Washington | 29°C (broken clouds)
Bluetooth Slip‑Up Leaves Millions of U.S. Cars Open to Remote Theft

A newly uncovered Bluetooth weakness lets thieves unlock and start many American vehicles from a distance

Security researchers have identified a flaw in the Bluetooth‑based anti‑theft systems of dozens of popular U.S. car models, allowing criminals to bypass key‑fob protections and steal cars with inexpensive tools.

It sounds like something out of a sci‑fi thriller, but the reality is far less glamorous: a simple Bluetooth glitch is giving car thieves a back‑door into millions of vehicles cruising the streets of the United States. A team of researchers from the University of Michigan, in partnership with the cybersecurity firm Kryptos Logic, announced this week that they’ve managed to unlock and even start several makes and models by spoofing the very signal the key‑fob uses to talk to the car.

What makes the bug especially worrisome is that it isn’t confined to a single brand or a niche luxury model. The study found the same faulty implementation across a roster that includes popular picks from General Motors, Ford, Stellantis and other major manufacturers. In plain English, the Bluetooth Low Energy (BLE) link that should protect your ride is, in many cases, sitting there with a broken lock.

At the heart of the problem is a misuse of the rolling‑code algorithm that’s supposed to change the authentication token every time you press the fob button. Instead of a truly random sequence, many cars were re‑using a static identifier that a cheap Bluetooth sniffer can capture from a distance—sometimes as far as 100 meters. Once the attacker has that identifier, they can replay it, fool the car into thinking the legitimate key is present, and the doors pop open.

The researchers demonstrated the attack with off‑the‑shelf hardware that costs less than $30. In their lab, they placed a vulnerable vehicle in a parking lot, walked a few steps away, and unlocked it with a device that looked more like a Bluetooth speaker than a sophisticated hacking rig. The car’s anti‑theft system, which is supposed to be the first line of defense, didn’t even flinch.

Automakers have responded quickly, at least on paper. General Motors issued a statement saying it is working on a software update that will randomize the BLE key and roll out the patch later this year. Ford and Stellantis made similar pledges, urging owners to keep their key fobs in a Faraday pouch and to stay tuned for OTA (over‑the‑air) updates. Until those patches land, experts recommend simple steps: keep the fob away from windows, use a steering‑wheel lock where possible, and consider a RFID‑blocking wallet.

While the flaw is certainly a wake‑up call for the auto industry, it also highlights a broader trend: as vehicles get smarter, they also become more exposed to the same wireless vulnerabilities that have plagued smartphones for years. The lesson here is clear—stay vigilant, keep your firmware current, and don’t assume that a blinking key‑less entry light means you’re safe from prying hands.

Comments 0
Please login to post a comment. Login
No approved comments yet.

Editorial note: Nishadil may use AI assistance for news drafting and formatting. Readers can report issues from this page, and material corrections are reviewed under our editorial standards.