Alert on hacking tool (Flipper Zero) being used to steal cars … including A LOT of Fords

sborsch

Well-Known Member
First Name
Steve
Joined
Jan 21, 2022
Threads
21
Messages
132
Reaction score
291
Location
Southern California
Vehicles
2024 MME; 2020 Lexus NX300 Hybrid
Occupation
I.T. Consultant
Country flag

XGC75

Active Member
Joined
Mar 15, 2025
Threads
1
Messages
38
Reaction score
39
Location
Michigan
Vehicles
2021 Genesis G70

azerik

Well-Known Member
First Name
Erik
Joined
Jan 8, 2023
Threads
79
Messages
4,545
Reaction score
4,558
Location
Chandler/Flagstaff, AZ
Vehicles
'21 Spacey Prem4x, '21 RX450H, 13 Focus EV
Occupation
DevSecNetOps, General PITA
Country flag
Video already pulled by YT. I expected it to be a flipperzero. We've played with these in the past and they have a good amount of power, fairly scary.
 


OP
OP
sborsch

sborsch

Well-Known Member
First Name
Steve
Joined
Jan 21, 2022
Threads
21
Messages
132
Reaction score
291
Location
Southern California
Vehicles
2024 MME; 2020 Lexus NX300 Hybrid
Occupation
I.T. Consultant
Country flag
@flapjake314 article in The Drive did say up to 2025 models but as you said, @Blue highway the list is note definitive. Wonder if that is why the video got pulled, @azerik as it’s not factual or up to YT standards.
 

azerik

Well-Known Member
First Name
Erik
Joined
Jan 8, 2023
Threads
79
Messages
4,545
Reaction score
4,558
Location
Chandler/Flagstaff, AZ
Vehicles
'21 Spacey Prem4x, '21 RX450H, 13 Focus EV
Occupation
DevSecNetOps, General PITA
Country flag
If it shows how to do it they'll pull it. (even though Flipper has plenty of video on how)
They eventually pulled the Kia video after tons a KIA's got stolen and kids said they saw it on YT
 

Ford Motor Company

Well-Known Member
Official Ford Account
First Name
Brian
Joined
May 10, 2021
Threads
68
Messages
3,462
Reaction score
6,548
Location
Michigan
Vehicles
Mustang Mach-E
Occupation
Real Human & Community Manager
Country flag
The Drive (and many other pubs) just released an article about this hacking device which will probably let thieves steal your car including and up to 2025 models!

Are you all over this @Ford Motor Company? This is bad on so many levels I don’t even know where or what to rant about with this hack! While it says “Mustang” in the chart that accompanies this YouTube video about the hack, does that include the Mach-e and when will a patch be available?

IMG_1393.jpeg
Our team is aware and investigating! If at any point there is action we advise owners to take, I’ll make sure to share it here.
 

Jeff-NoVA

Well-Known Member
First Name
Jeff
Joined
Oct 21, 2023
Threads
19
Messages
696
Reaction score
1,123
Location
Northern VA
Vehicles
2022 Mustang Mach-E Premium
Country flag
I think it's worth remembering, this is a $600 custom firmware for the Flipper Zero that a Russian guy has so far sold to a handful of people, many of them private dealers. This isn't something teens are likely to be running around your neighborhood using.
 

eponey

Well-Known Member
Joined
Nov 5, 2024
Threads
8
Messages
176
Reaction score
166
Location
USA
Vehicles
MME
Supposedly the vulnerability conceptually has been around for a while and it only unlocks the car but does not start it...yet.
 

Mach-Lee

Well-Known Member
First Name
Lee
Joined
Jul 16, 2021
Threads
262
Messages
11,381
Reaction score
25,066
Location
Wisconsin
Vehicles
2022 Mach-E Premium AWD
Occupation
Sci/Eng
Country flag
To avoid being hacked, do not use the buttons on your key fob. Phone-as-a-key would be immune to it since those use Bluetooth instead of 315 MHz. I also don't think it will work with intelligent access, just the remote buttons. And they can't start your car.

Honestly it was a matter of time before rolling code fobs would be hacked, I'm surprised it lasted this long.
 

XGC75

Active Member
Joined
Mar 15, 2025
Threads
1
Messages
38
Reaction score
39
Location
Michigan
Vehicles
2021 Genesis G70
To avoid being hacked, do not use the buttons on your key fob. Phone-as-a-key would be immune to it since those use Bluetooth instead of 315 MHz. I also don't think it will work with intelligent access, just the remote buttons. And they can't start your car.

Honestly it was a matter of time before rolling code fobs would be hacked, I'm surprised it lasted this long.
I'm not so sure an unlock key press is required. The key definitely broadcasts evidenced by the car waking up when you walk towards it. Ford could never confirm or deny without risking security, unfortunately.

On the other hand, if I'm the developer of this firmware I wouldn't want to try and make software that can break all the different methods that detect and validate proximity. Hacking a button press seems simpler.
 

ESJB

Active Member
Joined
Feb 28, 2025
Threads
0
Messages
41
Reaction score
53
Location
Canberra, Australia
Vehicles
Select SR RWD 2023.75 (Aus)
I'm not so sure an unlock key press is required. The key definitely broadcasts evidenced by the car waking up when you walk towards it. Ford could never confirm or deny without risking security, unfortunately.
It's maybe the same problem (and solution) as posted by @Trekkie101 in Mach E branded keys back in stock... The solution may be to replace all key fobs with ones that contain a motion sensor. So they only respond to car pings when picked up.
Sponsored

 
 







Top