Bit2Watt shows 1,000 GPUs can destabilize a 1-MW local grid and trigger blackouts
A malicious tenant can weaponize GPU workloads, causing harmonic distortion, unstable grid modes, and cascading failures.

Cybersecurity researchers from Zhejiang University in Hangzhou, China, unveiled Bit2Watt, a technique for malicious cloud tenants to attack datacenters via GPU workloads. The consequence is existential for operators: cyber monitoring may miss it, and the power grid can be pushed toward blackouts exceeding 80 percent in large-scale systems.
AI datacenters already stress the power grid. Bit2Watt argues a malicious cloud tenant could turn that stress into an attack, using GPU workloads to destabilize electrical infrastructure. In the researchers' proof of concept, an adversary simulating harm on a 1-MW local power grid made mainly of distributed energy resources like photovoltaics would use 1,000 GPUs to create total harmonic distortion of 46.8 percent. They also claim this would squander nearly half the electrical current on non-productive work, add about 20 percent more heat than normal operation, and introduce an unstable mode through a negative damping ratio of -0.27.
That is the core of the threat model: it is not “hack a firewall” first. It is “abuse the workload itself” to alter the physical behavior of power electronics and grid dynamics. The authors, Zhouhao Ji, Kaikai Pan, and Wenyuan Xu, lay out their technique in a preprint paper titled “Bit2Watt: A Cyber-Physical Vulnerability Exploiting GPU Workloads Across Power and Computing Infrastructures.” They describe an adversary masquerading as a legitimate cloud tenant, launching GPU workloads designed to produce high-frequency power modulation that could induce voltage excursions, harmonic distortion, and damping degradation.
Why does this even work in the first place? Because AI training workloads are already known to produce large, synchronized power swings inside datacenters. The source points to a 2025 research paper from Microsoft, Nvidia, and OpenAI that argues for power stabilization during AI training: the shift from GPU computation to GPU data synchronization causes large power swings. Meta’s paper on training Llama 3 also flags the risk. It notes that during training, tens of thousands of GPUs may increase or decrease power consumption at the same time, such as when GPUs wait for checkpointing or collective communications, or when the entire training job starts up or shuts down. When that happens, the paper says it can result in instant fluctuations of power consumption across the datacenter on the order of tens of megawatts, stretching the limits of the power grid.
Bit2Watt essentially weaponizes that synchronization. The researchers claim GPU loads can reach modulation frequencies exceeding 6,000 Hz, compared with only a few hertz observed in conventional household loads such as air conditioners. In plain English: the attack is about turning coordinated workload behavior into a pattern the electrical system struggles to absorb safely. The authors contend that in their scenario, the destabilization can get bad enough to exceed ordinary system tolerances, potentially leading to cascading failures. They write that once protections are triggered and computing loads are shed, it can trigger cascading failures, potentially leading to blackouts exceeding 80 percent in large-scale power systems.
One of the more uncomfortable parts for operators is the stealth angle. The researchers argue the attack is relatively covert because it can be launched within authorized workload execution paths. In other words, the workloads may look like “normal” permitted computing from a cyber perspective, and it would likely be missed by cloud-provider monitoring frameworks that focus on typical intrusion indicators rather than physical power signatures. That pushes the defense problem away from a single firewall upgrade. The paper’s proposed response is to coordinate defenses across the cyber and physical layers, specifically looking for malicious computation patterns that correlate with power behavior. They also emphasize the need for local energy buffering systems to handle power demand spikes.
There is also a second-order risk the authors point to: Watt2Bit, a potential side-channel attack. Bit2Watt describes how electrical and thermal stress from a malicious workload can create denial of service events, and, crucially, could enable covert exfiltration via power modulation. As a proof of concept, they showed they could recover a 50-bit test sequence using frequency-shift keying (FSK) encoding. The message for executives is not just “you might get hit.” It is “the same physical pathway that creates instability might also become a communication channel.” Even if the exact methodology is still early-stage research, it reflects a direction the industry is already moving: power and computing infrastructures are no longer separable.
For boards, CFOs, and operators, the immediate stake is continuity and liability. If workload scheduling can be a lever for physical disruption, then the classic split between IT risk and facilities or grid reliability becomes an expensive fantasy. The paper also implies a budgeting shift: defenses that include physical-layer monitoring, local buffering, and cross-domain detection likely cost real money and require real coordination with utility-facing reliability practices. And if the threat can masquerade as authorized execution, governance and auditability around workload behavior become as important as access control.
Bit2Watt also changes how competitors and partners should read each other’s posture. Microsoft, Nvidia, and OpenAI have already argued for power stabilization during AI training; Meta has already quantified the tens of megawatts swings that can stretch the grid. The Zhejiang University researchers are taking the next step: not just acknowledging the risk, but proposing a malicious mechanism and a plausible pathway to large-scale blackout outcomes exceeding 80 percent. In a world where AI compute procurement is increasingly constrained by power availability, any failure mode that turns compute scheduling into grid destabilization is a business-critical vulnerability, not a niche security paper.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Technology

By 2035, data centers could use 4x more electricity than today
A new build pipeline through 2033 may consume power on par with India, forcing operators to plan for scarcity now.
Frozen-fiber tech couples light and sound 1,000x more strongly than standard glass
A glass capillary frozen into a fiber lets photonic systems trade energy waste for tighter light-sound linkage.
Nvidia publishes Vera AI server CPU specs, posting SPEC CPU 2026 integer lead over AMD
The company released a white paper with SPEC CPU 2026 results, placing Vera ahead of AMD's Epyc 9755 for integer performance.

