Researchers created an app that could withhold insulin or trigger a lethal overdose after Medtronic and the FDA delayed a replacement plan for flawed pumps
TWO YEARS AGO, researchers Billy Rios and Jonathan Butts discovered disturbing vulnerabilities in Medtronic's popular MiniMed and MiniMed Paradigm insulin pump lines.
Context & Ripple Effects
Billy Rios and Jonathan Butts flagged the MiniMed vulnerabilities two years ago, and the disclosure arc has been slow-moving since: the FDA recently announced a recall of Medtronic pumps precisely because they connect wirelessly but cannot be updated to fix the flaws. This Wired report is the proof-of-concept stage of that story — an app that can withhold insulin or force a lethal overdose makes the abstract risk concrete.
It is also not the first time this class of device has failed publicly: Johnson & Johnson warned about an exploitable overdose risk in 114K insulin pumps back in 2016, so Medtronic is now the second major pump maker to face a wireless-security reckoning.
First-order effects
- Users dependent on MiniMed and Paradigm pumps face replacement of hardware that cannot be patched, with Medtronic bearing the cost and disruption of swapping out deployed devices.
- The demonstrated app converts a theoretical vulnerability into a public safety claim, pressuring the FDA to move faster than its delayed replacement plan.
Second-order effects
- Rivals gain a security-based selling point: Tandem Diabetes Care's later FDA-cleared dosing app shows the market rewarding newer, software-updatable pump platforms over legacy fleets.
- Insurers and clinicians weighing pump prescriptions now have a documented attack scenario to factor in, shifting procurement toward vendors who can ship firmware updates rather than recalls.
Third-order effects
- If unpatchable wireless hardware keeps triggering recalls, connected medical device makers will be pushed toward updatable-by-design architectures, with regulators treating inability-to-patch as a defect in itself.
- The pattern — researcher disclosure, delayed vendor response, then regulator-forced replacement — points toward mandatory premarket cybersecurity review for implantable and life-sustaining devices.
The trend: Connected medical devices are moving from security-through-obscurity to patchable, regulator-audited designs, as unpatchable hardware increasingly ends in recalls rather than fixes.