AMD silently removes memory encryption from consumer Ryzen CPUs, leaving users unaware that they may be vulnerable — security feature vanishes after newer AGESA firmware, AMD engineers go radio silent when pressed about the change
AMD quietly disabled Transparent Secure Memory Encryption (TSME) on consumer Ryzen CPUs through AGESA 1.2.7.0 firmware updates. AMD engineers went silent when pressed for answers.
AMD Silently Strips TSME Memory Encryption from Consumer Ryzen via Firmware Update — No Warning, No Explanation
Ben Kilpatrick discovered that a critical hardware security feature had vanished after updating to AGESA 1.2.7.0. Months of investigation later, AMD engineers stopped responding and the company still has not issued a statement.
What Happened to TSME?
AMD has silently disabled Transparent Secure Memory Encryption (TSME) on its consumer Ryzen processors through an AGESA firmware update, removing a hardware-level defense against physical memory attacks without informing users. Unlike standard Secure Memory Encryption (SME), which requires OS-level support and selective page encryption, TSME operates entirely at the firmware level — automatically encrypting all data between the CPU's memory controller and RAM modules. This protects against cold-boot attacks, DRAM bus snooping, and physical memory extraction without any software configuration.
The discovery was first made by Linux hobbyist Ben Kilpatrick, who noticed the feature was flagged as unsupported on his Ryzen 7 9700X (Zen 5) system despite being enabled in BIOS. His findings were later independently verified by motherboard manufacturer MSI, which confirmed that consumer Ryzen chips reported TSME as "not supported" under AGESA 1.2.7.0 while Ryzen Pro and EPYC processors continued to support the feature normally.
AMD Engineers Respond, Then Go Silent
Kilpatrick filed a bug report on AMD's public engineering GitHub repository, where two AMD engineers — Tom Lendacky (fellow software engineer) and Mario Limonciello (senior principal software engineer) — initially responded. Neither could explain why TSME had disappeared. Their advice was limited to disabling and re-enabling the BIOS option, effectively acknowledging they were as in the dark as the user.
After Kilpatrick pressed MSI for controlled lab testing — which revealed an internal AGESA flag returning FALSE for consumer chips and TRUE for Pro processors — he brought the evidence back to AMD's engineers. The response was definitive but unsatisfying: Limonciello wrote, "My apologies, but I don't have any more information to share on this topic." AMD has not released any official statement.
Invisible Removal — Users Left in the Dark
The most troubling aspect is that TSME's disappearance is completely undetectable on Windows and requires significant technical expertise to identify on Linux. Users who updated their motherboard firmware received no warning, changelog entry, or notification. AMD's only documented response is an email stating that TSME "is a security feature only applied to PRO CPUs as part of AMD PRO Technologies" — the first time AMD has publicly articulated such a restriction, despite the feature having worked on consumer hardware for years.
For most users, the practical impact is limited: TSME guards against physical attacks (theft, seizure, memory tampering) rather than software-based threats like malware. However, for journalists covering sensitive topics, legal professionals, and anyone relying on full-disk encryption in portable devices, the loss is significant. The only way to regain hardware memory encryption on AMD is now to upgrade to a Ryzen Pro or EPYC processor.
Intentional Segmentation or Accidental Regression?
The central question remains unanswered: was the TSME removal an intentional product-segmentation decision or an accidental firmware regression? The silicon is clearly capable — the feature worked on consumer chips for years, and Lendacky himself confirmed in 2020 that a consumer Ryzen 3700X "should support TSME."
If this is intentional, it represents a quiet, unannounced downgrade executed with zero transparency. If accidental, AMD's failure to correct it raises serious concerns about firmware quality assurance. Neither scenario reflects well on AMD's stewardship of hardware security, and the radio silence from its engineers has done little to restore confidence.
This article was updated following the Ars Technica investigation published June 17, 2026.



