News
Tesla cybersecurity measures fail, hackers win Model 3 at hacking event
Tesla has been hacked at the Pwn2Own hacking event, and the hacking group has taken home a Tesla Model 3 and $100,000.
As electric vehicles and their significant amount of integrated software have become more common in everyday life, the security around them has become significantly more critical. In the worst-case scenario, a hacker could not only gain access to a car but could leak user data or even take control of the vehicle. Now, at the Pwn2Own hacking competition, a group of hackers successfully hacked a Tesla Model 3 and won the vehicle along with a $100,000 prize.
The successful hack completed by the group Synactiv was initially reported by the Zero Day Initiative Twitter account, revealing that the group had used a TOCTOU exploit to gain access to the vehicle.
One of the main highlights from Day One of #Pwn2Own Vancouver 2023: @Synacktiv vs the Tesla Model 3. Their successful demonstration earned them $100,000 and the car itself pic.twitter.com/d7TY5mKHxK
— Zero Day Initiative (@thezdi) March 23, 2023
CONFIRMED! @Synacktiv successfully executed a TOCTOU exploit against Tesla – Gateway. They earn $100,000 as well as 10 Master of Pwn points and this Tesla Model 3. #Pwn2Own #P2OVancouver pic.twitter.com/W61NasJPAl
— Zero Day Initiative (@thezdi) March 22, 2023
Thanks to the nature of the hacking competition, the details of how the hack was performed have not been made entirely public to avoid a security risk for Tesla owners. Still, the method the hackers used was relatively straightforward.
The TOCTOU (Time-Of-Check Time-Of-Use) exploit involves altering internal files to gain system access. In essence, the hackers are altering the files that a system will check to ensure someone actually should have access. This could, for example, involve changing login credentials to allow yourself access. However, as the name suggests, this is highly time-dependent, as it involves using the discrepancy of time between the system checking the files and a person actually being logged in.
Pwn2Own is one of the most famous hacking events in the world. It involves teams of hackers attempting to gain access to some of the most popular software available on the market. Each group of hackers and security researchers will be given a list of devices and software and a series of objectives to achieve. The first team to navigate through the list gains a cash prize. In this case, for completing this step of the competition quickest, the Synactive team won the Tesla Model 3 that they hacked.
With software becoming ever more interconnected with the vehicles we drive, focusing on keeping that software secure will only become more important as time passes. And with the increasing interconnectedness of these car systems, the consequences of not keeping these systems secure will only become more dire. Hopefully, automakers will take this threat seriously and continue to work to keep their items as safe and secure as possible.
What do you think of the article? Do you have any comments, questions, or concerns? Shoot me an email at william@teslarati.com. You can also reach me on Twitter @WilliamWritin. If you have news tips, email us at tips@teslarati.com!
Elon Musk
Delaware Supreme Court reinstates Elon Musk’s 2018 Tesla CEO pay package
The unanimous decision criticized the prior total rescission as “improper and inequitable,” arguing that it left Musk uncompensated for six years of transformative leadership at Tesla.
The Delaware Supreme Court has overturned a lower court ruling, reinstating Elon Musk’s 2018 compensation package originally valued at $56 billion but now worth approximately $139 billion due to Tesla’s soaring stock price.
The unanimous decision criticized the prior total rescission as “improper and inequitable,” arguing that it left Musk uncompensated for six years of transformative leadership at Tesla. Musk quickly celebrated the outcome on X, stating that he felt “vindicated.” He also shared his gratitude to TSLA shareholders.
Delaware Supreme Court makes a decision
In a 49-page ruling Friday, the Delaware Supreme Court reversed Chancellor Kathaleen McCormick’s 2024 decision that voided the 2018 package over alleged board conflicts and inadequate shareholder disclosures. The high court acknowledged varying views on liability but agreed rescission was excessive, stating it “leaves Musk uncompensated for his time and efforts over a period of six years.”
The 2018 plan granted Musk options on about 304 million shares upon hitting aggressive milestones, all of which were achieved ahead of time. Shareholders overwhelmingly approved it initially in 2018 and ratified it once again in 2024 after the Delaware lower court struck it down. The case against Musk’s 2018 pay package was filed by plaintiff Richard Tornetta, who held just nine shares when the compensation plan was approved.
