Skip to main content

Bluetooth hack compromises Teslas, digital locks, and more

A group of security researchers has found a way to circumvent digital locks and other security systems that rely on the proximity of a Bluetooth fob or smartphone for authentication.

Using what’s known as a “link layer relay attack,” security consulting firm NCC Group was able to unlock, start, and drive vehicles and unlock and open certain residential smart locks without the Bluetooth-based key anywhere in the vicinity.

Tesla Model 3 keycard.
Image used with permission by copyright holder

Sultan Qasim Khan, the principal security consultant and researcher with NCC Group, demonstrated the attack on a Tesla Model 3, although he notes that the problem isn’t specific to Tesla. Any vehicle that uses Bluetooth Low Energy (BLE) for its keyless entry system would be vulnerable to this attack.

Many smart locks are also vulnerable, Khan adds. His firm specifically called out the Kwikset/Weiser Kevo models since these use a touch-to-open feature that relies on passive detection of a Bluetooth fob or smartphone nearby. Since the lock’s owner doesn’t need to interact with the Bluetooth device to confirm they want to unlock the door, a hacker can relay the key’s Bluetooth credentials from a remote location and open someone’s door even if the homeowner is thousands of miles away.

How it works

This exploit still requires that the attacker have access to the owner’s actual Bluetooth device or key fob. However, what makes it potentially dangerous is that the real Bluetooth key doesn’t need to be anywhere near the vehicle, lock, or other secured devices.

Instead, Bluetooth signals are relayed between the lock and key through a pair of intermediate Bluetooth devices connected using another method — typically over a regular internet link. The result is that the lock treats the hacker’s nearby Bluetooth device as if it’s the valid key.

As Khan explains, “we can convince a Bluetooth device that we are near it — even from hundreds of miles away […] even when the vendor has taken defensive mitigations like encryption and latency bounding to theoretically protect these communications from attackers at a distance.”

The exploit bypasses the usual relay attack protections as it works at a very low level of the Bluetooth stack, so it doesn’t matter whether the data is encrypted, and it adds almost no latency to the connection. The target lock has no way of knowing that it’s not communicating with the legitimate Bluetooth device.

Since many Bluetooth security keys operate passively, a thief would only need to place one device within a few feet of the owner and the other near the target lock. For example, a pair of thieves could work in tandem to follow a Tesla owner away from their vehicle, relaying the Bluetooth signals back to the car so that it could be stolen once the owner was far enough away.

These attacks could be carried out even across vast distances with enough coordination. A person on vacation in London could have their Bluetooth keys relayed to their door locks at home in Los Angeles, allowing a thief to quickly gain access simply by touching the lock.

This also goes beyond cars and smart locks. Researchers note that it could be used to unlock laptops that rely on Bluetooth proximity detection, prevent mobile phones from locking, circumvent building access control systems, and even spoof the location of an asset or a medical patient.

NCC Group also adds this isn’t a traditional bug that can be fixed with a simple software patch. It’s not even a flaw in the Bluetooth specification. Instead, it’s a matter of using the wrong tool for the job. Bluetooth was never designed for proximity authentication — at least not “for use in critical systems such as locking mechanisms,” the firm notes.

How to protect yourself

First, it’s essential to keep in mind that this vulnerability is specific to systems that rely exclusively on passive detection of a Bluetooth device.

For example, this exploit can’t realistically be used to bypass security systems that require you to unlock your smartphone, open a specific app, or take some other action, such as pushing a button on a key fob. In this case, there’s no Bluetooth signal to relay until you take that action — and you’re generally not going to try and unlock your car, door, or laptop when you’re not anywhere near it.

August Wi-Fi Smart Lock installed on door.
August smart lock August

This also won’t typically be a problem for apps that take steps to confirm your location. For instance, the auto-unlock feature in the popular August smart lock relies on Bluetooth proximity detection, but the app also checks your GPS location to make sure you’re actually returning home. It can’t be used to unlock your door when you’re already home, nor can it open your door when you’re miles away from home.

If your security system allows for it, you should enable an extra authentication step that requires that you take some action before the Bluetooth credentials are sent to your lock. For example, Kwikset has said that customers who use an iPhone can enable two-factor authentication in their lock app, and it plans to add this to its Android app soon. Kwikset’s Kevo application also disables proximity unlocking functionality when the user’s phone has been stationary for an extended period.

