The stories buried, spiked, or spun.
Government Secrets

The Secret Life of Circuits with lcamtuf / Michał Zalewski (Audio Interview)

Share
The Secret Life of Circuits with lcamtuf / Michał Zalewski (Audio Interview)

What they're not telling you: The Infrastructure Nobody's Watching: Inside the World of Circuit Design Security The people who secure the hardware that runs the financial system, power grid, and military command structure are working in near-total darkness—and nobody in Congress or the SEC appears to care who's paying attention to them. That's the through-line in a recent technical interview with Michał Zalewski, the principal security engineer at Google who spent years reverse-engineering circuit design workflows. What emerges from his work is a structural blindspot: while regulators obsess over cryptocurrency wallets and equity derivatives, the foundational silicon layer—the actual circuits that execute every financial transaction, route every dollar—operates without meaningful security auditing, mandatory disclosure requirements, or institutional oversight.

What the Documents Show

Here's what matters about Zalewski's beat: he's spent his career mapping how circuits get built, modified, and inserted into production systems. His research has documented instances where supply chains can be compromised at the design phase, long before a chip reaches a bank's server farm or a brokerage's trading terminal. The attacks he's documented aren't theoretical. They're documented in papers, in CVE databases, in vendor advisories that circulate among maybe two hundred people worldwide. The regulatory absence is the story.

🔎 Mainstream angle
The corporate press either ignored this story entirely or buried it in a 3-sentence brief. The framing, when it appeared at all, focused on process rather than impact.

Follow the Money

The Federal Reserve doesn't require banks to audit their hardware supply chains. The SEC doesn't mandate circuit-level security disclosures. The Department of Defense has a few classified programs, but there's no public regime, no standardized verification process, no named regulator whose job is to verify that JPMorgan Chase's trading infrastructure hasn't been compromised at the silicon level. Compare this to the apparatus around cryptocurrency. The SEC has brought enforcement actions against individual wallet holders. Gary Gensler's office has issued guidance on DeFi tokens.

What Else We Know

State banking regulators have created specialized crypto divisions. The resource allocation is inverted: we have armies of examiners watching $300 billion in speculative digital assets, but exactly zero permanent federal staff whose full-time responsibility is auditing the hardware that moves $800 trillion annually in cleared derivatives trades. Zalewski's work reveals why this matters structurally. A single compromised circuit—inserted into a single server by a sophisticated supply-chain actor—could theoretically alter execution of transactions without leaving logs. Not stealing money visibly. Not causing system crashes that trigger audits.

Diana Reeves
The Diana Reeves Take
Corporate Watchdog & Money & Markets

What I find striking is the regulatory silence, not the technical problem. Zalewski's research is public. The vulnerabilities are documented. The solution path—mandatory hardware supply-chain audits, third-party circuit verification, disclosure requirements—is professionally understood.

The pattern here is institutional capture through invisibility. When you regulate cryptocurrencies visibly, you can point to enforcement actions, to seized assets, to named defendants. When you fail to regulate circuits, nothing breaks loudly. The system keeps working. No press releases. The lobby that benefits from this invisible gap—the chip foundries, the defense contractors, the foreign state actors who maintain supply-chain access—gets to operate without scrutiny.

Here's what readers should demand: mandatory circuit-level supply-chain auditing for all systems handling more than $100 million in daily transaction volume. A named Federal Reserve examiner responsible for hardware security. Public disclosure of audit results. That's not radical. That's baseline.

Watch whether the financial services lobby blocks this. The answer tells you everything.

Primary Sources

What are they not saying?
Who benefits from this story staying buried? Follow the regulatory filings, the court dockets, and the FOIA releases. The truth is in the paperwork — it always is.

Disclosure: NewsAnarchist aggregates from public records, API feeds (Federal Register, CourtListener, MuckRock, Hacker News), and independent media. AI-assisted synthesis. Always verify primary sources linked above.

Share
Part of our Government Secrets coverage
See the full picture on our Government Secrets hub — including our ongoing coverage of declassification, whistleblowers, and government transparency.
How We Report Government Secrets

This article is produced by NewsAnarchist's AI reporting system, not a human staff reporter. It's built from the primary source cited above (a declassified document, a FOIA release, an inspector general or congressional report, or a named whistleblower disclosure reported by outlets we cite) and reports what that source states, attributed to it — it reports what the document or disclosure states and does not speculate about what remains classified beyond that. Part of our Government Secrets hub. Found an error? Tell us.