Skip to main content
  1. Home
  2. Cars
  3. News

Researchers hack and steal a Model S; Tesla says vulnerability now fixed

Add as a preferred source on Google
COSIC researchers hack Tesla Model S key fob

Stealing a car used to require a blunt object to break one of its windows, and basic electrical knowledge to hot-wire it. Two Belgian security experts discovered an encryption flaw that let them drive away in a Tesla Model S without busting any glass or cutting any wires.

Recommended Videos

Researchers working at the KU Leuven University in Belgium figured out a relatively simple way to digitally break into a Model S by defeating the encryption in the wireless key fob, according to Wired. It’s a technique that requires about $600 worth of radio and computing equipment, so it’s not something anyone can do with their smartphone, but that’s a small investment considering the price of a Model S. The hardware is used to access the cryptographic key programmed into each fob and copy it, which essentially creates a new key fob. The thieves can thereupon enter any Model S and drive off in it without setting off the alarm.

“Today, it’s very easy for us to clone these key fobs in a matter of seconds. We can completely impersonate the key fob and drive the vehicle,” revealed researcher Lennert Wouters in an interview with Wired. He added figuring out how to hack into a Model S took about nine months.

Tesla awarded the researchers a $10,000 bug bounty when they privately shared their discovery in August of 2017. It then spent nearly a year verifying the technique and developing a fix, which it began rolling out in June of 2018. First, it designed a more secure key fob. That means cars manufactured after that point aren’t affected by the problem.

Earlier models — a vast majority of the ones on the road — received an additional security barrier via an over-the-air software update. This lets owners set a PIN code that must be entered on the car’s touchscreen before it can be driven off. It’s similar to the PIN that protects a smartphone. Tesla told Digital Trends the PIN function will come to the Model 3 in the future.

“Due to the growing number of methods that can be used to steal many kinds of cars with passive entry systems, not just Teslas, we’ve rolled out a number of security enhancements to help our customers decrease the likelihood of unauthorized use of their vehicles,” a Tesla spokesperson told Digital Trends. “Based on the research presented by this group, we worked with our supplier to make our key fobs more secure by introducing more robust cryptography for Model S in June 2018,” the California-based company added.

Wouters and his partner, Tomer Ashur, blame the flaw on a key fob manufactured by British electronics firm Pektron. McLaren, Karma, and Triumph also use Pektron-sourced key fobs so the same hack could allow thieves to break into vehicles made by those brands.

“This attack is out there, and we’re not the only people capable of coming up with it,” Ashur warned.

Update: added statement from Tesla.

Ronan Glon
Ronan Glon is an American automotive and tech journalist based in southern France. As a long-time contributor to Digital…
Volvo’s parent just launched a $16,000 EV that looks shockingly luxurious
This $15,600 Geely EV has no business looking this premium
Geely Galaxy Starshine 7 Promo Image

Geely, the Chinese auto giant that also owns Volvo, has just unveiled a new RV that really does not look like it belongs anywhere near the budget end of the market.

The company has just kicked off the presales in China for the Galaxy Starshine 7, with its pricing starting at 112,900 yuan or about $16,550. For that money, buyers get a midsize electric sedan with a sleek fastback silhouette, full-width lighting, a richly trimmed cabin, and even an available dual-motor all-wheel-drive setup that can hit 0 to 100 km/h in 5.4 seconds.

Read more
Xiaomi makes dirt-cheap gadgets, but its CEO just ruled out cheap EVs
Xiaomi is staying out of the bargain EV fight
Xiaomi SU7 EV in blue

Xiaomi has been known for building some surprisingly cheap gadgets that still feel a little more premium than they should. But that philosophy apparently does not extend to electric cars.

According to ITHome, Xiaomi CEO Lei Jun said during a livestream for the company's SU7 endurance challenge on April 17 that Xiaomi will not make vehicles priced below 100,000 Yuan. That works out to be just under $15,000. Lei explained that if consumers expect an electric car to deliver strong intelligent features, software, and overall capability, the cost is harder to squeeze down that far.

Read more
The new electric Mercedes C-Class puts its giant screen front and center
Mercedes previews a richer electric C-Class interior with a dash-wide display, upgraded comfort features, and a stronger push to make the cabin feel like the main event
Car, Transportation, Vehicle

Mercedes-Benz is using the cabin to make its first electric C-Class feel like a bigger step than a normal model update. Ahead of the car’s April 20 world premiere, it has shown an interior centered on a sweeping digital display, extra space, and a more upscale finish that leans hard into comfort and theater.

The key visual is the new MBUX Hyperscreen, with Mercedes also offering a Superscreen setup. Both are designed to stretch the digital interface across the front of the car and blend the center console into the instrument panel, giving the dashboard a cleaner and more dramatic shape than the current C-Class.

Read more