https://eclypsium.com/blog/xray-counterfeit-usb-cable/ * * Platform + o Platform Overview o Protect critical software, firmware, and hardware in enterprise and national infrastructure. o Learn More + o Eclypsium Protects: # User Endpoints # Servers # Network Devices # AI Hardware + o Featured post [Eclypsium-Take-A-Tour] Take an interactive tour of the Eclypsium platform. Take a Tour * Solutions + o Solutions Overview o Build trust in every critical asset in your enterprise. o Read More + o By Business Need # Device Lifecycle Security # Firmware Security # Hardware Supply Chain Security # Regulatory Compliance + o - # Continuous Threat Exposure Management (CTEM) # Ransomware Defense # Zero Trust for Endpoints + o By Industry # Energy and Utilities # Financial Services # Government # Telecommunications + o Featured Post [Eclypsium-Take-A-Tour] Take an interactive tour of the Eclypsium platform. Take a Tour * Resources + o All Resources o Learn More + o Case Studies o Demos & Videos o Events & Webinars o Podcasts o Solution Briefs o Reports and eBooks o White Papers + o Blog o Newsletter o Support + o Latest Blogs Blog We X-Rayed A Suspicious FTDI USB Cable Learn more Blog Infographic: A History of Network Device Threats and What Lies Ahead Learn more * Research * Company + o Company Overview o We exist to defend the foundation of enterprise and national infrastructure. o Learn More + o Team o Newsroom o Careers o Partners o Security and Trust o Contact * US * JP * Get a demo * Take a Tour [ ] Search * US * JP * Get a demo * Take a Tour * Platform + o Platform Overview o Protect critical software, firmware, and hardware in enterprise and national infrastructure. o Learn More + o Eclypsium Protects: # User Endpoints # Servers # Network Devices # AI Hardware + o Featured post [Eclypsium-Take-A-Tour] Take an interactive tour of the Eclypsium platform. Take a Tour * Solutions + o Solutions Overview o Build trust in every critical asset in your enterprise. o Read More + o By Business Need # Device Lifecycle Security # Firmware Security # Hardware Supply Chain Security # Regulatory Compliance + o - # Continuous Threat Exposure Management (CTEM) # Ransomware Defense # Zero Trust for Endpoints + o By Industry # Energy and Utilities # Financial Services # Government # Telecommunications + o Featured Post [Eclypsium-Take-A-Tour] Take an interactive tour of the Eclypsium platform. Take a Tour * Resources + o All Resources o Learn More + o Case Studies o Demos & Videos o Events & Webinars o Podcasts o Solution Briefs o Reports and eBooks o White Papers + o Blog o Newsletter o Support + o Latest Blogs Blog We X-Rayed A Suspicious FTDI USB Cable Learn more Blog Infographic: A History of Network Device Threats and What Lies Ahead Learn more * Research * Company + o Company Overview o We exist to defend the foundation of enterprise and national infrastructure. o Learn More + o Team o Newsroom o Careers o Partners o Security and Trust o Contact Blog We X-Rayed A Suspicious FTDI USB Cable By: Eclypsium Research Team January 22, 2026 [feature_image_xray] We recently got an industrial X-Ray machine in the Eclypsium office to use to [S:make the next Doctor Manhattan:S] do serious cybersecurity research. In between X-raying yet-to-be released industrial IT technologies on behalf of giant companies whose names we cannot reveal, we have done some other fun experiments. Eclypsium researcher preparing to x-ray a suspicious USB cable. One thing we've done with it so far was to x-ray some FTDI USB to UART cables. We had an old cable lying around that seemed a little suspicious and dysfunctional. It worked at slow speeds but it failed when transferring firmware images from a product. These failures drove us to purchase the known good cables from DigiKey, which worked as expected. It is possible that this older cable came from a factory which also produced older generations of authentic FTDI cables, but this particular chip didn't meet the performance requirements for the FTDI brand. Or maybe it was just a production run based on stolen FTDI IP. Or it is actually completely unrelated to any FTDI IC but has been programmed to claim to be FTDI in software. Unless we could match the silicon exactly to a known supply chain, we can really only speculate. In either case, we wanted to see the difference between the suspicious cable and a newer, more obviously "legit" one that cost about $20 from DigiKey. It is not a stretch to assume that a suspicious looking cable is a counterfeit. FTDI has publicly announced issues with counterfeit devices. They have even fought back with drivers which brick counterfeit chips. Some people have even referred to this as vendor sanctioned malware. Here's what the two cables look like to the naked eye: [svg][xray-machine-2] Take a look at the two x-ray images below and see if you can tell which one is suspicious, and which one is authentic. Then scroll down and we'll tell you what we see. Xray of an authentic USB cable.Xray of an authentic USB cable. [svg] [usb-cable-xray-2] Before we tell you the answer, here are some clues to look out for in each picture. The authentic cable has the following features visible in the X-Ray image, not shared with the suspicious cable: 1. Ground pours (reduces impedance and ground loops while improving EMI resistance and thermal dissipation). While there is some debate about the actual value of copper ground pours, they are still used by reputable manufacturers. 2. Ground stapling 3. Decoupling passives nearer to the main integrated circuit (IC) 4. More isolation passives for USB data pins 5. Thermal pad under IC 6. Engineered strain relief for wire connections 7. More solder for mechanical tabs on USB A connector 8. Smaller/newer silicon process 9. Better passive alignment The Big Reveal, and the Implications for Supply Chain Security OK, the top image above is the authentic cable. The bottom image is the more questionable one. Did you get it right? If not, go back and see if you can pinpoint the various clues. The point is that, even when you know what to look for, spotting a counterfeit isn't necessarily easy. The consequences for a consumer buying a shady USB cable likely aren't too bad. But what happens when an enterprise gets counterfeit network gear with a backdoor pre-installed? Or when a major bank receives grey market servers with another company's data on them? Eclypsium has helped major worldwide organizations discover exactly these types of supply chain issues. Supply chain risk is growing rapidly. As AI data center projects capture more and more of the global supply for chips, memory, storage, and other key resources, the secondary market for all of these is heating up. The speed and complexity of these supply chains leaves gaps that cyber adversaries can exploit to introduce vulnerable components and backdoors into tech that makes its way into critical infrastructure. To learn more, grab our white paper on Why Supply Chain Security Demands Focus on Hardware Back to Blog Related Blogs View all [svg][feature_image_nettimeline] Blog Infographic: A History of Network Device Threats and What Lies Ahead Read more [svg][feature_image_fortinetunderfire2] Blog Fortinet Under Fire: Why Your Network Edge Remains Attackers' Favorite Entry Point Read more [svg][network-exploits-roundup-2025] Blog 2025: The Year of Network Device Exploitation Adds Three More Read more [svg][feature_image_hhg] Blog The Hitch-hacker's Guide to the Galaxy's Edge: 2025 in Cyber Stats Read more Eclypsium | Supply Chain Security for the Modern EnterpriseEclypsium | Supply Chain Security for the Modern Enterprise Get a Demo Contact Us Platform * Title + Supply Chain Security + Supply Chain Intelligence Research Solutions * Title + Digital Supply Chain Security + Firmware Protection for Enterprises + Compliance + Zero Trust for Endpoints Resources * Title + Blog + Events + Podcasts + White Papers + Support * Title + Solution Briefs + Threat Reports + Newsletter Company * Title + Team + Newsroom + Careers + Partners + Security + Contact * Linkedin * Youtube * Twitter * Facebook (c) 2025 Eclypsium, Inc. Privacy Policy | Terms of Use | Sitemap websights