Providers and Administrators in blue logo
MenuMENU
SearchSEARCH

VW Spent Two Years Trying to Hide a Security Flaw

August 14, 2015
4 min to read


LONDON (Bloomberg) - Thousands of cars from a host of manufacturers have spent years at risk of electronic car-hacking, according to expert research that Volkswagen has spent two years trying to suppress in the courts, reports Automotive News.

“Keyless” car theft, which sees hackers target vulnerabilities in electronic locks and immobilizers, now accounts for 42 percent of stolen vehicles in London. BMWs and Range Rovers are particularly at-risk, police say, and can be in the hands of a technically minded criminal within 60 seconds.

Ad Loading...

Security researchers have now discovered a similar vulnerability in keyless vehicles made by several carmakers. The weakness -- which affects the Radio-Frequency Identification (RFID) transponder chip used in immobilizers -- was discovered in 2012, but carmakers sued the researchers to prevent them from publishing their findings.

This week the paper, by Roel Verdult and Baris Ege from Radboud University in the Netherlands and Flavio Garcia from the University of Birmingham, U.K., is being presented at the USENIX security conference in Washington, D.C. The authors detail how the cryptography and authentication protocol used in the Megamos Crypto transponder can be targeted by malicious hackers looking to steal luxury vehicles.

The Megamos is one of the most common immobilizer transponders, used in Volkswagen-owned luxury brands including Audi, Porsche, Bentley and Lamborghini, as well as Fiats, Hondas, Volvos and some Maserati models.

'Serious flaw'

"This is a serious flaw and it's not very easy to quickly correct," explained Tim Watson, Director of Cyber Security at the University of Warwick. "It isn't a theoretical weakness, it's an actual one and it doesn't cost theoretical dollars to fix, it costs actual dollars."

Ad Loading...

Immobilizers are electronic security devices that stop a car's engine from running unless the correct key fob (containing the RFID chip) is in close proximity to the car. They are supposed to prevent traditional theft techniques like hot-wiring, but can be bypassed, for example by amplifying the signal.

In this case, however, researchers broke the transponder's 96-bit cryptographic system, by listening in twice to the radio communication between the key and the transponder. This reduced the pool of potential secret key matches, and opened up the "brute force" option: running through 196,607 options of secret keys until they found the one that could start the car. It took less than half an hour.

"The attack is quite advanced, but VW produces a lot of very high-end vehicles that get stolen to order. The criminals involved are more sophisticated than the sorts who just steal your keys and drive off with your car," said security researcher Andrew Tierney.

There's no quick fix for the problem -- the RFID chips in the keys and transponders inside the cars must be replaced, incurring significant labor costs.

One sentence removed

Ad Loading...

The research team first took its findings to the manufacturer of the affected chip in February 2012 and then to Volkswagen in May 2013. The car-maker filed a lawsuit to block the publication of the paper, arguing that it would put the security of winning an injunction in the U.K.'s High Court. Now, after lengthy negotiations, the paper is finally in the public domain -- with just one sentence redacted.

"This single sentence contains an explicit description of a component of the calculations on the chip," Verdult said, adding that by removing the sentence it was much more difficult to recreate the attack.

While challenging, determined "organized gangs" may persevere, said Watson.

"If you're a maker of high-end cars I would suggest that the onus is on you to look after your customers' purchases after they've bought them to make sure your systems are resistant to attack," he added.

A VW spokesman responded: "Volkswagen maintains its electronic as well as mechanical security measures technologically up-to-date and also offers innovative technologies in this sector."

Ad Loading...

Anti-theft protection is generally still ensured, he added, even for older models, because criminals need access to the key signal to hack the immobilizer. "Current models, including the current Passat and Golf, don't allow this type of attack at all," he said.

The Megamos Crypto is not the only immobilizer to have been targeted in this way – other popular products including the DST transponder and KeeLoq have both been reverse-engineered and attacked by security researchers.


More Industry

Blurred photo of red car moving down a road
Industryby Hannah MitchellMarch 31, 2026

Automakers Have More Tricks Up Their Sleeves

JD Power analysts see auto retail faring this year’s storms well through various means, though it acknowledges conditions are challenging to accurately predict.

Read More →
background view of Washington D.C. with the capitol building and cherry trees. Text says 'What's the Cost?' with two diverging arrows and the Providers and Administrator's logo
Industryby Lauren LawrenceMarch 31, 2026

Insurance Rates Continue to Fall

Car insurance premiums have continued to decline so far this year, the overall national average settling at $138 per month in March, according to Insurify data.

Read More →
Bar graphic showing car segment activity for the previous week
Industryby StaffMarch 31, 2026

Black Book: Weekly Market Update

Last week's wholesale auction activity was stable, though buyers exercised selectivity as they focused on certain segments.

Read More →
Ad Loading...
gray background with white text that says Dealer Debrief 03/25/2026 with Lauren Lawrence. picture of a white woman (Lauren) with red hair
Industryby Lauren LawrenceMarch 25, 2026

Dealer Debrief: Safety, Supply & Partnership

In this week's Dealer Debrief, host Lauren Lawrence covers a new safety assessment, current inventory issues, and a new payables process for dealerships.

Read More →
Line chart depicting retail used-vehicle auction volume
Industryby StaffMarch 24, 2026

Black Book: Weekly Market Update

Both conversions and values were up last week, though business was spotty depending on the segment in question.

Read More →
red battery-electric vehicle using a Tesla Supercharging station
Industryby Lauren LawrenceMarch 24, 2026

Stellantis Expands Charging Network

Five of its brands now have greater access to battery-electric vehicle charging through Tesla’s Supercharger network across North America.

Read More →
Ad Loading...
blue subaru crosstrek in city with Save with SUVS text and Providers and Administrators logo
Industryby Lauren LawrenceMarch 17, 2026

Safety Drives Insurance Rates

Sixteen out of the 20 cheapest vehicles to insure in 2026 are SUVs, according to CarInsurance.com, largely because of their safety features and lower repair costs.

Read More →
Close-up photo of the front of a new-looking white car
Industryby Hannah MitchellMarch 17, 2026

New-Vehicle Shoppers Get Some Relief

Overall conditions in February tipped slightly in consumers’ favor as prices stayed high, granting a reprieve of sorts just before the war on Iran commenced and started to reverse the welcome trend.

Read More →
row of cars, used vehicle demand spikes, chart showing data spike, F&I and Showroom logo
Showroomby Lauren LawrenceMarch 11, 2026

Used Market Gains Speed

New-vehicle sales fell year-over-year for the fifth month in a row in February, making retail deliveries the slowest they’ve been since 2023, according to a CarGurus report.

Read More →
Ad Loading...
text reading Auto Loan Defaults Reach 2% on desk background with car keys, calculator, notepad, and toy car
Industryby Lauren LawrenceMarch 10, 2026

Auto Loan Defaults Measured Amid Inflation

According to LendingTree data, the average monthly auto loan payment was $540 in the fourth quarter, and the average credit score for those with a recorded default was 529.

Read More →