E-rickshaw battery ‘hacks’ and Bluetooth BMS vulnerabilities | Explained
Recent viral videos showing individuals disabling e-rickshaw batteries via Bluetooth are not the result of high-tech sabotage, but rather the exploitation of known security vulnerabilities in specific battery management systems. These systems, manufactured by companies like Jiabaida, lack basic authentication, allowing unauthorized users to connect and manipulate them.
Why it matters
The incident highlights significant cybersecurity risks in the growing electric vehicle infrastructure and the need for better security standards in IoT-enabled hardware.
The story so far: Over the last week, social media has been flooded with videos depicting individuals using mobile applications such as BAT-BMS, Lossigy and Epoch-i-ion to wirelessly disable the batteries of e-rickshaws using Bluetooth. The videos have largely been shared as “pranks” — however cruel, unethical and unlawful they may be — while some have speculated that the applications were designed for high-tech sabotage by China’s manufacturers. The reality is far less dramatic, yet still worth understanding carefully.
The article provides a technical explanation of a security issue without sensationalism.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in