/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers discover flaws in immobilizer encryption systems used in some Toyota, Hyundai, and Kia keys, letting attackers gain access with inexpensive hardware

Andy Greenberg / Wired :

Wired Andy Greenberg

Context & Ripple Effects

This disclosure closes a loop that has been running for years: researchers first showed in Volkswagen's shared-key fob cloning that cheap radio hardware could defeat proprietary vehicle access crypto, and later demonstrated radio amplification attacks spanning 24 models from 19 manufacturers. The new work moves the same class of attack from the remote fob to the immobilizer itself — the last line of defense between an attacker and the ignition.

For Hyundai and Kia specifically, it lands on top of a recent software-side failure: the Kia web portal flaw that let researchers track, unlock, and start millions of cars remotely. Two exposed layers at two of the same brands within a short window makes the pair a recurring case study in how broad the automotive attack surface really is.

First-order effects

  • Owners of affected Toyota, Hyundai, and Kia vehicles face a concrete theft risk from attackers with inexpensive off-the-shelf hardware, since the immobilizer — designed to stop exactly this — can be defeated.
  • The three automakers are pushed into remediation mode: identifying which key generations share the weak encryption, deciding between dealer fixes, recalls, or owner advisories, and managing disclosure fallout alongside Wired's Andy Greenberg's reporting.

Second-order effects

  • Hyundai and Kia now carry compounded security reputational exposure — a cloud-side portal breach plus a hardware-side immobilizer flaw — pressuring them to fund deeper cryptographic audits than rivals who have only one layer implicated.
  • Insurers and fleet buyers gain fresh grounds to price vehicle brand and model year by demonstrated key-system vulnerability, shifting procurement conversations toward documented immobilizer architecture rather than marketing claims.

Third-order effects

  • The pattern across Volkswagen, the amplification studies, the API findings, and now immobilizer crypto points toward standardized, externally auditable vehicle-access cryptography replacing each manufacturer's proprietary scheme — likely eventually codified in regulation as connected-car mandates expand.
  • If cheap-hardware attacks keep defeating both RF and cloud layers, vehicle security consolidates around defense-in-depth as a design requirement, making single-point systems like a shared immobilizer secret structurally obsolete across the industry.

The trend: Automotive security research keeps showing that inexpensive hardware defeats proprietary vehicle access systems — from fob cloning to immobilizer crypto — pushing automakers toward standardized, auditable cryptographic design across every layer of the car.

Discussion

  • @picketer Tim Lyons on x
    So we pretty much eliminated car theft and then over-engineered the ignition system so it is back. Nice work. https://www.wired.com/...
  • @phoebesaid Phoebe Wall Howard on x
    A former FBI agent just sent me a note saying, “You were way ahead of this.” ➡️➡️ Our stories in 2018 quoted cyber security experts who advised using metal coffee cans and tin foil to protect car fobs. https://www.wired.com/... @freep @freepautos #autos #CyberSecurity
  • @a_greenberg Andy Greenberg on x
    Researchers found crypto flaws in the immobilizer systems used in millions of Toyotas, Hyundais and Kias that would make it possible to clone the transponders in their key fobs in seconds. (If they can get close enough to the key to read it once) https://www.wired.com/...
  • @doctorow @doctorow on x
    Toyota, Hyundai and Kia keyless ignition fobs can be cloned by attackers who get within a few inches of your pocket (say, at a conference), thanks to implementation errors that the auto-makers made with their Texas Instruments DST80 security systems. https://www.wired.com/... 1/ …