Stealthium monitors neo-cloud telemetry for accelerator hacks

Startup Stealthium installs an agent in customer infrastructure to scan neo-cloud telemetry for signs of compromise in AI accelerators and address visibility gaps in existing security tools.

Stealthium, a security startup, is deploying a software agent inside customer environments to monitor telemetry from neo-clouds and flag signs of compromise in AI accelerators. The company’s system looks for faint indicators of tampering in telemetry flows rather than attempting to inspect accelerator hardware directly.

Neo-clouds are specialized, AI-first clouds built around accelerator chips that differ from standard CPUs and general-purpose GPUs. Chipmakers include Tenstorrent, Groq, Cerebras, Graphcore and Google. Cloud providers such as CoreWeave and Nebius use these accelerators to support large-scale model training and high-throughput inference, including low-latency applications like chatbots.

Security tools developed for CPU-centric operating systems do not have direct visibility into accelerator silicon or high-speed video memory. That gap can leave compromises undetected by both neo-cloud providers and customers. Stealthium describes the situation as a supply-chain risk for organizations that train or deploy sensitive models on third-party neo-cloud infrastructure.

Stealthium’s agent runs inside a customer’s environment and analyzes telemetry emitted by the neo-cloud nodes. The software is trained to recognize patterns consistent with misuse or tampering, such as abnormal virtualization behavior, unexpected resource usage, or telemetry anomalies that can indicate cross-tenant access or hidden processes.

The company points to recent malware campaigns that exploited nested virtualization as an example of how an attacker might create rogue environments or sell access to compromised instances. A similar exploitation in a neo-cloud could produce cross-tenant leakage, allowing a third party to read or influence another customer’s models.

Chris Hosking, GTM advisor at Stealthium, warned that many organizations lack real-time controls and observability for the accelerator layer. “If you cannot see something happening, then nothing is happening,” he said, adding that standard shared-responsibility models for cloud security are harder to apply when the attack surface includes accelerator silicon and its memory.

Stealthium states that its detections focus on hints in telemetry rather than direct hardware inspection. The company maintains and updates detection logic to adapt to new techniques, and it delivers alerts so customers can investigate and respond when telemetry indicates suspicious activity.

Industry observers note that access to model weights or the ability to alter model behavior could be used for financial theft, intellectual property loss, influence operations or covert computing tasks such as cryptomining. Stealthium describes its product as an early entrant in a group of firms aiming to provide observability for AI-accelerated runtimes through telemetry analysis.

Customers who install the agent receive an additional line of sight into neo-cloud environments while continuing to rely on the neo-cloud provider for infrastructure. The agent’s role is to surface anomalies that conventional CPU-focused security tools cannot detect inside accelerator-driven services.

Articles by this author