Security Flaws Found in TCG Opal2 Hardware-Encrypted SSDs

Security Flaws Found in TCG Opal2 Hardware-Encrypted SSDs

First seen 21 Jul 2026, 10:35 UTC Feeds2.FeedburnerFeeds.4Sysops 79% similarity 64.5

Article Content

Browse articles
ThreatCluster

Researchers tested 38 hardware-encrypted SSDs compliant with the TCG Opal2 standard and discovered significant vulnerabilities. Issues included predictable random number generation, flawed PSID reset tokens, and a reused tweak value on some Lenovo OEM drives. These flaws compromise the integrity of the encryption, leading to potential data exposure. While Micron addressed one firmware issue, many other vulnerabilities remain unpatched and unsupported. Millions of laptops and workstations rely on these drives for encryption, raising concerns about widespread security risks. The findings highlight the need for verification rather than blind trust in hardware encryption features.

Key Points: • 38 SSDs tested revealed critical vulnerabilities in hardware encryption. • Flaws included predictable random numbers and flawed PSID reset tokens. • Many vulnerabilities remain unpatched, affecting millions of devices.

ThreatCluster AI

Timeline

2026-07-21
Research findings published on SSD vulnerabilities
Researchers tested 38 TCG Opal2 compliant SSDs and found significant security flaws, impacting data encryption.
Feeds.4Sysops
2026-07-21
Testing results shared by Milan Brož
Milan Brož and colleagues revealed vulnerabilities in hardware encryption of SSDs, affecting millions of laptops.
Feeds2.Feedburner

Community

Browse all →