Connect with us
Tesla hackers find a vulnerability with NFC relay attack Tesla hackers find a vulnerability with NFC relay attack

News

Tesla hackers find a vulnerability with NFC relay attack

Jeremy from Sydney, Australia, CC BY 2.0 , via Wikimedia Commons

Published

on

Tesla hackers have found a vulnerability with an NFC relay hack but there’s a catch. Thieves will have to work in pairs and get close to the NFC chip or smartphone.

According to IOActive, the relay attack needs two attackers. One uses the Proxmark device at the vehicle’s NFC reader. The other uses any NFC-capable device close to a Tesla owner’s NFC card or smartphone. The team is then able to use Bluetooth to communicate between the devices and replicate the key to one of the thieve’s smartphones.

This new demonstration comes a few days after the National Highway Traffic Safety Administration (NHTSA) recently released an update to its 2016 edition of its Cybersecurity Best Practices for the Safety of Modern Vehicles. Dr. Steven Cliff, NHTSA’s Administrator emphasized the need for cybersecurity to be a top priority for every automaker, developer, and operator.

According to the agency, a layered approach to vehicle cybersecurity reduces the probability of a successful attack while mitigating the ramifications of unauthorized vehicle system access. The NHTSA also added that public key cryptography techniques are more secure than symmetric keys valid across multiple vehicles.

In 2018, Tesla began rolling out the PIN to Drive feature and improved cryptography for its key fobs as a response to several Tesla vehicle thefts through relay attacks in Europe.

In 2019, Tesla began releasing over-the-air software updates addressing the findings of Lennert Wouters of Katholieke Universiteit Leuven in Belgium (KU Leuven). Wouters discovered a security flaw that allowed car thieves to clone a key fob in less than two seconds. Tesla’s solution included the PIN to Drive, a software update, and a new fob that made the Tesla Models S and X  almost 90% less likely to get stolen than the average car.

The new demonstration may show a vulnerability if thieves are dedicated enough to work at it, but Tesla is pretty fast at addressing these flaws. However, all car owners, whether they own an EV or not, should always be aware of their surroundings. You can watch IOActive’s demonstration video below.

Note: Johnna is a Tesla shareholder and supports its mission. 

Your feedback is important. If you have any comments, or concerns, or see a typo, you can email me at johnna@teslarati.com. You can also reach me on Twitter at @JohnnaCrider1.

Advertisement

Teslarati is now on TikTok. Follow us for interactive news & more.

Johnna Crider is a Baton Rouge writer covering Tesla, Elon Musk, EVs, and clean energy & supports Tesla's mission. Johnna also interviewed Elon Musk and you can listen here

Advertisement
Comments

News

Swedish unions consider police report over Tesla Megapack Supercharger

The Tesla Megapack Supercharger opened shortly before Christmas in Arlandastad, outside Stockholm.

Published

on

Credit: Tesla Charging/X

Swedish labor unions are considering whether to file a police report related to a newly opened Tesla Megapack Supercharger near Stockholm, citing questions about how electricity is supplied to the site. The matter has also been referred to Sweden’s energy regulator.

Tesla Megapack Supercharger

The Tesla Megapack Supercharger opened shortly before Christmas in Arlandastad, outside Stockholm. Unlike traditional charging stations, the site is powered by an on-site Megapack battery rather than a direct grid connection. Typical grid connections for Tesla charging sites in Sweden have seen challenges for nearly two years due to union blockades.

Swedish labor union IF Metall has submitted a report to the Energy Market Inspectorate, asking the authority to assess whether electricity supplied to the battery system meets regulatory requirements, as noted in a report from Dagens Arbete (DA). The Tesla Megapack on the site is charged using electricity supplied by a local company, though the specific provider has not been publicly identified.

Peter Lydell, an ombudsman at IF Metall, issued a comment about the Tesla Megapack Supercharger. “The legislation states that only companies that engage in electricity trading may supply electricity to other parties. You may not supply electricity without a permit, then you are engaging in illegal electricity trading. That is why we have reported this… This is about a company that helps Tesla circumvent the conflict measures that exist. It is clear that it is troublesome and it can also have consequences,” Lydell said.

Police report under consideration

The Swedish Electricians’ Association has also examined the Tesla Megapack Supercharger and documented its power setup. As per materials submitted to the Energy Market Inspectorate, electrical cables were reportedly routed from a property located approximately 500 meters from the charging site.

Tomas Jansson, ombudsman and deputy head of negotiations at the Swedish Electricians’ Association, stated that the union was assessing whether to file a police report related to the Tesla Megapack Supercharger. He also confirmed that the electricians’ union was coordinating with IF Metall about the matter. “We have a close collaboration with IF Metall, and we are currently investigating this. We support IF Metall in their fight for fair conditions at Tesla,” Jansson said.

