Skip to main content
  1. Home
  2. Cars
  3. News

Researchers find Tesla Model 3 and Cybertruck are hackable machines on wheels

Cybertruck? More like Cyber-Oops, say researchers

Add as a preferred source on Google
Cybertruck
Cybertruck Unsplash

Security researchers have uncovered major vulnerabilities in two of Tesla’s most popular vehicles, revealing that the Tesla Model 3 and Cybertruck can be transformed into remotely controlled, highly compromised “machines on wheels.” The findings highlight new concerns around the growing complexity of connected cars – and how deeply embedded software systems can introduce risks most drivers never consider.

Researchers demonstrate deep access inside Tesla’s system software

A research team from Northeastern University has shown that they could manipulate core systems inside the Tesla operating environment by exploiting vulnerabilities in the vehicle’s internal networking architecture. Rather than breaking into the car from a distance, researchers focused on what happens once an attacker gains physical access – a scenario they argue is far more realistic than fully remote Hollywood-style car hacks.

Their work demonstrated that plugging a compromised device into Tesla’s internal network could unlock access to subsystems responsible for power steering, braking behavior, acceleration logic, and even driver-assistance features. By reverse-engineering protocols and communication pathways inside the vehicles, researchers created proof-of-concept attacks capable of altering vehicle behavior in ways the driver would not immediately detect.

Why the findings matter for connected vehicles

Modern vehicles rely heavily on a network of microcontrollers, sensors, and software layers – more than 100 million lines of code in some cases. This complexity increases the potential attack surface dramatically. The research underscores that today’s EVs and smart cars function much like rolling computers, and that traditional automotive safety assumptions don’t fully account for systemic software vulnerabilities.

Recommended Videos

Critically, the team notes that an attacker wouldn’t need to be a nation-state actor or elite hacker. With basic technical skills and short-term physical access – for example during valet parking, routine servicing, or rental car use – a malicious device could be introduced to modify internal communications on the vehicle’s CAN bus.

These are not remote takeover attacks, but they show that internal system protections are not robust enough to prevent malicious code execution once an intruder reaches the car’s physical ports.

Implications for drivers and the industry

For everyday drivers, the research brings attention to the importance of treating modern cars as digital devices with their own cybersecurity risks. Features like keyless entry, over-the-air updates, and extensive onboard sensors dramatically improve convenience – but they also create more potential failure points.

The findings also highlight a broader industry challenge: car manufacturers are racing to add autonomous features, AI-driven systems, and always-connected infotainment platforms, but security frameworks have not evolved at the same pace. With EV adoption rising and cars becoming increasingly software-dependent, security researchers warn that vulnerabilities could become more common unless cybersecurity becomes a core design priority.

What’s next for Tesla, regulators, and automakers

Researchers disclosed their findings to Tesla before publication, and while the company acknowledged the report, it noted that the tests involved devices plugged directly into the vehicle – a scenario it considers lower-risk than remote compromise. Still, the research community argues that physical-access hacks remain critical threats in real-world contexts.

Going forward, academics expect more attention on automotive cybersecurity standards, including stronger encryption of internal communications, authenticated software messaging, and redesigned access ports that minimize the risk of malicious injections.

Regulators may also revisit standards around connected vehicle safety as cars increasingly resemble complex cloud-connected computing platforms.

As connected vehicles become the norm, the automotive industry is likely to face increasing pressure to harden systems, adopt zero-trust architectures, and treat cybersecurity as seriously as crash safety.

Moinak Pal
Moinak Pal is has been working in the technology sector covering both consumer centric tech and automotive technology for the…
Two Indian automakers just beat Tesla at the one thing you’d expect it to own
Two Indian automakers, Tata Motors and Mahindra, just topped a global EV efficiency ranking ahead of Tesla and BYD.
Car, Suv, Transportation

I'll admit, Tesla topping an efficiency ranking felt like a foregone conclusion until I actually saw the numbers. Turns out two Indian automakers just embarrassed both Tesla and the world's biggest EV maker at their own game. 

The first time I read the report, I couldn’t believe it, and I’ve been following the Indian automobile industry for a couple of years now.  

Read more
BYD’s new Racco is Japan’s first electric kei car with over 300 km range
The Racco also undercuts Nissan's Sakura on price before taxes and incentives, which packing in features rarely seen in the kei car segment.
BYD Racco

BYD has entered the Japanese kei car market with the Racco, an electric car built specifically for the country's compact car segment. Its top trim delivers 320 km of range, making it the first compact electric car in the market to pass 300 km, according to ITHome.

Kei cars are a Japanese vehicle class with strict size and power limits, and the segment has long been dominated by domestic automakers such as Honda, Nissan, Suzuki, and Daihatsu. The Racco is BYD's first attempt to compete in that space.

Read more
BMW could finally be building the electric convertible fans have always wanted
Good things come to those who wait, and apparently that means until 2028.
BMW convertible

There have been whispers about a two-door BMW i4 for years, and according to a new report from BMWBlog, at least one version is actually in the works. The outlet's sources close to BMW claim the automaker is readying an i4 Convertible under the internal codename NA3.

Why is BMW waiting until 2028 to launch it?

Read more