fast16 as a Second-Order Subversion Attack

Bilar, Daniyel Yaacov · 2026

SentinelOne's April 2026 disclosure of fast16, a precision sabotage framework compiled in August 2005, predates Stuxnet by five years and corrupts floating-point calculations in engineering simulation software via kernel-mode filesystem filtering. The infosec community described the mechanism accurately but did not classify the attack class. This paper applies the nth-order attackframework from Bilar (NATO CCDCOE, 2009) and argues fast16 is a second-order subversion attack: the high-precision research end system is reached through two successive ancillary systems, the OS kernel filesystem stack and the engineering simulation software above it. The wormlet is a delivery mechanism, not a distinct ancillary hop. fast16 is structurally comparable to Thompson's compiler trojan but one order lower and more covert: it operates at runtime below the application layer with no source-level or on-disk trace, defeating the reproducible-build defense that catches Thompson. Stuxnet, dr0wned, and FLAW3D are mapped at the same second order in different substrates, showing the taxonomy holds across software and physical manufacturing pipelines. The classification yields concrete defenses (hardware-rooted driver attestation, diverse independent toolchains across validation hosts, air-gapped reference baselines) that follow from the framework rather than the incident report.Companion to Bilar (2026), "Volt Typhoon as Operational Realization of the nth-Order Bleeding Thesis" (Zenodo 19739954).

Read the paper · More papers on PaperTik