Hyundai keyless entry exploit
In August 2025, a flaw was discovered in the security of Hyundai's wireless communications protocol, which allows hackers with a "Game Boy-style" device to access the Ioniq 5 and gain physical access to the vehicle without the owner's consent. Hyundai is offering to fix this flaw in their production software for customers who pay a £49 charge.[1]
Background
[edit | edit source]Keyless entry systems and push-button start systems in cars are becoming increasingly prevalent, offering drivers greater convenience and enhanced features like remote start. While these systems enhance the user experience, they have also introduced new security challenges, with criminals developing ways to exploit vulnerabilities. These systems have long been vulnerable to relay attacks, a broader issue in the automotive industry documented by security researchers. [2] Previous incidents (e.g., Kia “USB hacks”[3] and BMW relay thefts[4]) illustrate a systemic security problem across the industry.
Incident
[edit | edit source]
Hyundai's response
[edit | edit source]Hyundai put out a statement on their website:[5]
All vehicles produced by Hyundai are developed and certified in accordance with all applicable security and regulatory standards in place at the time of production and sale, including the applied security systems installed.
Recently, evolving security threats, including the use of unauthorised electronic devices to bypass vehicle locking systems have become more prevalent in the UK. This is an industry-wide issue and Hyundai is providing appropriate responses in line with industry practices.
As part of the Company’s commitment to supporting our customers, we are able to offer a subsidised software and hardware upgrade for a customer contribution of £49.
Hyundai’s statement frames the £49 charge as part of their “commitment to supporting customers,” describing the fix as a “subsidised upgrade.” However, this phrasing shifts attention away from the underlying issue—that customers are being asked to pay to address a security vulnerability in the company’s product. While the cost may be reduced, the language used makes it less clear that responsibility for the expense has been placed on owners rather than covered by the manufacturer.
Consumer response
[edit | edit source]Many consumers have expressed sharp frustration and disillusionment over Hyundai's handling of the Ioniq 5 keyless theft vulnerability.[6][7] One notable case involves a digital security expert, whose Ioniq 5 was stolen in under 20 seconds using a handheld emulator device disguising itself as a Game Boy.[8] The owner says Hyundai had warned him of other modifications the vehicle required, but failed to alert him and other motorists that its security systems were compromised.
References
[edit | edit source]- ↑ Warren, Tom (2025-08-13). "Hyundai wants Ioniq 5 owners to pay to fix a keyless entry security hole". The Verge. Archived from the original on 24 Aug 2025.
- ↑ Francillon, Aurelien; Danev, Boris; Capkun, Srdjan (2010-10-21). "Relay Attacks on Passive Keyless Entry and Start Systems in Modern Cars" (PDF). Cryptology ePrint Archive. Archived from the original (PDF) on 31 Jan 2026 – via Cryptology ePrint Archive.
- ↑ Stumpf, Rob (2022-08-02). "How Thieves Are Stealing Hyundais and Kias With Just a USB Cable". The Drive. Archived from the original on 14 Jan 2026. Retrieved 2025-08-20.
- ↑ "BMW stolen with " Remote Relay Attacks "". iXforums. 2023-11-27. Retrieved 2025-08-20.
{{cite web}}: CS1 maint: url-status (link) - ↑ "Security and Locking Systems". Hyundai. 2025-08-20. Archived from the original on 2025-08-21. Retrieved 2025-08-20.
- ↑ Warren, Tom (2025-08-13). "Hyundai wants Ioniq 5 owners to pay to fix a keyless entry security hole". The Verge. Archived from the original on 24 Aug 2025.
- ↑ "Hyundai facing legal action over car that can be stolen 'effortlessly in seconds'". Reddit. 2025-03-29. Retrieved 2025-08-20.
{{cite web}}: CS1 maint: url-status (link) - ↑ Ungoed-Thomas, Jon (2025-03-29). "Hyundai facing legal action over car that can be stolen 'effortlessly in seconds'". The Guardian. Retrieved 2025-08-20.
{{cite web}}: CS1 maint: url-status (link)