Signal & Supply
โ† Archive
September 24, 2026 CHIP SECURITY

China Has Up to 660,000 Smuggled Nvidia Chips. Congress's Fix Turns Every GPU Into a Traceroute.

Export controls have always worked at the border: check the paperwork, watch the crate leave. Once the chip is out the door, nobody checks again. A bipartisan bill headed through Congress would change that โ€” by making every export-controlled AI chip continuously prove where it physically is, using the same trick that tells a website roughly which city you're browsing from.

Key takeaway The Chip Security Act (H.R. 3447 / S.1705) cleared the House Foreign Affairs Committee 42โ€“0 in March 2026 and would direct the Commerce Department to require "chip security mechanisms" โ€” location verification โ€” on covered AI chips within 180 days of enactment. The leading method, ping-based location verification, times round-trip signals between the chip and servers at known locations: because no signal beats the speed of light, a chip can be made to look farther away than it is, but never closer. Nvidia has confirmed it's already built and tested this on H100-class silicon. The backdrop for the urgency: Epoch AI estimates 290,000 to 1.6 million H100-equivalent chips โ€” a median of roughly 660,000, or about a third of China's total AI compute โ€” have been diverted there through illicit channels, including a $2.5 billion pipeline tied to Super Micro that federal prosecutors charged in March 2026.

Try to spoof the chip's location

Three landmark servers at known positions time how long a signal takes to reach the chip and bounce back (RTT). Drag the slider to make the chip's firmware inject fake delay into every reply โ€” the attacker's only real lever. Watch what happens to the estimate. Illustrative scale only: assumes an effective signal speed of 100 km per millisecond of round trip and ignores routing overhead a real network would add.

0 ms
RTT to servers A / B / C
โ€”
Max possible distance
โ€”
Estimated zone size
โ€”
Drag the slider: the shaded zone only ever grows and stays centered on the truth. Delay can blur the estimate. It can't move it, and it can't shrink it below the chip's real distance from any server.

The plain version

Picture proving you're at home using nothing but a phone. Three friends in different, known locations call you, and each times how long it takes your voice to reach them and bounce back. Sound can't travel instantly, so that round-trip time sets a hard ceiling on how far away you could possibly be โ€” you could be closer, but you cannot be farther than the ceiling implies. Draw a circle of that radius around each friend, and the overlap of all three circles is roughly where you are. Add a second and third friend from different directions and the overlap tightens into a small patch.

That's the idea behind "ping-based location verification," and Nvidia has already tested a version of it on its H100 chips. Instead of friends on the phone, it's servers with known coordinates pinging the chip's onboard telemetry. The clever part is what an attacker can and can't fake: they can stall their replies to seem farther away, which only makes the circle bigger and blurrier. They cannot make a reply arrive faster than physics allows, so they can never fake being closer, or in a different country entirely, without visibly breaking the math. It doesn't need GPS, which is easily spoofed and doesn't work inside a windowless data center anyway, and it doesn't require a remote kill switch โ€” it only reports, it doesn't shut anything off.

Why build this now? Because the honor system has failed badly. Researchers at Epoch AI estimate somewhere between 290,000 and 1.6 million Nvidia H100-class chips โ€” call it roughly 660,000 as a middle guess, worth billions of dollars โ€” have been smuggled into China despite export bans, including a $2.5 billion scheme prosecutors tied to server-maker Super Micro this past March. A bill moving through Congress, the Chip Security Act, would require chips like these to keep proving their location for as long as they run, not just at the moment they leave the warehouse.

The expert version

Ping-based location verification (PBLV) exploits a fixed physical constant: signal propagation delay in fiber. Landmark servers at surveyed coordinates issue authenticated challenge-response pings to a chip's onboard telemetry firmware; round-trip time (RTT) sets an upper bound on one-way distance, since routing, queuing, and processing overhead only ever add latency, never subtract it. With three or more non-collinear landmarks, multilateration narrows the feasible region to the intersection of distance circles (spheres, in practice). Independent research groups analyzing this approach report median accuracy on the order of tens of miles โ€” sufficient for confident country-level attribution, though not building-level precision.

The security property that matters is asymmetric: an adversary can trivially inflate apparent distance from a landmark by adding artificial delay or routing through extra hops, which only widens the estimated region while leaving the true location inside it. Faking a shorter distance โ€” the only way to spoof being in an authorized jurisdiction while physically elsewhere โ€” would require beating the true propagation delay, which is not a software problem but a physics one. Nvidia has confirmed its Hopper- and Blackwell-generation silicon already generates the telemetry PBLV needs and that the capability could plausibly ship as a firmware update; the company has explicitly stated the mechanism reports location without functioning as a kill switch or remote shutdown, an important distinction for chipmakers wary of persistent backdoors.

The legislative vehicle is the Chip Security Act (H.R. 3447, introduced by Rep. Bill Huizenga and co-sponsors; S.1705, Sen. Tom Cotton's companion), which passed the House Foreign Affairs Committee 42โ€“0 in March 2026. It directs Commerce to mandate location verification on covered integrated circuits within 180 days of enactment, deliberately written as mechanism-agnostic โ€” software, firmware, or hardware โ€” rather than mandating PBLV specifically. The policy backdrop is Epoch AI's diversion estimate: 290,000 to 1.6 million H100-equivalents smuggled into China through 2025, a median around 660,000, roughly a third of China's total installed AI compute, plus the March 2026 DOJ indictment of Super Micro co-founder Yih-Shyan "Wally" Liaw over an alleged $2.5 billion diversion pipeline. One limitation worth flagging: PBLV verifies where a chip is, not what it's running โ€” a legitimately imported chip can still be repurposed for unauthorized workloads once inside the correct border, so it complements rather than replaces end-use audits and know-your-customer diligence.

Why it matters for tech + supply chain: export controls have policed paperwork at the loading dock for decades; this moves enforcement inside the data center and makes it continuous, which is a genuinely different kind of leverage over where compute actually ends up.

Why it matters for tech + supply chain: if PBLV becomes a firmware-level standard, it shifts export enforcement from a point-in-time customs check to a persistent telemetry stream โ€” changing both the economics of chip diversion and the privacy/sovereignty calculus for legitimate buyers.

Get it in your inbox every morning