Security flaw exposes 30 years of DNA evidence to tampering in major US crime labs

Image for Security flaw exposes 30 years of DNA evidence to tampering in major US crime labs

A DNA match can send someone to prison for life.

Now imagine that match could be quietly rewritten — no alarms, no trace, no way to prove it happened.

That's exactly what a team of forensic and computer scientists just showed is possible with the software running inside most of America's crime labs.

They didn't need elite hacking skills.

They used a chatbot.


🧬 The gold standard has a crack in it

For 30 years — since 1995 — crime labs across the US have used equipment from Thermo Fisher Scientific to turn physical DNA swabs into digital analysis files.

Those files are treated as courtroom gospel.

The gold standard of forensic science.

But researchers found something unsettling: the files carry almost none of the tamper-proofing you'd expect.

As University of New Haven forensic scientist Laura Gaydosh Combs put it — these records lack "the same level of tamper-evident markings that we require for a paper bag."

Let that sink in.

A paper bag is better protected than 30 years of DNA evidence.


🤖 45 minutes, one chatbot, one rewritten file

Here's the part that should worry you.

Nathan Adams, a systems engineer at Forensic Bioinformatics, decided to test the theory himself earlier this year.

He used Anthropic's Claude to help write the code.

👉 Time to successfully alter a DNA file: 45 minutes

👉 Decryption key needed to crack the more protected files: found sitting publicly on the internet for years

👉 Result: he merged two separate DNA profiles into one file that looked completely untouched since 2015

The lab software used to check for tampering?

It raised zero red flags.

Zero.


⚖️ Why this isn't just a tech story

This isn't a hypothetical about servers and code.

It's about real trials, real verdicts, real people.

In theory, someone with server access and enough know-how could:

  • 🕵️ Insert a suspect's DNA profile into crime-scene evidence that was never actually there
  • 🚫 Delete a profile to make it look like someone wasn't at the scene
  • 🔓 Do all of it while leaving files looking exactly as they did the day they were created

The researchers stress there's no known case of this actually happening.

But "no evidence of exploitation" and "undetectable if it did" are two very different kinds of reassurance.


🚨 The company's response

The researchers quietly flagged the flaw to Thermo Fisher back in May.

The company privately acknowledged it in July.

It only went public with a formal, high-severity security bulletin after The Wall Street Journal started asking questions.

The fix: a software update adding digital signatures, so labs can finally verify a file hasn't been secretly altered — going forward.

The 30 years of files already sitting in evidence lockers, though, remain exactly as vulnerable as they always were.

Thermo Fisher says it's been coordinating with the U.S. Cybersecurity and Infrastructure Security Agency since the flaw surfaced.


🗂️ Not the first crack in the system

This lands right after a Colorado state forensic analyst pleaded guilty in June to four felonies for manipulating DNA evidence and other misconduct spanning 2008 to 2023.

That was a human insider abusing trust.

This is a software gap that anyone with server access and an AI assistant could theoretically exploit.

Two very different failure modes.

Same shaky foundation.


🧩 Nobody's actually watching the whole system

Here's the uncomfortable structural truth underneath all of this.

There are more than 200 labs across the US handling everything from murder cases to paternity tests.

And there is no single national regulator enforcing consistent digital security across all of them.

Sarah Chu of the Perlmutter Center for Legal Justice didn't mince words about it: "Lessons learned from other industries haven't been imported into forensic science in a serious way. We've been behind the ball for so long."

Every other industry that got hacked — banking, healthcare, elections — eventually built tamper-proofing into its core systems.

Forensic DNA, the thing juries treat as unimpeachable truth, apparently didn't get the memo.


⚡ The real twist

AI didn't create this vulnerability.

It just made exploiting it trivially easy for anyone curious enough to try.

The flaw was baked into crime-lab systems since 1995 — decades before anyone worried about chatbots writing exploit code.

What's changed isn't the lock.

It's how many people now have the tools to pick it in under an hour.

That's all for now!