What TSME Is and How Ryzen 9000 Lost It
Transparent Secure Memory Encryption (TSME) is an AMD hardware feature that automatically encrypts all data stored in system RAM, reducing the impact of cold-boot attacks and other physical attacks that try to read sensitive information directly from memory modules while a machine is powered on or recently powered off. TSME debuted on high-end AMD processors and later appeared on mainstream Ryzen, Ryzen Pro, Threadripper, and EPYC parts, where it offered additional physical attack protection with minimal user effort. The trouble started in April when Linux hobbyist Ben Kilpatrick installed a new OS on a Ryzen 7 9700X and found Host Security ID now reporting “encrypted RAM: not supported,” despite TSME being enabled in the BIOS. Comparing logs showed that the same system had previously reported memory as encrypted, pointing to a change introduced by newer firmware rather than a hardware limitation in the Ryzen 9000 security design.

The Silent RAM Encryption Removal and Pro-Only Lock-In
Kilpatrick’s investigation, backed by MSI testing, traced the RAM encryption removal to AGESA 1.2.7.0, AMD’s firmware base: older AGESA builds reported TSME as supported on consumer Ryzen, while the new one flipped it to “not supported.” Ryzen Pro chips, however, kept reporting TSME availability across boards and firmware versions, signaling that the silicon remained capable. Further analysis of AMD Boot Loader dumps showed an internal flag, DfIsTsmeEnabled, set to FALSE on non-Pro Ryzen even when BIOS options said AUTO or ENABLED, but TRUE on Pro parts. MSI told Kilpatrick that AMD had “officially communicated” TSME was now exclusive to Pro series processors. In practical terms, that meant physical attack protection from TSME memory encryption was quietly downgraded for regular Ryzen owners, even though they had previously benefited from the same hardware security feature on their systems.

Security Impact: Cold-Boot Attacks and Lost Trust
AMD framed the removal as not a major vulnerability because attackers still need physical access to exploit RAM contents, but for privacy-conscious users the stakes are clear. TSME defends against cold-boot attacks, where an attacker reboots or quickly powers off a system to dump lingering data from DIMMs, and against direct memory extraction in hands-on scenarios. Losing this layer of Ryzen 9000 security without warning undermines expectations that firmware updates improve safety rather than strip protections. Even if most desktop users never toggle Memory Guard, the principle matters: quietly turning off TSME memory encryption on capable CPUs weakens default defenses for those who rely on full-disk encryption, secure virtualization, or shared machines. The episode shows how opaque hardware security decisions can damage trust, especially when vendor communication lags behind what enthusiasts and researchers discover on their own.

Community Backlash and AMD’s BIOS Update Reversal
For weeks, AMD provided little clarity. Engineers replying to Kilpatrick’s public GitHub bug report suggested BIOS toggles or contacting the board vendor, and did not acknowledge a deliberate policy change. As testing evidence mounted and coverage spread, criticism shifted from the technical choice to the lack of transparency: users were frustrated that a meaningful security feature could vanish through an AMD BIOS update without any public note. The backlash worked. Speaking to Tom’s Hardware and PCMag, AMD confirmed a BIOS option to enable Memory Guard on certain non-Pro Ryzen 9000 processors “was previously available but was removed in a recent update” and said that “based on valuable community feedback, we will reinstate this option in an upcoming BIOS release in July.” Restoring TSME satisfies immediate concerns, but it also highlights how visible community pressure can still influence platform-level security decisions.

What This Means for Future Hardware Security Features
AMD now calls TSME “a foundational security feature” for Ryzen Pro, promising no plans to remove it there, yet its brief disappearance on consumer Ryzen shows how fluid feature boundaries can be. For security-conscious buyers, the episode is a warning: protections like TSME may depend as much on policy and firmware as on silicon capabilities. It also underlines why transparent changelogs for AGESA and board firmware matter—few users expect a routine update to disable physical attack protection. Going forward, AMD and its rivals will face pressure to document any security-relevant changes, avoid silent downgrades, and separate marketing segmentation from baseline safeguards. For now, Ryzen 9000 owners should watch for the July BIOS releases that bring back TSME memory encryption and verify, with tools like Host Security ID, that the restored setting behaves as advertised on their systems.








