment. Step-up MFA and session management belong in your stack.
  • State-level adversaries. Outside the threat model for any commercial SaaS.
  • Supply-chain compromise of manufacturer PKI. Detection and response only — the risk every PKI-based system carries.
  • Insider threat at Root Herald. SOC 2 controls, in progress. Not protocol.

Catalogue

Every threat, with its cost tier, defence layers and residual risk.

Tier 1 — Software-only attacks

Bots, throwaway cloud servers, software chip emulators. Stopped outright: the proof does not check out.

T-101VM-spawn-and-discard account farming$0.01–$0.10 · Infinite
Mechanism
Rent cloud VMs, run signup with each as a fresh identity. Cost ~$0.005/hr per instance.
Defence
L2, L3, L9
Residual
None at the cryptographic layer. Attacker must escalate.
Real-world
LayerZero's 803K excluded wallets were largely cloud-VM clusters.
T-102Cloud-vTPM account farming (NitroTPM / Azure / GCP)$0.01–$0.50 · Infinite
Mechanism
Cloud VM has a real virtual-TPM 2.0 producing a structurally valid attestation. Bypasses naive 'did they have a TPM' checks.
Defence
L2, L3, L4, L9
Residual
None under strict-hardware. Under cloud-permissive policy, IID cross-validation closes it.
T-103swtpm emulator account farming~$0 · Infinite
Mechanism
Userspace swtpm emulator produces TPM 2.0 commands and certs chaining to swtpm-localca.
Defence
L2, L3, L9
Residual
None.
Real-world
SUSE virt guide documents emulated TPM reports manufacturer 49424d00 regardless of host.
T-104CAPTCHA solver-farm bot signup$0.001–$0.005 · Infinite
Mechanism
Solver farms defeat CAPTCHA at $1–$3 / 1000 solves.
Defence
Out of scope at the cryptographic layer.
Residual
Out-of-scope for Root Herald directly — but composes: solver-farm wins CAPTCHA, fails attestation.
T-105Anti-detect browser + residential proxy$0.20–$1 · Infinite
Mechanism
Rotated browser fingerprints + residential IP egress. Defeats FingerprintJS / Castle / DataDome.
Defence
L8 (partial), L10
Residual
None when paired with attestation.
T-106Email/phone churn signup$0.05–$0.50 · Infinite
Mechanism
Throwaway emails, SIM farms, virtual-number services.
Defence
Out of scope at the cryptographic layer.
Residual
Out-of-scope alone; composes with attestation.

Tier 2 — Firmware-vulnerability attacks

A known flaw in a chip's firmware, on the shrinking pool of un-patched machines. Boot-fingerprint drift is flagged and revoked bootloaders honoured; there is no blocklist of vulnerable firmware.

T-201TPM-Fail timing side-channel~$0 · Bounded
Mechanism
Timing side-channel against Intel fTPM ECDSA. Recovers private keys in minutes locally.
Defence
L8 (partial), L9
Residual
Root Herald ships no known-bad firmware deny-list. The compensating controls are change-detection against a customer's known-good PCR reference values (a device whose measured boot no longer matches its allow-listed reference is flagged) plus dbx bootloader revocation.
Real-world
tpm.fail PoC; CVE-2019-11090.
T-202ROCA on Infineon RSAcompute only · Bounded
Mechanism
Coppersmith's attack on Infineon RSA generation flaw. ~760K still-vulnerable May 2025.
Defence
L3 (partial), L8 (partial), L9
Residual
Estonian national ID recall (2017) — 750K cards re-keyed.
Real-world
CVE-2017-15361; weaponized PoCs exist.
T-203faulTPM voltage glitching$200 rig + hours · Bounded
Mechanism
Voltage-glitching against AMD fTPM on Zen 2/3. ~$200 hardware, hours per chip.
Defence
L8 (partial), L9
Residual
Requires physical access; bounds to ≈ Tier 3.
Real-world
USENIX / Black Hat USA 2023.
T-204CVE-2025-2884 OOB read (Pluton/fTPM)~$0 · Bounded
Mechanism
OOB read in TCG TPM 2.0 reference. Patched in AGESA 1.2.0.3e.
Defence
L9
Residual
Large unpatched OEM tail through 2026. There is no CVE/firmware-rev deny-list; the policy-layer control is change-detection against known-good PCR reference values plus dbx revocation.
T-205TPM-Genie hardware interposer$30 + skill · Bounded
Mechanism
Hardware interposer on LPC bus intercepts and modifies commands.
Defence
L7, L8
Residual
Bounds to Tier 3 + labor; uneconomic for most use cases.

