Nvidia Manager Unlocked B300 Server Diversion to China, Taiwan Indictment Says
Nvidia Taiwan manager certified fake inspection; B300 servers flowed to China

Taiwan's Keelung District Prosecutors' Office indicted nine people on August 24 over the alleged illegal export of 130 advanced AI servers to mainland China — and, for the first time in this enforcement story, prosecutors named an Nvidia distribution manager, not a downstream assembler or broker, as the "key figure" who opened the gate. The indictment does not merely add defendants to a running tally of enforcement actions — it demonstrates that export controls on the world's most restricted AI hardware can be defeated from inside the office of the chip designer itself.
The defendants include a distribution manager at Nvidia's Taiwan office identified by the surname Chang, two sales managers at the Taiwan branch of Super Micro Computer identified as Lin and Wang, and the chief executive of Albatron Technology, a Super Micro distributor, identified as Lu. Prosecutors are seeking the maximum five-year prison sentence for four of the nine defendants, including Chang — whom they say showed a clearly poor attitude following the offense.
Neither Nvidia nor Super Micro was named as a corporate defendant. Nvidia spokesperson Patrick Rutherford said in a written statement that the company will cooperate with Taiwan's investigation to help resolve the allegations as quickly as possible. Super Micro said the arrests of its former employees resulted from its cooperation with Taiwanese authorities and that it will enhance its robust export compliance program to protect American innovation.
All persons named in this article are charged and have not been convicted of any offense.
How a Five-Point Inside Scheme Defeated Nvidia and Super Micro's Compliance Program
The Keelung indictment describes what Tom's Hardware, citing the prosecutors' statement, characterized as a compliance regime defeated from inside. Understanding why the scheme succeeded requires understanding how the compliance system was designed to fail-safe — and at exactly which point it did not.
Under joint Nvidia and Super Micro policy, buyers of high-end B300 servers must hold an approved position on Nvidia's distribution whitelist, submit end-user and end-use documentation, and accept a strict no-resale condition. Any purchase order above eight units triggers on-site inspections by staff from both companies, designed to confirm the declared buyer can actually house the hardware. The system depends entirely on the honesty of the employee at Nvidia who certifies that the site inspection was completed and satisfactory.
According to prosecutors, the alleged scheme began in February 2025, when two men at server trading company Flying Tiger Technology obtained whitelist status. Flying Tiger's purchase order was placed through Albatron — a listed Super Micro distributor — which, prosecutors allege, shielded Flying Tiger's origins from scrutiny because Albatron itself was an established, Taiwan-stock-listed firm. Flying Tiger then leased colocation space from Chief Telecom, a publicly listed data center operator, to serve as the declared end-user site.
When Nvidia and Super Micro staff conducted an on-site inspection in September 2025, they reportedly found the Chief Telecom facility operational — but lacking the racks, power capacity, and bandwidth necessary to run the 130 B300 servers that had been ordered. According to the indictment as reported by Tom's Hardware, no one raised that finding to compliance authorities. Instead, Chang — the Nvidia Taiwan distribution manager — allegedly emailed headquarters to certify inspection completion. A senior Super Micro sales manager allegedly coached Flying Tiger through the review process; a second Super Micro manager reportedly learned where the servers were actually heading but was cut into the commission structure rather than reporting the diversion.
Super Micro ultimately approved the sale in three batches — two units, then 64, then 64 — totaling 130 B300 servers. Of the first 74 units that moved: 16 were shipped directly to mainland China in January 2026; 50 were routed through Indonesia before final delivery to China; and 8 traveled through a shell company incorporated in Japan, then transited Hong Kong before reaching Chinese buyers. The proceeds from those 74 completed shipments totaled approximately $21.2 million, according to prosecutors.
The scheme collapsed when the remaining 56 servers were declared for export to Japan and flagged by customs authorities, who demanded a strategic high-tech commodities export permit. Prosecutors allege the defendants then filed using fake Supermicro website mockups — spliced together from real pages — to create fraudulent documentation. By that point, word of the scheme had reached authorities, and the 56 servers were seized before they could leave Taiwan.
A parallel financial concealment case found the head of Quintai Electronics allegedly issuing four false invoices to obscure the money trail, billing Albatron Technology approximately NT$39.16 million (approximately $1,228,000 USD) for installation work that was never performed. Prosecutors say the proceeds were divided among participants.
What Nvidia's Manager Is Accused of — and Why It Changes the Frame
Every prior prosecution in this enforcement story placed Nvidia in a particular role: the company whose technology was being diverted against its compliance procedures, with alleged perpetrators operating in the downstream distribution chain. Liaw, the Super Micro co-founder charged in the $2.5 billion U.S. case, is accused of orchestrating diversions through a Southeast Asian front company — not through anyone inside Nvidia's own organization.
