Researchers find cryptographic keys shared by millions of Volkswagen vehicles can allow them clone key fobs using cheap radio hardware
In 2013, when University of Birmingham computer scientist Flavio Garcia and a team of researchers were preparing to reveal a vulnerability that allowed …
Context & Ripple Effects
Flavio Garcia's University of Birmingham team had been sitting on this result since 2013, when they were first preparing to reveal the vulnerability — the multi-year gap before publication suggests coordinated disclosure with Volkswagen took that long to settle. The finding lands five months after researchers showed 24 cars from 19 manufacturers were open to a radio amplification attack, making this the second keyless-entry failure of 2016 to hit the same supplier ecosystem.
The distinction matters: amplification extends an owner's own fob's range, while this attack clones fobs outright because cryptographic material is shared across millions of vehicles rather than unique per car. The same research lineage resurfaced in 2020, when immobilizer encryption flaws were found in some Toyota, Hyundai, and Kia keys — evidence the weakness was architectural, not one automaker's mistake.
First-order effects
- Millions of Volkswagen owners are left holding fobs whose secrets cannot be individually rotated, since the cloned key material is baked into the fleet — remediation falls on dealers and lock re-keying rather than a software patch.
- Volkswagen faces the disclosure directly: Garcia's team withheld publication for years negotiating fixes, so the company has had lead time, but the shared-key design limits how much of the fleet any fix can reach.
Second-order effects
- Other manufacturers using similar immobilizer architectures face pressure to audit their own key hierarchies — a check that four years later surfaced equivalent flaws at Toyota, Hyundai, and Kia, confirming the problem crossed suppliers and brands.
- The economics of the attack invert the usual threat model: when cloning needs only cheap radio hardware rather than bespoke equipment, insurers and fleet operators price physical theft risk differently than they do for per-vehicle-unique systems.
Third-order effects
- Shared-secret designs across vehicle fleets prove structurally fragile, pushing the industry toward per-vehicle cryptography and, eventually, distance-bounding defenses like the ultra-wideband keyless system that GoGoByte's 2024 relay demonstration against a Tesla Model 3 still managed to defeat.
- A decade-long disclosure pattern — Birmingham's years-long embargo here, then successive findings through 2020 and beyond — hardens into the template for how automotive key vulnerabilities reach the public, feeding regulatory attention on vehicle cybersecurity standards.
The trend: Automotive keyless entry is locked in a decade-long cycle where each cryptographic fix shifts attacks to the next weakest layer — from range amplification to shared-key cloning to relay attacks on newer protocols.