
Wed Jul 08 2026
The security mechanism at the heart of confidential computing — the technology hyperscalers cite as proof that sensitive data is safe in their clouds — has been formally proven to contain a fundamental architectural flaw, and the strongest fix may not be possible at all. That is the conclusion of independently verified research from TU Dresden, presented at the AsiaCCS 2026 and ESORICS 2026 conferences, which used formal verification tools to exhaustively analyse “attested TLS” — the protocol that is supposed to cryptographically prove a client is talking to a genuine, unmodified Trusted Execution Environment (TEE) before any sensitive data changes hands. The verdict: it doesn’t.
The research, led by Muhammad Usama Sardar, uncovered relay and diversion attacks against state-of-the-art attested TLS implementations. A client can verify the attestation evidence of a genuine, trustworthy server — and still end up encrypting its traffic to an entirely different, malicious machine. The protocol checks the software’s integrity, not the identity of the machine actually receiving the data.
Worse, the team tested seven different mechanisms for cryptographically binding attestation evidence to the underlying connection. None of them prevented relay attacks. The strongest level of binding — tying evidence to the key that actually encrypts application data — may not be achievable within the current architecture without fundamentally changing TLS 1.3 itself.
These are not laboratory curiosities. The vulnerable implementations analysed include systems running in production today, among them Meta’s Private Processing infrastructure for WhatsApp. The responsible disclosure produced CVE-2026-33697, rated 7.5 (high severity) — a higher score than the headline-making BadRAM attack of 2024.
Notably, a prior security audit of Meta’s implementation by a well-regarded firm missed the flaw entirely. Manual audits sample; formal verification checks every scenario the threat model allows. The flaw was provably there all along — it simply took mathematics, not inspection, to find it.
Confidential computing has been marketed as the technical backbone of sovereign cloud strategies — the argument being that even if a foreign hyperscaler operates the infrastructure, hardware-enforced enclaves and remote attestation guarantee that customer data remains protected and verifiable.
Germany’s Federal Office for Information Security (BSI), the country’s national cybersecurity authority, has now publicly undercut that positioning. BSI characterises confidential computing as a defence-in-depth component — useful, but one that does not mitigate dependencies on identity and key management, and whose vendor marketing “might give too much weight” to its technical capabilities. The agency’s assessment is blunt: confidential computing alone cannot satisfy the requirements for digital sovereignty.
The legal dimension is equally uncomfortable. When asked whether US legislation that can compel hardware manufacturers to cooperate with intelligence orders poses a sovereignty risk to its attestation infrastructure, Intel declined to answer. The architecture may be defensible; the jurisdiction is not.
Confidential computing is frequently positioned as the pragmatic alternative to Fully Homomorphic Encryption (FHE) — the argument being that if hardware enclaves can protect data in use, the computational overhead of FHE is unnecessary. This research punches a significant hole in that argument.
The two approaches rest on fundamentally different foundations. Confidential computing asks you to trust a chain: the hardware manufacturer, the attestation infrastructure, and a handshake protocol that has now been formally shown to fail. FHE asks you to trust mathematics. Data protected by FHE remains encrypted throughout processing — there is no enclave to attest, no handshake to divert, and no relay attack that yields anything but ciphertext.
FHE is not a complete fix for data sovereignty, and no single technology is. But encryption-based protection — where security travels with the data itself rather than depending on whose hardware it lands on — is the one layer of a sovereignty strategy that doesn’t require trusting a vendor’s silicon, a vendor-dominated standards body, or a foreign legal regime.
This is the principle behind 01 Quantum’s approach. Our Quantum AI Wrapper (QAW) combines FHE with NIST-standardised post-quantum cryptography (FIPS 203/204/205), enabling AI workloads to process sensitive data that remains encrypted end to end — in transit, at rest, and critically, in use. The protection is cryptographic, not architectural: it holds regardless of which cloud, which chip, or which jurisdiction the computation runs in.
The same philosophy extends to our digital asset solutions. The Quantum Crypto Wrapper (QCW) and Quantum DeFi Wrapper (QDW) bring post-quantum protection to assets on existing blockchains including Bitcoin, Ethereum, Solana, and Hyperliquid — because the “harvest now, decrypt later” threat means data and assets encrypted with today’s standards are already being collected for future decryption.
With over 30 years of cybersecurity heritage and strategic guidance from NIST PQC contributors like Dr. Edoardo Persichetti, co-author of the HQC standard selected by NIST in 2025, 01 Quantum builds security that doesn’t ask you to take a vendor’s word for it.
When the handshake that underpins confidential computing can’t prove who’s on the other end, the case for protection rooted in encryption itself — quantum-safe, verifiable, and jurisdiction-proof — has never been stronger.