US systems run on fielded hardware that may have been tampered with in the supply chain or in the field — routers, cameras, controllers, radios, drives. Faced with gear they can't fully trust, a program has only three choices. Two of them fail.
US agencies attribute to China the pre-positioning inside US infrastructure through compromised network devices (Volt Typhoon), and undocumented hardware has turned up in Chinese-made port cranes and solar inverters. The equipment is already installed across government and critical-infrastructure sites — and once it's in the field, the usual options run out fast.
You can't prove a hidden implant isn't there by looking for it — an adversary designs it to evade the scan. A clean report is not a clean device.
Grounding the asset, desoldering fine-pitch chips one board at a time, recertifying everything you touch, sourcing trusted replacements. Certain, but it cannot be done fleet-wide.
Overwrite the firmware with code you trust, and prove it. The one option that scales — minutes per chip, in the field, without touching the hardware. That's us.
We reflash the firmware with clean firmware we build ourselves — opaque foreign firmware out, open and inspectable firmware in — and prove the chip holds exactly that image, byte-for-byte. On site, by cleared staff. A laptop, a clip, and a validated image, not a depot.
Read the chip's current firmware, hash it, and keep a full forensic copy of what was on the device.
Screen the firmware for known-bad indicators — banned-maker references, documented backdoors by firmware build.
Overwrite the chip with a trusted image — the manufacturer's known-good build, or a trusted US-built / open replacement compiled for that board.
Read the chip back and prove, byte for byte, that it holds exactly the trusted image. Verify the device still boots and operates.
The device's own firmware is opaque — you don't know what's in it or who touched it. We replace it with firmware whose origin we can prove, two ways: the manufacturer's clean build, verified against the vendor's signature; or a US-built / open-source rebuild (coreboot / U-Boot / OpenWrt class) compiled from auditable source that anyone can read and reproduce. Each trusted image is validated once, centrally, and registered by hash.
Mechanically: we read the raw chip with a clip below the vendor's encrypted/signed update layer — so their signing can neither hide anything from us nor block us — back up the original, write the trusted image, then read the chip back and hash-compare. It must equal the trusted image byte for byte, or the job is marked FAILED. Our tooling does this today, with hard safety gates: always back up first, refuse the write if the image doesn't match the chip, and fail the job on any read-back mismatch.
[1] READ CVE-2017-7921 backdoor present: YES
[2] FLUSH trusted image written; original backed up; verified by read-back
[3] CONFIRM backdoor present now: NO (removed)
chip matches trusted image (hash): YES
RESULT: PASS — backdoor gone; device provably running only trusted firmware
We demonstrate the whole method on a real device with a real, public backdoor — not a hypothetical.
A Hikvision DS-2CD2132F-I IP camera. Hikvision is partly Chinese-state-owned, banned from federal use under NDAA Section 889, and on the FCC Covered List and Commerce Entity List.
CVE-2017-7921 (DHS ICS-CERT advisory, CVSS 10.0) — a documented access-control backdoor in firmware builds up to V5.4.0. One unauthenticated request returns the admin password.
Read the firmware, confirm the backdoor by build, reflash a clean image, and verify by hash that the backdoor is gone and the chip holds only trusted code — original preserved as evidence.
We run the whole method on a real DS-2CD2132F-I with nothing more than a laptop and a clip — no lab, no depot. That is what field remediation looks like.
Everyone else in firmware security scans and reports. We don't. Firmware Shield assumes the compromise, flushes the firmware, and replaces it with code we control — and we're the only ones doing it. Keep the hardware the country already paid for; lose whatever was hiding in it.
Every firm in firmware security sells scanning — analyze the firmware, report what it finds. That fails against a hidden supply-chain implant, because a clean scan only means the scan missed — exactly what a competent implant is built to produce. The only certain alternative is physically replacing the hardware, impossibly expensive at fleet scale. We take the third path: assume compromise, flush the firmware, and replace it with code we control — in place, by cleared staff, with proof.