Continue Reading

News

Tesla HW4.5 spotted in new Model Y, triggers speculation

Owners taking delivery of recent Model Y builds have identified components labeled “AP45.”

Published

on

Credit: Tesla

Tesla’s Hardware 4.5 computer appears to have surfaced in newly delivered Model Y vehicles, prompting fresh speculation about an interim upgrade ahead of the company’s upcoming AI5 chip.

Owners taking delivery of recent Model Y builds have identified components labeled “AP45,” suggesting Tesla may have quietly started rolling out revised autonomy hardware.

Hardware 4.5 appears in new Model Y units

The potential Hardware 4.5 sighting was first reported by Model Y owner @Eric5un, who shared details of a Fremont-built 2026 Model Y AWD Premium delivered this January. As per the Model Y owner, the vehicle includes a new front camera housing and a 16-inch center display, along with an Autopilot computer labeled “AP45” and part number 2261336-02-A.

The Tesla owner later explained that he confirmed the part number by briefly pulling down the upper carpet liner below the Model Y’s glovebox. Other owners soon reported similar findings. One Model Y Performance owner noted that their December build also appeared to include Hardware 4.5, while another owner of an Austin-built Model Y Performance reported spotting the same “AP45” hardware.

These sightings suggest that Tesla may already be installing revised FSD computers in its new Model Y batches, despite the company not yet making any formal announcements about Hardware 4.5.

What Hardware 4.5 could represent

Clues about Hardware 4.5 have surfaced previously in Tesla’s Electronic Parts Catalog. As reported by NotATeslaApp, the catalog has listed a component described as “CAR COMPUTER – LEFT HAND DRIVE – PROVISIONED – HARDWARE 4.5.” The component, which features the part number 2261336-S2-A, is priced at $2,300.00.

Longtime Tesla hacker @greentheonly has noted that Tesla software has contained references to a possible three-SoC architecture for some time. Previous generations of Tesla’s FSD computer, including Hardware 3 and Hardware 4, use a dual-SoC design for redundancy. A three-SoC layout could allow for higher inference throughput and improved fault tolerance.

Such an architecture could also serve as a bridge to AI5, Tesla’s next-generation autonomy chip expected to enter production later in 2026. As Tesla’s neural networks grow larger and more computationally demanding, Hardware 4.5 may provide additional headroom for vehicles built before AI5 becomes widely available.

Advertisement
Continue Reading

Elon Musk

Elon Musk’s Grokipedia is getting cited by OpenAI’s ChatGPT

Some responses generated by OpenAI’s ChatGPT have recently referenced information from Grokipedia.

Published

on

UK Government, CC BY 2.0 , via Wikimedia Commons

Some responses generated by OpenAI’s ChatGPT have recently referenced information from Grokipedia, an AI-generated encyclopedia developed by rival xAI, which was founded by Elon Musk. The citations appeared across a limited set of queries.

Reports about the matter were initially reported by The Guardian

Grokipedia references in ChatGPT

Grokipedia launched in October as part of xAI’s effort to build an alternative to Wikipedia, which has become less centrist over the years. Unlike Wikipedia, which is moderated and edited by humans, Grokipedia is purely AI-powered, allowing it to approach topics with as little bias as possible, at least in theory. This model has also allowed Grokipedia to grow its article base quickly, with recent reports indicating that it has created over 6 million articles, more than 80% of English Wikipedia. 

The Guardian reported that ChatGPT cited Grokipedia nine times across responses to more than a dozen user questions during its tests. As per the publication, the Grokipedia citations did not appear when ChatGPT was asked about high-profile or widely documented topics. Instead, Grokipedia was referenced in responses to more obscure historical or biographical claims. The pattern suggested selective use rather than broad reliance on the source, at least for now.

Broader Grokipedia use

The Guardian also noted that Grokipedia citations were not exclusive to ChatGPT. Anthropic’s AI assistant Claude reportedly showed similar references to Grokipedia in some responses, highlighting a broader issue around how large language models identify and weigh publicly available information.

In a statement to The Guardian, an OpenAI spokesperson stated that ChatGPT “aims to draw from a broad range of publicly available sources and viewpoints.” “We apply safety filters to reduce the risk of surfacing links associated with high-severity harms, and ChatGPT clearly shows which sources informed a response through citations,” the spokesperson stated.

Anthropic, for its part, did not respond to a request for comment on the matter. As for xAI, the artificial intelligence startup simply responded with a short comment that stated, “Legacy media lies.”

Continue Reading