The Keelung indictment changes that. Chang is the first named Nvidia employee alleged to have actively enabled a B300 server diversion — not by failing to catch a scheme, but by allegedly certifying a fraudulent inspection as complete and emailing that certification to Nvidia headquarters. In the compliance architecture Nvidia and Super Micro jointly maintain, that certification is the gate. It is the step that converts a pending order into an approved sale. By allegedly providing a false certification, Chang did not circumvent the system — he was, per the indictment, the system, making a decision only he had the authority to make.
Prosecutors described Chang's post-arrest posture as showing a clearly poor attitude — language that suggests an absence of cooperation and is cited in Keelung prosecutors' charging statement and is being used by the Keelung office to justify seeking the maximum available sentence.
Why B300 Chips Are Restricted — and Worth Twice Their List Price on Gray Markets
The B300 GPU is the central hardware at issue. It belongs to Nvidia's Blackwell Ultra generation — the most capable AI accelerator architecture Nvidia currently produces — and is classified under ECCN 3A090.a by the U.S. Bureau of Industry and Security. That classification places B300 chips under a presumption of export license denial for China — meaning applications to sell them to Chinese buyers are effectively blocked under current policy, unlike the H200, which was shifted to a case-by-case review standard in January 2026.
The reason for the restriction is the chip's dual-use nature: the same computational architecture that accelerates commercial AI model training has documented applications in weapons simulation, autonomous systems development, nuclear research modeling, and large-scale military intelligence analysis. The B300 is not a gaming GPU that can train AI workloads as a secondary use — it is purpose-built for the kind of large-scale parallel computation that training frontier AI models requires, and those workloads are indistinguishable from each other at the hardware level.
The financial incentive driving the alleged scheme is equally specific. An authorized Nvidia GPU that retails through legitimate channels at roughly $25,000 to $30,000 commands $40,000 to $60,000 or more on gray markets accessible to Chinese buyers, according to CSIS analyst Gregory Allen, who has noted that profit margins on smuggled chips rival those in narcotics trafficking. Those margins — not ideology, not state direction — are the economic engine of the smuggling networks prosecutors have been dismantling since late 2025.
Parallel U.S. Case: Trial Scheduled for November
Taiwan's indictment arrives five months after the U.S. Department of Justice unsealed its own prosecution with a structurally similar architecture. On March 19, 2026, federal prosecutors charged Super Micro co-founder Yih-Shyan Liaw with conspiring to divert servers containing controlled GPUs to China without a Commerce Department export license. The U.S. case alleges approximately $2.5 billion in server purchases by a Southeast Asian pass-through entity between 2024 and 2025, with at least $510 million in hardware diverted to China over a single three-week period.
The concealment methods alleged in the two cases share a basic grammar: falsified verification documents, inspections deliberately passed by insiders who knew the declared end-user was fictitious, and multi-country logistics chains designed to break the paperwork trail before hardware reached its final Chinese destination. In the U.S. case, prosecutors allege that thousands of non-functional dummy servers were staged for compliance auditors, with labels and serial-number stickers transferred from real units using heat — some of the process allegedly captured on surveillance cameras.
Liaw has pleaded not guilty and faces up to 20 years on the lead conspiracy count. His U.S. trial is scheduled to begin November 2, 2026. His co-defendant Ruei-Tsang "Steven" Chang remains a fugitive.
Super Micro is not a named defendant in either the Taiwan investigation or the U.S. federal proceedings.
Why Paper-Based Compliance Cannot Solve What Insider Certification Breaks
The Keelung indictment is, in one sense, a confirmation of a structural problem that security researchers and policymakers have been describing for years: the U.S. export control system for AI hardware is fundamentally a paper system, and paper systems are only as honest as the people who fill them out.
The Bloomsbury Intelligence and Security Institute documented in April 2026 that export controls are being systematically circumvented and that the cases represent a broader trend. The Center for New American Security estimates that between 10,000 and several hundred thousand export-controlled GPUs were smuggled into China in 2024 alone, with a median estimate of approximately 140,000 — a quantity researchers calculate could represent roughly 10 percent of China's AI model training compute capacity. SemiAnalysis analyst Ray Wang has estimated that more than 60 percent of leading AI models running in China use Nvidia's hardware — a figure underscoring why demand for restricted chips has not diminished despite years of enforcement.
The insider compliance failure documented in the Keelung case cannot be addressed by more thorough end-user certificates, more frequent site visits, or stricter distributor vetting — because those controls all terminate at the same point: the employee who certifies whether the verification was genuinely completed. This is the structural vulnerability the Chip Security Act — approved by House Foreign Affairs on March 26, 2026 — is designed to address. Rather than relying on end-user certificates, shipping declarations, and compliance audits — all of which this indictment shows can be falsified or circumvented from the inside — the legislation would embed tracking technology directly into covered chips, creating a hardware-level location verification mechanism that functions independently of whether any certifying employee is honest.
