agent Entrepreneur logo
MenuMENU
SearchSEARCH

VW Spent Two Years Trying to Hide a Security Flaw

LONDON (Bloomberg) – Thousands of cars from a host of manufacturers have spent years at risk of electronic car-hacking, according to expert research that Volkswagen has spent two years trying to suppress in the courts, reports Automotive News. “Keyless” car theft, which sees hackers target vulnerabilities in electronic locks and immobilizers, now accounts for 42 ... Read More »

August 14, 2015
4 min to read


LONDON (Bloomberg) – Thousands of cars from a host of manufacturers have spent years at risk of electronic car-hacking, according to expert research that Volkswagen has spent two years trying to suppress in the courts, reports Automotive News.

“Keyless” car theft, which sees hackers target vulnerabilities in electronic locks and immobilizers, now accounts for 42 percent of stolen vehicles in London. BMWs and Range Rovers are particularly at-risk, police say, and can be in the hands of a technically minded criminal within 60 seconds.

Ad Loading...

Security researchers have now discovered a similar vulnerability in keyless vehicles made by several carmakers. The weakness — which affects the Radio-Frequency Identification (RFID) transponder chip used in immobilizers — was discovered in 2012, but carmakers sued the researchers to prevent them from publishing their findings.

This week the paper, by Roel Verdult and Baris Ege from Radboud University in the Netherlands and Flavio Garcia from the University of Birmingham, U.K., is being presented at the USENIX security conference in Washington, D.C. The authors detail how the cryptography and authentication protocol used in the Megamos Crypto transponder can be targeted by malicious hackers looking to steal luxury vehicles.

The Megamos is one of the most common immobilizer transponders, used in Volkswagen-owned luxury brands including Audi, Porsche, Bentley and Lamborghini, as well as Fiats, Hondas, Volvos and some Maserati models.

‘Serious flaw’

“This is a serious flaw and it’s not very easy to quickly correct,” explained Tim Watson, Director of Cyber Security at the University of Warwick. “It isn’t a theoretical weakness, it’s an actual one and it doesn’t cost theoretical dollars to fix, it costs actual dollars.”

Ad Loading...

Immobilizers are electronic security devices that stop a car’s engine from running unless the correct key fob (containing the RFID chip) is in close proximity to the car. They are supposed to prevent traditional theft techniques like hot-wiring, but can be bypassed, for example by amplifying the signal.

In this case, however, researchers broke the transponder’s 96-bit cryptographic system, by listening in twice to the radio communication between the key and the transponder. This reduced the pool of potential secret key matches, and opened up the “brute force” option: running through 196,607 options of secret keys until they found the one that could start the car. It took less than half an hour.

“The attack is quite advanced, but VW produces a lot of very high-end vehicles that get stolen to order. The criminals involved are more sophisticated than the sorts who just steal your keys and drive off with your car,” said security researcher Andrew Tierney.

There’s no quick fix for the problem — the RFID chips in the keys and transponders inside the cars must be replaced, incurring significant labor costs.

One sentence removed

Ad Loading...

The research team first took its findings to the manufacturer of the affected chip in February 2012 and then to Volkswagen in May 2013. The car-maker filed a lawsuit to block the publication of the paper, arguing that it would put the security of winning an injunction in the U.K.’s High Court. Now, after lengthy negotiations, the paper is finally in the public domain — with just one sentence redacted.

“This single sentence contains an explicit description of a component of the calculations on the chip,” Verdult said, adding that by removing the sentence it was much more difficult to recreate the attack.

While challenging, determined “organized gangs” may persevere, said Watson.

“If you’re a maker of high-end cars I would suggest that the onus is on you to look after your customers’ purchases after they’ve bought them to make sure your systems are resistant to attack,” he added.

A VW spokesman responded: “Volkswagen maintains its electronic as well as mechanical security measures technologically up-to-date and also offers innovative technologies in this sector.”

Ad Loading...

Anti-theft protection is generally still ensured, he added, even for older models, because criminals need access to the key signal to hack the immobilizer. “Current models, including the current Passat and Golf, don’t allow this type of attack at all,” he said.

The Megamos Crypto is not the only immobilizer to have been targeted in this way – other popular products including the DST transponder and KeeLoq have both been reverse-engineered and attacked by security researchers.

Topics:VWIndustry

More Industry

Photo of two men in suit jackets shaking hands next to new car inside of a dealership
IndustryApril 23, 2026

A New Consumer Culture in the Auto Dealership

Dealers should aim to build a positive work environment, helping employees execute an efficient experience, from their online research to the final delivery of the vehicle.

Read More →
Closeup of the side of an Audi car
Industryby Hannah MitchellApril 23, 2026

New-Vehicle Sales Down

A cloudy April forecast was expected due to last April’s sales surge in anticipation of U.S. trade tariff-inflated prices. Meanwhile, automakers pumped up incentives to address today’s consumer wallet woes.

Read More →
Photo of Cadillac Lyriq SUV on road with partly cloudy sky in background
Industryby Hannah MitchellApril 16, 2026

Used Autos Selling for More

A recent price spike due to several larger market forces, though it hasn’t dulled demand, is pushing more consumers to efficient models to squeeze in buys.

Read More →
Ad Loading...
Photo of facade of Waldorf Toyota car dealership
Industryby Hannah MitchellApril 16, 2026

Maryland Auto Group Sells

A group out West picked up the major D.C.-area collection, putting it in the upper tiers of private automotive groups in the U.S.

Read More →
Line graphic showing Cox Automotive's March Credit Availability Index status
Industryby Hannah MitchellApril 13, 2026

Auto Lending Opens Up in March

Lenders loosened access for subprime borrowers, and consumers with negative equity reached a record high, Cox Automotive reported.

Read More →
electric vehicle next to an urban charging station. EV Demand Diverges. F&I and Showroom logo
Industryby Lauren LawrenceApril 10, 2026

EV Interest Varies Regionally

U.S. consumer interest in electric vehicles lags behind other countries despite the rising gas prices caused by the ongoing war in the Middle East.

Read More →
Ad Loading...
Photo of the rear of a Mercedes GLC 400 electric SUV with a skyline in the background
Industryby Hannah MitchellApril 10, 2026

Brands Weighed on Projected Recalls

Research reveals the brands and models most likely to have higher recall rates over their lifetimes. While some brands rank high, addressing safety issues can be a selling point.

Read More →
Photo of white 2026 Ford Bronco on a sandy beach
Industryby Hannah MitchellApril 10, 2026

March New-Vehicle Sales Don’t Reflect War

Cox Automotive data shows Americans doubled down on big-is-better despite price increases. Slightly higher incentives helped fuel the demand.

Read More →
Photo of several cars on lifts in a service center
Industryby Hannah MitchellApril 9, 2026

Franchised Dealers Stand to Gain Service Business

Cox Automotive research shows both the opportunities and the challenges in turning consumers’ growing affordability needs into increased fixed-operations revenue.

Read More →
Ad Loading...
Photo of office desk with open laptop on it and an empty chair next to it
IndustryApril 9, 2026

What Matters Most in Building Your Agency

The partner you choose for growth and expansion is key, because better is the ultimate goal instead of growth for growth’s sake.

Read More →