Firmware Shield
Threat active — compromised hardware is already in the field
The threat

There is hardware you can't trust,
already in the field.

US systems run on fielded hardware that may have been tampered with in the supply chain or in the field — routers, cameras, controllers, radios, drives. Faced with gear they can't fully trust, a program has only three choices. Two of them fail.

Documented, not hypothetical

The threat is real

US agencies attribute to China the pre-positioning inside US infrastructure through compromised network devices (Volt Typhoon), and undocumented hardware has turned up in Chinese-made port cranes and solar inverters. The equipment is already installed across government and critical-infrastructure sites — and once it's in the field, the usual options run out fast.

Three choices

Two of them fail

Choice 1 — Scan

Scan it

You can't prove a hidden implant isn't there by looking for it — an adversary designs it to evade the scan. A clean report is not a clean device.

Choice 2 — Rip it out

Replace the hardware

Grounding the asset, desoldering fine-pitch chips one board at a time, recertifying everything you touch, sourcing trusted replacements. Certain, but it cannot be done fleet-wide.

Choice 3 — Flush

Reflash it clean

Overwrite the firmware with code you trust, and prove it. The one option that scales — minutes per chip, in the field, without touching the hardware. That's us.

The solution

Image. Check.
Flush. Confirm.

We reflash the firmware with clean firmware we build ourselves — opaque foreign firmware out, open and inspectable firmware in — and prove the chip holds exactly that image, byte-for-byte. On site, by cleared staff. A laptop, a clip, and a validated image, not a depot.

What we do — the flush

The four steps

Image

Read the chip's current firmware, hash it, and keep a full forensic copy of what was on the device.

Check

Screen the firmware for known-bad indicators — banned-maker references, documented backdoors by firmware build.

Flush

Overwrite the chip with a trusted image — the manufacturer's known-good build, or a trusted US-built / open replacement compiled for that board.

Confirm

Read the chip back and prove, byte for byte, that it holds exactly the trusted image. Verify the device still boots and operates.

Every device leaves with a record: asset tag, operator, location, before/after hashes, how the trusted image was validated, and the backup of the original. An auditable chain, not a verbal assurance.
Why our firmware is better

Firmware whose origin we can prove

The device's own firmware is opaque — you don't know what's in it or who touched it. We replace it with firmware whose origin we can prove, two ways: the manufacturer's clean build, verified against the vendor's signature; or a US-built / open-source rebuild (coreboot / U-Boot / OpenWrt class) compiled from auditable source that anyone can read and reproduce. Each trusted image is validated once, centrally, and registered by hash.

Mechanically: we read the raw chip with a clip below the vendor's encrypted/signed update layer — so their signing can neither hide anything from us nor block us — back up the original, write the trusted image, then read the chip back and hash-compare. It must equal the trusted image byte for byte, or the job is marked FAILED. Our tooling does this today, with hard safety gates: always back up first, refuse the write if the image doesn't match the chip, and fail the job on any read-back mismatch.

[1] READ    CVE-2017-7921 backdoor present:            YES
[2] FLUSH   trusted image written; original backed up; verified by read-back
[3] CONFIRM backdoor present now:                      NO (removed)
            chip matches trusted image (hash):         YES
RESULT: PASS — backdoor gone; device provably running only trusted firmware
Proof

Demonstrated on a banned Chinese camera

We demonstrate the whole method on a real device with a real, public backdoor — not a hypothetical.

The device

A Hikvision DS-2CD2132F-I IP camera. Hikvision is partly Chinese-state-owned, banned from federal use under NDAA Section 889, and on the FCC Covered List and Commerce Entity List.

The backdoor

CVE-2017-7921 (DHS ICS-CERT advisory, CVSS 10.0) — a documented access-control backdoor in firmware builds up to V5.4.0. One unauthenticated request returns the admin password.

The flush

Read the firmware, confirm the backdoor by build, reflash a clean image, and verify by hash that the backdoor is gone and the chip holds only trusted code — original preserved as evidence.

In the field

We run the whole method on a real DS-2CD2132F-I with nothing more than a laptop and a clip — no lab, no depot. That is what field remediation looks like.

The verdict

The third path —
and we built it.

Everyone else in firmware security scans and reports. We don't. Firmware Shield assumes the compromise, flushes the firmware, and replaces it with code we control — and we're the only ones doing it. Keep the hardware the country already paid for; lose whatever was hiding in it.

Why us

Why Firmware Shield

Every firm in firmware security sells scanning — analyze the firmware, report what it finds. That fails against a hidden supply-chain implant, because a clean scan only means the scan missed — exactly what a competent implant is built to produce. The only certain alternative is physically replacing the hardware, impossibly expensive at fleet scale. We take the third path: assume compromise, flush the firmware, and replace it with code we control — in place, by cleared staff, with proof.

And the payoff is bigger than security: we save the hardware. The fielded electronics the country runs on would otherwise be scrapped and replaced — billions of dollars — just to clear a firmware threat. We keep that hardware in service and make it trusted, for the price of labor. You protect US systems and preserve the hardware you already paid for.

