Skip to content
Security Flaws Found in TCG Opal2 Hardware-Encrypted SSDs

Security Flaws Found in TCG Opal2 Hardware-Encrypted SSDs

First seen 21 Jul 2026, 10:35 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 22, 2026 at 10:22 UTC
  • 38 SSDs tested revealed critical vulnerabilities in hardware encryption.
  • Flaws included predictable random numbers and flawed PSID reset tokens.
  • Many vulnerabilities remain unpatched, affecting millions of devices.

Researchers tested 38 hardware-encrypted SSDs compliant with the TCG Opal2 standard and discovered significant vulnerabilities. Issues included predictable random number generation, flawed PSID reset tokens, and a reused tweak value on some Lenovo OEM drives. These flaws compromise the integrity of the encryption, leading to potential data exposure. While Micron addressed one firmware issue, many other vulnerabilities remain unpatched and unsupported. Millions of laptops and workstations rely on these drives for encryption, raising concerns about widespread security risks. The findings highlight the need for verification rather than blind trust in hardware encryption features.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 62d ago How this analysis works

Timeline

2026-07-21
Research findings published on SSD vulnerabilities
Researchers tested 38 TCG Opal2 compliant SSDs and found significant security flaws, impacting data encryption.
Feeds.4Sysops
2026-07-21
Testing results shared by Milan Brož
Milan Brož and colleagues revealed vulnerabilities in hardware encryption of SSDs, affecting millions of laptops.
Feeds2.Feedburner

More articles in this cluster (2)