Taiwan's own domestic enforcement gap compounds the problem. Because Taiwan has no domestic statute that directly criminalizes the export of AI chips to China, every defendant in this investigation faces charges of document forgery and breach of trust — offenses related to the fraudulent paperwork that accompanied the shipments — rather than charges for the underlying diversion itself. A proposed amendment to Taiwan's Foreign Trade Act would close that gap by adding a mainland China semiconductor chip clause, but the legislation had not passed as of this reporting.
The global enforcement record underlines how much pressure is accumulating: in December 2025, Alan Hao Hsu of Hao Global pleaded guilty in the first-ever U.S. conviction for AI chip smuggling, involving approximately $160 million in H100 and H200 GPUs. Singapore prosecutors charged three individuals in a case involving an estimated $390 million in alleged fraud against Dell and Super Micro. Finnish customs seized 48 Nvidia H100 accelerators at Helsinki airport in March 2026. The Trump administration has requested $450 million and approximately 1,077 positions for export control enforcement in fiscal 2027 — nearly doubling the Bureau of Industry and Security's current budget.
None of those enforcement actions addressed the specific vulnerability that the Keelung indictment lays bare: a compliance officer inside the chip designer's own distribution network who can authorize a fraudulent transaction with a single internal email, and whose honesty is the only safeguard standing between a restricted sale and a completed one.
Frequently Asked Questions
How did the alleged scheme defeat Nvidia and Super Micro's internal compliance checks?
The indictment describes what Tom's Hardware characterized as a compliance regime designed to track every unit that was defeated from the inside. Prosecutors allege that the Nvidia Taiwan distribution manager certified to Nvidia headquarters that an on-site inspection of the declared end-user's facility had been completed satisfactorily — when, according to the indictment, the facility lacked the power, racks, and network capacity to house the hardware ordered. Because the compliance system terminates at that certification step, the false email allegedly cleared the sale without triggering any independent verification. Two Super Micro employees allegedly compounded the failure by coaching the buyer through the review process and accepting a share of commission proceeds rather than reporting the apparent diversion.
What makes B300 GPUs so restricted — and what gray market value does that restriction create?
The Nvidia B300 is a Blackwell Ultra generation AI accelerator classified under ECCN 3A090.a by the Bureau of Industry and Security — the strictest export restriction category for advanced computing hardware. Unlike the H200, which was shifted to a case-by-case review standard for China in January 2026, Blackwell-class chips including the B300 remain under a presumption of license denial, meaning applications to sell them to Chinese buyers are effectively blocked. The restriction reflects the chip's dual-use nature: the same parallel computation architecture that accelerates commercial AI training has documented military applications. The restriction also creates the financial incentive driving the alleged scheme: B300 servers that sell for roughly $25,000–$30,000 through legitimate channels command $40,000–$60,000 or more on gray markets accessible to Chinese buyers, according to CSIS analysis — a premium large enough that enforcement officials have compared the profit margins to narcotics trafficking.
What is the Chip Security Act, and does the Keelung indictment support its passage?
The Chip Security Act, passed by House Foreign Affairs on March 26, 2026, would require AI chips exported from the United States to carry a hardware-level location verification mechanism — software, firmware, or embedded hardware — that continuously confirms the device's physical location. The Keelung indictment is a direct argument for the legislation, because it demonstrates the specific failure mode the Chip Security Act is designed to address: an insider at the certifying level of the compliance chain who can authorize a fraudulent transaction with no external check. A hardware-embedded location tracker that the chip itself reports — independently of any human certification — would, in theory, create exactly that external check. The legislation has not yet received a full House vote.
What happens to the Nvidia employee named in the indictment?
Chang — the Nvidia Taiwan distribution manager identified as the "key figure" in the Keelung indictment — was initially detained in July 2026 and has now been formally charged with breach of trust and document forgery. Prosecutors are seeking the maximum five-year prison sentence and cited his clearly poor attitude following the offense as a factor. Taiwan does not have a dedicated AI chip export offense statute, so Chang cannot be charged for the underlying diversion itself — only for the fraudulent paperwork used to accomplish it. His case will proceed through Taiwan's criminal courts. Whether the U.S. Department of Justice pursues any related charges against a Taiwan-based Nvidia employee has not been publicly announced. Details are confirmed in Taipei Times reporting and AP wire coverage.
Originally published on Tech Times
ⓒ {{Year}} TECHTIMES.com All rights reserved. Do not reproduce without permission.




















