Researchers Find Super Simple Way to Hack Tesla Keys

Chris Teague
by Chris Teague

Security researchers have found numerous vulnerabilities in some of today’s most popular vehicles, including finding ways to access owner data, take control of vehicle systems, and more. Tesla’s vehicles aren’t immune, and a team of researchers recently showed how easy accessing one of the advanced EVs with a simple electronic device can be.


The crew at Mysk has found a way to clone Tesla owners’ keys by hacking into the wireless internet networks at the automaker’s Supercharger stations. They use a device called Flipper Zero, which can broadcast a fake Wi-Fi network with a name similar to the ones used at Superchargers.


Once the user is connected and has entered their Tesla account information, their data is captured by the Flipper Zero. Hackers then prompt the user for a multi-factor authentication code, which allows them to access a Tesla account using an app on their smartphones. The hackers can then gain access to the car, clone a key using the Flipper Zero, and other malicious actions.


Some companies pay bounties to hackers who come forward with information about a vulnerability or security issue, but Tesla’s response to Mysk was surprising. The automaker responded, “Thanks for the report. We have investigated and determined that this is the intended behavior. The ‘Phone Key’ section of the owner’s manual makes no mention of a key card being required to add a phone key.”


While there are a few steps involved in this hack, and the bad actors have to be somewhat nearby to commit the crime, it’s worth noting that this is one of the simpler vulnerabilities we’ve seen so far. Some hackers have outlined having to access deeply protected vendor accounts and other complicated pathways to gain user info, while this one appears to be pretty straightforward by comparison.


[Image: Shutterstock]


Become a TTAC insider. Get the latest news, features, TTAC takes, and everything else that gets to the truth about cars first by   subscribing to our newsletter.

Chris Teague
Chris Teague

Chris grew up in, under, and around cars, but took the long way around to becoming an automotive writer. After a career in technology consulting and a trip through business school, Chris began writing about the automotive industry as a way to reconnect with his passion and get behind the wheel of a new car every week. He focuses on taking complex industry stories and making them digestible by any reader. Just don’t expect him to stay away from high-mileage Porsches.

More by Chris Teague

Comments
Join the conversation
2 of 26 comments
  • User User on Mar 16, 2024

    I had fallen victim to a malicious scam exploited by a cunning fraudster friend, who lured me into a fake cryptocurrency investment scheme through a website called CryptoCirtus.com. Sadly, i had lost a staggering $400,000 to this elaborate deception. Determined to seek justice and recovers my hard-earned money, It was during this desperate search that i came across Trustwizards Hackworld, a renowned cybersecurity and financial recovery agency. Trustwizards,(trustwizards(AT)G'MAIL) known for their expertise in handling complex scams and financial fraud cases, understood the gravity of the situation and quickly assembled a team of skilled professionals to assist me. As the investigation unfolded.

    Finally, Trustwizards had successfully traced the stolen funds. Through their relentless efforts, they recover my $400,000. It brought a sense of closure and relief to me, who had feared losing everything. Trustwizards not only helped me recover my funds but also provided me with guidance and education on how to protect myself from future scams. They shared valuable insights and best practices for online security and investment precautions, empowering me and others to make informed decisions in the digital realm. And so, with Trustwizards' expertise and unwavering dedication, my tale of loss and despair transformed into a story of resilience, justice, and hope in the face of adversity. I vowed to become an advocate for cybersecurity awareness, helping others avoid falling victim to similar scams, fighting against cybercrime and bringing hope to those who had lost everything. If you have similar experience you can contact: trustwizards AT G'mail Dot com. W/app: (+1) 3,8,6,- (3,8,7,)

    7,0,5,4. Telegram: trustwizards_hackworld

  • Joe Joe on Mar 19, 2024

    This is called a man in the middle attack and has been around for years. You can fall for this in a Starbucks as easily as when you’re charging your car. Nothing new here…

  • Redapple2 Front tag obscured. Rear tag - clear and sharp. Huh?
  • Redapple2 I can state what NOT to buy. HK. High theft. Insurance. Unrefined NVH. Rapidly degrading interiors. HK? No way !
  • Luke42 Serious answer:Now that I DD an EV, buying an EV to replace my wife’s Honda Civic is in the queue. My wife likes her Honda, she likes Apple CarPlay, and she can’t stand Elon Musk - so Tesla starts the competition with two demerit-points and Honda starts the competition with one merit-point.The Honda Prologue looked like a great candidate until Honda announced that the partnership with GM was a one-off thing and that their future EVs would be designed in-house.Now I’m more inclined toward the Blazer EV, the vehicle on which the Prologue is based. The Blazer EV and the Ultium platform won’t be orphaned by GM any time soon. But then I have to convince my wife she would like it better than her Honda Civic, and that’s a heavy lift because she doesn’t have any reason to be dissatisfied with her current car (I take care of all of the ICE-hassles for her).Since my wife’s Honda Civic is holding up well, since she likes the car, and since I take care of most of the drawbacks of drawbacks of ICE ownership for her, there’s no urgency to replace this vehicle.Honestly, if a paid-off Honda Civic is my wife’s automotive hill to die on, that’s a pretty good place to be - even though I personally have to continue dealing the hassles and expenses of ICE ownership on her behalf.My plan is simply to wait-and-see what Honda does next. Maybe they’ll introduce the perfect EV for her one day, and I’ll just go buy it.
  • 2ACL I have a soft spot for high-performance, shark-nosed Lancers (I considered the less-potent Ralliart during the period in which I eventually selected my first TL SH-AWD), but it's can be challenging to find a specimen that doesn't exhibit signs of abuse, and while most of the components are sufficiently universal in their function to service without manufacturer support, the SST isn't one of them. The shops that specialize in it are familiar with the failure as described by the seller and thus might be able to fix this one at a substantial savings to replacement. There's only a handful of them in the nation, however. A salvaged unit is another option, but the usual risks are magnified by similar logistical challenges to trying to save the original.I hope this is a case of the seller overvaluing the Evo market rather than still owing or having put the mods on credit. Because the best offer won't be anywhere near the current listing.
  • Peter Buying an EV from Toyota is like buying a Bible from Donald Trump. Don’t be surprised if some very important parts are left out.
Next