Note that unlocking solutions that use a mix of Bluetooth and other protocols are not vulnerable to this attack. A typical example of this is Apple’s feature that lets folks unlock their Mac with their Apple Watch. Although this does use Bluetooth to detect the Apple Watch nearby initially, it measures the actual proximity over Wi-Fi — mitigation that Apple’s executives specifically said was added to prevent Bluetooth relay attacks.

NCC Group has published a technical advisory about Bluetooth Low Energy vulnerability and separate bulletins about how it affects Tesla vehicles and Kwikset/Weiser locks.

Editors' Recommendations

Jesse Hollington
Jesse has been a technology enthusiast for his entire life — he probably would have been born with an iPhone in his hand…
Best Samsung Galaxy S22 deals: Save big on unlocked models
The back of the Galaxy S22 and Galaxy S22 Plus.

For a couple of years now the Samsung Galaxy S22 has made for some of the best phone deals you can shop. This includes both the Galaxy S22 and its big brother in the lineup, the Samsung Galaxy S22+. These phones have been out for a little while now, and they’re getting more and more difficult to find brand new. We’ve managed to find a few deals available on both the Galaxy S22 and the Galaxy S22+, however, and there are several ways to save on refurbished models out there. We’ve rounded up all of the best Samsung Galaxy S22 deals taking place at a number of different retailers, but if you're looking for a newer model, be sure to check out other Samsung Galaxy deals, such as Samsung Galaxy S23 deals and Samsung Galaxy S24 Ultra deals.
Samsung Galaxy S22 deals at Samsung

Samsung isn’t currently carrying very many older models of the Samsung Galaxy S phone. You’ll find some newer models like the recently released Samsung Galaxy S24 there, but if you’re looking for something from the S22 model lineup all you’ll find is a Galaxy S22 renewed model. It’s offering some great savings, however, as you can claim it for just $679 with up to $300 in trade-in savings.

Read more
Best Samsung Galaxy S23 Ultra deals: How to get the phone for free
Close-up view of the cameras on the Galaxy S23 Ultra.

Despite the recent release of the Samsung S24 Ultra, the Samsung Galaxy S23 Ultra remains a powerhouse smartphone worth considering. Right now is also one of the best times to buy a new Galaxy S23 Ultra, as it becoming a generation older has ushered in some really impressive Samsung Galaxy S23 Ultra deals. You’ll find these deals scattered across all kinds of retailers, so we’ve done the heavy lifting of organizing all of them in one place. The best Samsung Galaxy deals include some massive savings through sales and trade-in credits, so keep reading for more details on which retail outlet may net you the most savings on a new Galaxy S23 Ultra. Be sure to compare these to older Samsung Galaxy S22 deals and newer Samsung Galaxy S24 deals.
Samsung Galaxy S23 Ultra deals at Amazon

Amazon is offering a 14% discount on the 512GB version of the Samsung Galaxy S23 Ultra, bringing the price from $1,380 to $1,199. That's a savings of nearly $200 to get the new phone. This version of the phone is unlocked for all carriers, so you have the freedom to use whatever plan you choose with it.

Read more
Best Samsung Galaxy Z Flip 5 deals: Get the foldable for free
YouTube Flex mode features on Samsung Galaxy Z Flip 5.

While there are a lot of great foldable flip phones that you can grab, the Galaxy Z Flip 5 is one of the best folding phones on the market right now. It has excellent performance, some of the best cameras on any Samsung device, and the overall build quality makes it feel luxurious. Of course, all this quality comes at quite a premium, and with a device that can cost over $1,000, depending on which model you want to grab, you'll want to snag a deal on it. That's why we've gone out and found some of our favorite Samsung Galaxy deals out there, either as a direct discount or through trade-in deals for both locked and unlocked models of the phone. Be sure to compare these with the similar Samsung Galaxy Z Fold 5 deals and non-folding Samsung Galaxy S24 deals.
Samsung Galaxy Z Flip 5 deals at Samsung

Go directly to the source by buying the Samsung Galaxy Z Flip 5 from Samsung, and you can get up to $600 instant trade-in credit. It depends on what phone you're trading in but it's useful if you prefer to go direct.

Read more