A cloud tenant could rattle the power grid with nothing but a rented GPU, researchers say Researchers at Zhejiang University have shown in a preprint called Bit2Watt that a cloud tenant could destabilize a power grid by rapidly cycling a rented GPU's power draw more than 6,000 times per second. In a worst-case simulation of 1,000 GPUs pulsing in lockstep on a small solar-and-battery grid, nearly half the current was wasted and the grid turned unstable; on a model of the European transmission network, the disturbance cascaded to shed about 81% of the load. The attack exploits the fact that a GPU's power draw follows its workload, and the authors note that no bug exists to patch because standard monitoring samples power too slowly to catch the fast flicker. AI data centres already strain the grid https://thenextweb.com/news/nscale-essex-data-centre-uk-grid-delay just by running. A new paper asks a darker question: what if a tenant tried to break it on purpose? Three researchers at Zhejiang University set out the idea in a preprint https://arxiv.org/abs/2607.05993 called Bit2Watt, accepted to a leading hardware-security conference. As The Register https://www.theregister.com/ai-and-ml/2026/07/20/malicious-cloud-customers-can-bring-down-the-power-grid/5275193 reported, it imagines a paying customer as the attacker. How it works The trick rests on a simple fact. A GPU’s power draw follows whatever it is computing. Load it hard and the current spikes. Let it idle and the current drops. Flip between those states on a schedule and you get a controllable power wobble at the wall socket. The researchers pushed it past 6,000 times a second, far faster than the gentle sway of a household load like an air conditioner. They show two ways to do it. One uses a purpose-built workload that a provider might learn to spot. The other, harder to catch, hides the pattern inside a real AI training run, where it blends into normal noise. Neither needs special access, because a tenant already controls its own jobs. The scary number, and the asterisk Alone, one GPU does little. The danger, the paper argues, is in bulk. It models 1,000 GPUs pulsing in perfect lockstep on a small grid mostly fed by solar and batteries. In that worst case, the simulated grid turns unstable, wasting nearly half its current and running hot. Pushed onto a model of the European transmission network, a small local disturbance cascades until it sheds about 81% of the load. Here is the asterisk. As reporting on cloud attacks https://thenextweb.com/news/hugging-face-ai-agent-breach-glm-forensics often has to stress, that figure is a property of one simulation stacked with worst-case assumptions, not a forecast. The whole attack hinges on getting a real fleet of cloud GPUs to pulse in perfect sync, which the authors admit is still unsolved. No live system was attacked. Grounded in real physics What keeps this from being pure theory is that the physics is on record. In 2025, Microsoft, OpenAI, and Nvidia https://arxiv.org/abs/2508.14318 warned that the synchronised power swings of large training jobs can damage grid infrastructure when their rhythm lines up with a utility’s. Meta flagged the same risk while training Llama 3. The grid has already had a fright by accident. In July 2024, a fault near data-centre-heavy Northern Virginia knocked about 1,500 megawatts https://www.nerc.com/globalassets/our-work/reports/event-reports/incident review large load loss.pdf of load off the grid at once. Regulators said there was no crisis, then set up a task force to study the danger as these power-hungry sites https://thenextweb.com/news/white-house-utilities-ai-power-cost-pledge multiply. The loop back, and no bug to patch The researchers also sketch a feedback attack they call Watt2Bit. The same electrical stress that rattles the grid can overheat the servers, tripping their protection and knocking them offline. A power problem becomes a denial of service. The awkward part is that there is no bug to patch. Standard monitoring samples power far too slowly to catch the fast flicker. The deeper issue is the design itself. Volatile GPU loads now sit on a grid full of solar inverters, and nothing watches across the two. As the data centre https://thenextweb.com/news/europe-sovereign-ai-data-centre-constraints-onnec and the grid it leans on grow more entangled, they stay run by different firms, watched by different tools. That seam, the paper implies, has no clear owner. Fixes exist on each side, but tying them together is still to come, even as the AI build-out https://thenextweb.com/news/ai-memory-crunch-boom-bust-2028 races ahead. Get the TNW newsletter Get the most important tech news in your inbox each week.