Billions
in fielded hardware kept in service instead of replaced
Minutes
to remediate a device in the field, not months in a depot
Byte-for-byte
cryptographic proof of what each device now runs
Why reflashing wins

Same certainty as replacement, a fraction of the cost

 Scan (detect)Rip out (replace)Flush (reflash clean)
Fixes the threat?No — only reportsYesYes — overwrites it whether or not we see it
Scales to a fleet?n/aNo — depot work, one board at a timeYes — minutes per chip, in the field
Touches the hardware?NoDestroys and replaces itNo — non-destructive, a clip on the chip
Asset downtimeNoneGrounded, depot-levelMinimal, done on site
ResultA report, and a maybeA new unit at high costA device provably running trusted code
The gap in the market

Everyone scans. No one flushes.

No one else offers firmware-flush remediation as a service. The money and the products cluster at the two options that don't work for this threat.

Detection vendors scan and report

Eclypsium, Finite State, ONEKEY, Binarly, NetRise. They analyze firmware and tell you what they find. None reflashes fielded gear to a trusted image.

Hardware replacement is the fallback

How bad gear is handled operationally today — expensive and slow, and impossible at fleet scale.

Reflashing to a clean image is the textbook fix for a firmware implant, but it is thrown back on the device owner as a manual task — nobody productizes it. The buyers are defense program offices and critical-infrastructure operators who already own fielded gear they no longer trust and need it made safe without replacing it.

How we help

We make fielded gear
trusted again — on site.

A cleared team reflashes your equipment to trusted firmware where it sits, and hands back proof for every device. Here's exactly what we claim, who it takes, and where it stands.

Honest limits, and the moat

What a flush does and doesn't fix

Fixes firmware, not silicon

Reflashing removes firmware implants and tampering. A malicious chip — a hardware implant in the silicon — is not removed by a flush and still needs the part replaced. We claim the first, never the second, and our banned-maker screen flags when to suspect the second.

Needs a trusted image per device — and that's the moat

A clean image is specific to each board. "Flush anything" does not exist; we flush what we have a validated image for. Building that trusted-image library, model by model, is the real work — and what a competitor can't copy overnight.

Some firmware is locked

Signed boot and hardware roots of trust can refuse an outside write. We identify those up front rather than promise a universal fix.

The defensible claim: we flush every device class we can build a trusted image for and that accepts it — a large, unserved set — and reserve hardware replacement for the few parts confirmed to be malicious silicon.

What working with us looks like

A cleared team, your site, proof for every device

On site

We come to the gear

Cleared staff work on your equipment where it sits — in your spaces, on your controlled networks. No shipping sensitive hardware anywhere.

Non-destructive

A clip, not a soldering iron

We read and reflash the chip in place. The device stays intact and goes back into service the same day.

Proof, not promises

An auditable record

Every device leaves with before/after hashes, the validated trusted image, the operator and location, and a forensic backup of the original firmware.

Built to scale

Minutes per device

Once we hold a trusted image for a device class, we remediate across a whole fleet fast — economics that rip-and-replace can never touch.

Sources

The evidence behind the claims

Where the proof stands: our scan → flush → confirm workflow runs end to end, and the result shown is verified against a controlled test target. Live-hardware validation on a real Hikvision camera is underway — the method is proven; the field result is the step in progress.

The news

This is happening right now.

The firmware and hardware supply-chain threat isn't theoretical or dated — it's front-page reporting and active federal warnings. A sample of the record.

In the headlines

The threat, documented in the open press

Reuters / pv-magazineMay 2025

Hidden devices found in Chinese-made inverters in the U.S.

Reuters reports undocumented communication devices discovered inside Chinese-made solar inverters connected to the US grid — hardware that could bypass firewalls and threaten the power supply.

Read the report →
Associated PressMay 2025

Rogue communication devices found in Chinese solar power inverters

US experts warn that rogue cellular radios embedded in imported inverters could be used to remotely destabilize power grids — a hardware channel no software scan would catch.

Read the report →
The RecordFeb 2024

CISA, FBI warn China-linked hackers are pre-positioning in US infrastructure

Volt Typhoon: PRC state-sponsored actors found living inside US critical-infrastructure networks via compromised devices, positioned to disrupt in a crisis.

Read the report →
Straight Arrow News2025

Rogue Chinese comm devices found in US solar panels and wind turbines

The embedded-device problem extends across renewable-energy hardware installed throughout the US — gear already in the field that owners can't simply rip out.

Read the report →
U.S. House Homeland SecuritySep 2024

Joint investigation finds potential Chinese espionage threats at U.S. ports

Congressional investigators found undocumented cellular modems on Chinese-made ZPMC ship-to-shore cranes operating at American ports.

Read the report →
CISA (primary source)Feb 2024

AA24-038A — PRC state-sponsored actors compromising US critical infrastructure

The official multi-agency advisory: how Volt Typhoon gains and holds persistence on fielded network devices, and why firmware trust is the battleground.

Read the advisory →

Headlines link to third-party reporting and official advisories; summaries are ours. See the Sources panel under How We Help for the full citation list.

Keep the hardware. Lose the compromise.

Firmware Shield is remediation built for the equipment already in the field — defense, critical infrastructure, and government. If that's your problem, let's talk.

Get in touch