News

'Hackers' Show How to Steal a Tesla Model X in Minutes

Giulio Saggin
Giulio Saggin
Tuesday 28 November 2023
'Hackers' Show How to Steal a Tesla Model X in Minutes
Tesla Model X

A group of 'hackers' have shown it's possible to break into a Tesla Model X car in a matter of minutes.

Thankfully the hackers were researchers, who showed it was possible to breach a Tesla's key fob which, like many other makes of car, uses Bluetooth Low Energy (BLE) to lock and unlock the vehicle.

"Using a modified Electronic Control Unit (ECU), obtained from a salvage Tesla Model X, we were able to wirelessly force key fobs to advertise themselves as connectable BLE devices," said Lennert Wouters, one of the researchers from the Computer Security and Industrial Cryptography (COSIC) research group at the University of Leuven in Belgium.

The researchers first had to 'wake up' a victim's fob, which needed to be done within five metres. Once accessed, the researchers loaded their software and gained full control over the fob. This took them less than two minutes and could be done anywhere up to 30 metres away.

"With the ability to unlock the car we could then connect to the diagnostic interface normally used by service technicians. Because of a vulnerability in the implementation of the pairing protocol we can pair a modified key fob to the car, providing us with permanent access and the ability to drive off with the car," said Wouters.

All of this was done for under $200, too. The researchers used a self-made device built from a Raspberry Pi computer ($35) with a CAN shield ($30), a modified key fob and ECU from a salvage vehicle ($100 on eBay) and a LiPo battery ($30).

The researchers informed Tesla of issues in mid-August this year and were awarded a bug bounty. Tesla has released an over-the-air software update to fix the issues.

COSIC video showing how they hacked a Tesla Model X.

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203