abstract:A supply chain attack is a cryptographic attack where a product, typically a device that performs encryption or secure transactions, is tampered with during manufacture or while it is still in the supply chain by persons with physical access. The tampering may, for example, install a rootkit or hardware-based spying components.