A hard-fought victory
As noted in a Reuters report, Tesla’s win avoids a potential $26 billion earnings hit from replacing the award at current prices. Tesla, now Texas-incorporated, had hedged with interim plans, including a November 2025 shareholder-approved package potentially worth $878 billion tied to Robotaxi and Optimus goals and other extremely aggressive operational milestones.
The saga surrounding Elon Musk’s 2018 pay package ultimately damaged Delaware’s corporate appeal, prompting a number of high-profile firms, such as Dropbox, Roblox, Trade Desk, and Coinbase, to follow Tesla’s exodus out of the state. What added more fuel to the issue was the fact that Tornetta’s legal team, following the lower court’s 2024 decision, demanded a fee request of more than $5.1 billion worth of TSLA stock, which was equal to an hourly rate of over $200,000.
Delaware Supreme Court Elon Musk 2018 Pay Package by Simon Alvarez
News
Tesla Cybercab tests are going on overdrive with production-ready units
Tesla is ramping its real-world tests of the Cybercab, with multiple sightings of the vehicle being reported across social media this week.
Tesla is ramping its real-world tests of the Cybercab, with multiple sightings of the autonomous two-seater being reported across social media this week. Based on videos of the vehicle that have been shared online, it appears that Cybercab tests are underway across multiple states.
Recent Cybercab sightings
Reports of Cybercab tests have ramped this week, with a vehicle that looked like a production-ready prototype being spotted at Apple’s Visitor Center in California. The vehicle in this sighting was interesting as it was equipped with a steering wheel. The vehicle also featured some changes to the design of its brake lights.
The Cybercab was also filmed testing at the Fremont factory’s test track, which also seemed to involve a vehicle that looked production-ready. This also seemed to be the case for a Cybercab that was spotted in Austin, Texas, which happened to be undergoing real-world tests. Overall, these sightings suggest that Cybercab testing is fully underway, and the vehicle is really moving towards production.
Production design all but finalized?
Recently, a near-production-ready Cybercab was showcased at Tesla’s Santana Row showroom in San Jose. The vehicle was equipped with frameless windows, dual windshield wipers, powered butterfly door struts, an extended front splitter, an updated lightbar, new wheel covers, and a license plate bracket. Interior updates include redesigned dash/door panels, refined seats with center cupholders, updated carpet, and what appeared to be improved legroom.
There seems to be a pretty good chance that the Cybercab’s design has been all but finalized, at least considering Elon Musk’s comments at the 2025 Annual Shareholder Meeting. During the event, Musk confirmed that the vehicle will enter production around April 2026, and its production targets will be quite ambitious.
News
Tesla gets a win in Sweden as union withdraws potentially “illegal” blockade
As per recent reports, the Vision union’s planned anti-Tesla action might have been illegal.
Swedish union Vision has withdrawn its sympathy blockade against Tesla’s planned service center and showroom in Kalmar. As per recent reports, the Vision union’s planned anti-Tesla action might have been illegal.
Vision’s decision to pull the blockade
Vision announced the blockade in early December, stating that it was targeting the administrative handling of Tesla’s facility permits in Kalmar municipality. The sympathy measure was expected to start Monday, but was formally withdrawn via documents sent to the Mediation Institute and Kalmar Municipality last week.
As noted in a Daggers Arbete report, plans for the strike were ultimately pulled after employer group SKR highlighted potential illegality under the Public Employment Act. Vision stressed its continued backing for the Swedish labor model, though Deputy negotiation manager Oskar Pettersson explained that the Vision union and IF Metall made the decision to cancel the planned strike together.
“We will not continue to challenge the regulations,” Petterson said. “The objection was of a technical nature. We made the assessment together with IF Metall that we were not in a position to challenge the legal assessment of whether we could take this particular action against Tesla. Therefore, we chose to revoke the notice itself.”
The SKR’s warning
Petterson also stated that SKR’s technical objection to the Vision union’s planned anti-Tesla strike framed the protest as an unauthorized act. “It was a legal assessment of the situation. Both for us and for IF Metall, it is important to be clear that we stand for the Swedish model. But we should not continue to challenge the regulations and risk getting judgments that lead nowhere in the application of the regulations,” he said.
Vision ultimately canceled its planned blockade against Tesla on December 9. With Vision’s withdrawal, few obstacles remain for Tesla’s long-planned Kalmar site. A foreign electrical firm completed work this fall, and Tesla’s Careers page currently lists a full-time service manager position based there, signaling an imminent opening.