And the payoff is bigger than security: we save the hardware. The fielded electronics the country runs on would otherwise be scrapped and replaced — billions of dollars — just to clear a firmware threat. We keep that hardware in service and make it trusted, for the price of labor. You protect US systems and preserve the hardware you already paid for.
| Scan (detect) | Rip out (replace) | Flush (reflash clean) | |
|---|---|---|---|
| Fixes the threat? | No — only reports | Yes | Yes — overwrites it whether or not we see it |
| Scales to a fleet? | n/a | No — depot work, one board at a time | Yes — minutes per chip, in the field |
| Touches the hardware? | No | Destroys and replaces it | No — non-destructive, a clip on the chip |
| Asset downtime | None | Grounded, depot-level | Minimal, done on site |
| Result | A report, and a maybe | A new unit at high cost | A device provably running trusted code |
No one else offers firmware-flush remediation as a service. The money and the products cluster at the two options that don't work for this threat.
Eclypsium, Finite State, ONEKEY, Binarly, NetRise. They analyze firmware and tell you what they find. None reflashes fielded gear to a trusted image.
How bad gear is handled operationally today — expensive and slow, and impossible at fleet scale.
Reflashing to a clean image is the textbook fix for a firmware implant, but it is thrown back on the device owner as a manual task — nobody productizes it. The buyers are defense program offices and critical-infrastructure operators who already own fielded gear they no longer trust and need it made safe without replacing it.
A cleared team reflashes your equipment to trusted firmware where it sits, and hands back proof for every device. Here's exactly what we claim, who it takes, and where it stands.
Reflashing removes firmware implants and tampering. A malicious chip — a hardware implant in the silicon — is not removed by a flush and still needs the part replaced. We claim the first, never the second, and our banned-maker screen flags when to suspect the second.
A clean image is specific to each board. "Flush anything" does not exist; we flush what we have a validated image for. Building that trusted-image library, model by model, is the real work — and what a competitor can't copy overnight.
Signed boot and hardware roots of trust can refuse an outside write. We identify those up front rather than promise a universal fix.
The defensible claim: we flush every device class we can build a trusted image for and that accepts it — a large, unserved set — and reserve hardware replacement for the few parts confirmed to be malicious silicon.
Cleared staff work on your equipment where it sits — in your spaces, on your controlled networks. No shipping sensitive hardware anywhere.
We read and reflash the chip in place. The device stays intact and goes back into service the same day.
Every device leaves with before/after hashes, the validated trusted image, the operator and location, and a forensic backup of the original firmware.
Once we hold a trusted image for a device class, we remediate across a whole fleet fast — economics that rip-and-replace can never touch.
Where the proof stands: our scan → flush → confirm workflow runs end to end, and the result shown is verified against a controlled test target. Live-hardware validation on a real Hikvision camera is underway — the method is proven; the field result is the step in progress.
The firmware and hardware supply-chain threat isn't theoretical or dated — it's front-page reporting and active federal warnings. A sample of the record.
Reuters reports undocumented communication devices discovered inside Chinese-made solar inverters connected to the US grid — hardware that could bypass firewalls and threaten the power supply.
Read the report →US experts warn that rogue cellular radios embedded in imported inverters could be used to remotely destabilize power grids — a hardware channel no software scan would catch.
Read the report →Volt Typhoon: PRC state-sponsored actors found living inside US critical-infrastructure networks via compromised devices, positioned to disrupt in a crisis.
Read the report →The embedded-device problem extends across renewable-energy hardware installed throughout the US — gear already in the field that owners can't simply rip out.
Read the report →Congressional investigators found undocumented cellular modems on Chinese-made ZPMC ship-to-shore cranes operating at American ports.
Read the report →The official multi-agency advisory: how Volt Typhoon gains and holds persistence on fielded network devices, and why firmware trust is the battleground.
Read the advisory →Headlines link to third-party reporting and official advisories; summaries are ours. See the Sources panel under How We Help for the full citation list.
Firmware Shield is remediation built for the equipment already in the field — defense, critical infrastructure, and government. If that's your problem, let's talk.
Get in touch