Chinese automotive cybersecurity firm GoGoByte demonstrates a cheap and simple relay attack to unlock a Tesla Model 3 despite its ultra-wideband keyless system
Ultra-wideband radio has been heralded as the solution for “relay attacks” that are used to steal cars in seconds. X: @a_greenberg . Forums: Hacker News X: Andy Greenberg / @a_greenberg : The latest Tesla Model 3 can still be stolen using a cheap and common radio hack known as a “relay attack.” That's despite it using ultra-wideband radio in its keyless entry system, an upgrade widely seen as a fix for relay attacks. Not yet, apparently. https://www.wired.com/... Forums: Hacker News : Teslas Can Still Be Stolen with a Cheap Radio Hack-Despite New Keyless Tech
Context & Ripple Effects
Tesla had already characterized relay attacks as a known limitation after researchers showed that a BLE relay attack could unlock and operate a Tesla beyond the phone’s normal range. This result tests whether moving to ultra-wideband changes that exposure in practice.
It also extends a longer record of automotive access systems being undermined by range-extension and key-management weaknesses, including radio amplification vulnerabilities across 24 vehicles from 19 manufacturers.
First-order effects
- Tesla Model 3 owners using the affected ultra-wideband keyless-entry setup remain exposed to an inexpensive relay technique that can unlock the vehicle.
- Tesla’s newer proximity-access design loses its presumed security advantage against this specific class of attack, increasing pressure to assess the implementation rather than the radio technology alone.
Second-order effects
- Other automakers adopting ultra-wideband keyless entry will face stronger scrutiny of their distance-bounding and relay defenses, not simply whether they include UWB hardware.
- Vehicle-security teams and insurers may treat passive-entry protections as an end-to-end system problem, spanning the key, phone, vehicle, and the conditions under which access is granted.
Third-order effects
- If similar demonstrations recur, passive keyless entry will increasingly be evaluated on resilience to low-cost physical-layer attacks rather than on the presence of a newer wireless standard.
- The pattern favors layered access controls that can limit what proximity credentials authorize, though the corpus does not establish which mitigations Tesla or peers will adopt.
The trend: Automotive access security is shifting from replacing older radios to proving that complete proximity-authentication systems withstand cheap relay attacks.