Skip to content
Conference

CRYPTIC: CRYptographic FPGA Targeting through Intelligent Corruption

Aug 2026 · National Aerospace and Electronics Conference · pp. 373-377 · 0 citations · 13 references

Abstract

Cryptographic accelerators implemented on Field-Programmable Gate Arrays (FPGAs) are highly vulnerable to bitstream-level fault injection attacks. However, executing spatially precise attacks on undocumented, proprietary bitstreams remains a significant reverse-engineering challenge. In this paper, we propose a novel, fully automated framework that leverages Large Language Models (LLMs) to guide bitstream manipulation without requiring access to the original HDL source code or post-synthesis netlists. Leveraging the Project X-Ray toolchain, we abstract proprietary Xilinx Artix-7 bitstreams into semantic FPGA Assembly (FASM). We apply an information-entropy heuristic to successfully localize high-density Look-Up Tables (LUTs) corresponding to Advanced Encryption Standard (AES) S-Boxes, and utilize an LLM to autonomously synthesize partial stuck-at faults. Our evaluation on a ChipWhisperer CW305 target yielded a critical discovery: targeted manipulation of the X40 slice column caused a catastrophic state machine failure rather than localized data-path corruption. The hardware consistently output a null-state ciphertext array (all zeros) regardless of the provided plaintext. These results expose a severe Denial of Service (DoS) vulnerability stemming from the physical co-location of sequential control routing and combinatorial cryptographic logic by standard synthesis tools. Our findings demonstrate the feasibility of neutralizing secure cryptographic wrappers via targeted bitstream mutation and underscore the necessity of enforcing strict physical isolation boundaries (p-blocks) in secure hardware floorplanning.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.