Tier 3 — Physical device farm

The cost floor. The chips are real, so the attacker buys real hardware; each chip is unique and bulk purchases cluster.

T-301Refurb device farm$30–$200 · Bounded
Mechanism
Buy hundreds of cheap real devices, each a unique valid attestable identity. Logistics-bound.
Defence
L8, L10
Residual
The honest cost floor: capital-bound and detectable, not impossible. Six-figure airdrops still clear this bar.
Real-world
Southeast Asia click-farm operations photographed publicly.
T-302Burner-phone-service farm$40–$100 · Bounded
Mechanism
Many 'fresh' phones used briefly, then retired.
Defence
L8, L10
Residual
Same as T-301.

Tier 4 — Physically swapping the chip

Only on machines with a removable TPM. Most modern PCs bake the chip into the CPU.

T-401TPM chip swap (discrete TPM only)$40–$200 · Bounded
Mechanism
Desolder existing discrete TPM, solder in a new $5 Infineon SLB 9672, mint fresh EKpub.
Defence
L8, L10
Residual
Only applies to discrete TPMs — ~70% of modern Windows uses in-CPU Pluton/PTT/fTPM.
T-402Header-pin TPM module replacement$20–$40 · Bounded
Mechanism
Enthusiast motherboards with TPM header pins allow swap without soldering.
Defence
L8, L10
Residual
Same shape as T-401.

Tier 5 — Extracting a key from the silicon

Lab work, one device at a time. Outside any commercial abuse case.

T-501Decapping / electron microscopy$50K–$200K · Singular
Mechanism
Physical attacks against the TPM die.
Defence
L8 (partial), L10
Residual
Not on the cost ladder for any commercial abuse case.

Relay attacks

Reusing a real device's proof elsewhere. Cloud relays are bound to one instance; physical relays gain nothing because each proof is tied to one chip.

T-601Cloud-cuckoo relay~$0 · Infinite if it works
Mechanism
Harvest a real NitroTPM attestation from one EC2, replay from a different cloud instance.
Defence
L4
Residual
None when RequireCloudCrossValidation = true. Default for cloud-permissive policy.
T-602Physical-cuckoo relay~$0 · Infinite attempts, 1 identity
Mechanism
Script N fresh signup sessions, pipe each nonce to one real TPM, collect N quotes.
Defence
L8
Residual
Attacker is pushed back to Tier 3 (acquire more real chips). The 'cheap relay shortcut' doesn't exist.
T-603Quote replay$0 · Singular
Mechanism
Capture a valid attestation quote, re-submit later.
Defence
L5
Residual
None within the quote-freshness window.
T-604Session-binding bypass$0 · Singular
Mechanism
Use a valid verdict in a context other than the one it was produced for.
Defence
L5, L9
Residual
Depends on RP integrating correctly; libraries get this right by default.

Out of scope for hardware alone

A real person paid to sign up, a stolen account, a stolen device, a compromised manufacturer, a rogue insider.

T-701Compensated real users ('device mercenaries')$1–$50 · Bounded
Mechanism
Pay N real users $X each to perform a real attestation from their real devices.
Defence
L10
Residual
Honest disclosure. Hardware attestation alone cannot stop this. Layered defense (hardware floor + behavioral) is the strategy.
Real-world
Documented in LayerZero's airdrop retrospective.
T-702Account-takeover post-enrollmentvariable · Bounded
Mechanism
Compromise a legitimate user's session post-enrollment.
Defence
Out of scope at the cryptographic layer.
Residual
Out-of-scope; step-up MFA / CAEP / session-management is the customer's stack.
T-703Device theft / borrowed devicevaries · Singular
Mechanism
Legitimate hardware under attacker's physical control.
Defence
Out of scope at the cryptographic layer.
Residual
A user can mark a device stolen; the per-tenant ban list then rejects further attestations from it.
T-704Supply-chain compromise of manufacturer CAnation-state · Singular
Mechanism
Attacker compromises an Infineon/ST/Nuvoton/Intel/AMD/Microsoft CA and mints arbitrary EK certs.
Defence
Out of scope at the cryptographic layer.
Residual
Detection + response only.
T-705Insider threat (Root Herald operator)n/a · Singular
Mechanism
Root Herald employee exfiltrates EKpub data or forges verdicts.
Defence
Out of scope at the cryptographic layer.
Residual
SOC 2 controls (in progress, not yet certified); not protocol-level.

Price every attack out of profitability.

Free up to 1,000 active devices a month, no card.