Evidence: well sourced. Imported from the supplied 65-Case Master Edition, dated September 19, 2026. Source links and classifications are retained as an attributed case account; import is not an independent source review.
Case at a glance
- Case number
- 047
- Date / range
- 2017
- Sector
- Genomic cybersecurity and infrastructure
- Genetic asset
- Engineered DNA input and modified analysis software
- Security principle
- Cross-Domain Input Validation
Event summary
University of Washington researchers demonstrated a deliberately engineered proof of concept in which synthetic DNA, after sequencing, produced data that exploited intentionally modified analysis software. The case is a warning about untrusted biological inputs—not evidence of a common real-world attack.
Source: usenix.org — DNA-Encoded Malware Proof Of Concept source 1.
Source: dnasec.cs.washington.edu — DNA-Encoded Malware Proof Of Concept source 2.
The case in context
The DNA-encoded malware demonstration deliberately connected a biological input to vulnerable analysis software under engineered conditions. The proof of concept is informative precisely because those conditions are explicit. It does not establish that ordinary specimens naturally contain executable malware or that production laboratories were compromised.
The general software lesson is about trust at an input boundary. Data produced from a specimen should still be handled as input by downstream tools. Sandboxing, validation, and least privilege reduce the consequences of processing an unexpected file without requiring an operational account of how to reproduce the demonstration.
Acquisition and processing
crafted synthetic DNA → sequencer → base-call file → vulnerable parser → code execution in demonstration environment
The sequence of events
- crafted synthetic DNA
- sequencer
- base-call file
- vulnerable parser
- code execution in demonstration environment
What became inferable or exposed
Engineered DNA input and modified analysis software
University of Washington researchers demonstrated a deliberately engineered proof of concept in which synthetic DNA, after sequencing, produced data that exploited intentionally modified analysis software. The case is a warning about untrusted biological inputs—not evidence of a common real-world attack.
Affected parties and consent
- Direct parties
- Researchers' demonstration environment; no victims asserted
- Indirect parties
- Connected institutions, communities, or resource users; no affected-person total is assigned.
- Direct count
- Unknown / not assigned
- Indirect count
- Unknown / not assigned
- Consent status
- Legitimate instrument access does not authorize compromise. Vulnerability notices and research demonstrations are not evidence of consent violations against a known victim group.
Security dimensions
Confidentiality
The confidentiality question concerns engineered dna input and modified analysis software. Exposure and further inference must be distinguished from the fact of collection or availability.
Integrity
The integrity question is whether the described material, permissions, processing, or interpretation can be relied upon. Cross-Domain Input Validation identifies the particular boundary examined here.
Availability
Access and continuity are assessed for the described event; potential effects are not presented as confirmed outages or losses.
Provenance
The relevant chain follows engineered dna input and modified analysis software through the stages shown below. Missing public detail is not proof that internal records did not exist.
Consent, persistence, and relational exposure
Consent
Legitimate instrument access does not authorize compromise. Vulnerability notices and research demonstrations are not evidence of consent violations against a known victim group.
Persistence
Later reuse depends on the actual asset and links to other records; no future misuse is asserted.
Relational exposure
Connected institutions, communities, or resource users; no affected-person total is assigned.
Case-specific assessment
integrity and availability critical; confidentiality possible; provenance high; real-world likelihood in the demonstration low.
GeneticSecurity.org analysis
Genetic Exposure Radius
No single level is assigned where the supplied dossier gives a range, conditional outcome, or broad institutional consequence. The affected parties and proposed assessment are shown separately.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Genetic Persistence Risk
Persistence depends on the specific biological material or information retained. A potential effect is not treated as an observed genomic disclosure.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Genetic Provenance Integrity
A numeric provenance level is not inferred from the existence of a source or court record. It requires evidence of the relevant custody and processing controls.
Confidence: not assigned. Classification: GeneticSecurity.org analysis.
Proposed classification and its limits
Suggested GER: workload-dependent. Suggested GPR: not central unless data is exfiltrated. Suggested GPI: GPI-0 after pipeline compromise.
These are proposed classifications from the supplied case dossier. Conditional scores describe an assumed exposure; they are not evidence that it occurred. A single numeric value is left unassigned when the asset or outcome is not sufficiently bounded.
What this case does not prove
It did not show that ordinary DNA naturally carries executable malware or that production sequencers were broadly compromised.
Mitigations and lessons
- Memory-safe parsers
- Sandboxing
- Least privilege
- Fuzzing
- Signed pipelines
- File-size/input validation
- Isolation of sequencing networks
- Treating submitted samples as untrusted
Primary sources
Secondary sources
No additional source listed. See the evidence notes for limitations.
Policy and standards
Genetic Security Policy and StandardsReview and correction history
Source edition: September 19, 2026. Imported case account; no substantive corrections recorded.
Correction policy and logCite this case
GS-CASE-047. DNA-Encoded Malware: When a Biological Sample Became an Input Attack. GeneticSecurity.org. https://geneticsecurity.org/cases/047-dna-encoded-malware-sequencing-pipeline/