V2GEvil: Ghost in the Wires
Pavel Khunt, Thomas Sermpinis aka Cr0wTom
DEF CON 32 Creator Stage · Day 1 · Creator Stage
Overview
The DEF CON 32 talk "V2GEvil: Ghost in the Wires" presented by Pavel Khunt and Thomas Sermpinis (also known as Cr0wTom) from Auxilium Pentest Labs, addresses the critical and often overlooked cybersecurity landscape surrounding electric vehicle (EV) charging infrastructure. The speakers highlighted the rapid evolution of the automotive industry, particularly with the advent of electric and hybrid vehicles, and the associated expansion of attack surfaces. Their presentation served as an in-depth analysis of EV architecture and the communication protocols that govern charging, aiming to shed light on emerging attack vectors within this undeniably growing sector.

Key moments
- 0:00 Introduction to V2GEvil: Ghost in the Wires and speakers
- 0:25 Talk's main goals, EV architecture, and V2GEvil tool
- 1:00 Automotive industry struggles with new technology security
- 2:00 EV charging standards expand vehicle attack surface
- 2:40 EV charging security: a barely touched topic, new external port risk
V2GEvil: Ghost in the Wires
Speakers: Pavel Khunt, Cyber Security Researcher, Auxilium Pentest Lab; Thomas Sermpinis aka Cr0wTom, Technical Director, Auxilium Pentest Labs
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=Ui2etjRyrUE
Overview
The DEF CON 32 talk "V2GEvil: Ghost in the Wires" presented by Pavel Khunt and Thomas Sermpinis (also known as Cr0wTom) from Auxilium Pentest Labs, addresses the critical and often overlooked cybersecurity landscape surrounding electric vehicle (EV) charging infrastructure. The speakers highlighted the rapid evolution of the automotive industry, particularly with the advent of electric and hybrid vehicles, and the associated expansion of attack surfaces. Their presentation served as an in-depth analysis of EV architecture and the communication protocols that govern charging, aiming to shed light on emerging attack vectors within this undeniably growing sector.
At the core of their research is the introduction of V2G evil, a specialized security tool developed by Pavel Khunt during his university thesis. This tool is positioned as a crucial reference point for EV security research and evaluation, addressing a perceived lack of dedicated resources in the industry. The talk underscores that while the automotive industry is over a century old, the integration of advanced digital technologies and external connectivity, especially through charging mechanisms, introduces a paradigm shift in its security posture. This transition, while beneficial for environmental and efficiency goals, creates significant cybersecurity challenges that are only just beginning to be explored by researchers.
The significance of this talk lies in its focus on an area that, despite its critical importance to future infrastructure and personal safety, remains "barely touched" by the cybersecurity community. As more vehicles become electric and rely on standardized charging protocols, understanding and mitigating vulnerabilities in Vehicle-to-Grid (V2G) and Vehicle-to-Vehicle (V2V) communication, as well as the broader charging ecosystem, becomes paramount. Khunt and Sermpinis aim to catalyze further research and provide foundational knowledge to secure this essential component of modern transportation.
Background
▶ Watch: Introduction to V2GEvil: Ghost in the Wires and speakers (0:00)
The automotive industry, historically rooted in mechanical engineering for over a century, is undergoing a profound transformation driven by the constant demand for increased connectivity and technological integration. This shift has forced traditional automakers, often lacking deep expertise in software and network security, to rapidly adopt complex digital systems. While newer automotive startups, born from a technology-first mindset, tend to exhibit a more robust security posture and culture, the industry as a whole has struggled over the past decade to adequately secure these increasingly sophisticated vehicles. This struggle creates a significant gap in the security landscape, leaving a vast number of connected vehicles vulnerable.
The emergence of electric and hybrid vehicles represents a pivotal aspect of this technological revolution. Driven by global efforts to decentralize pollution, leverage clean energy solutions, and achieve significant gains in speed and efficiency, EVs are rapidly becoming mainstream. Early EV models often relied on basic charging mechanisms, but the last decade has seen a concerted push towards standardization. This has led to the widespread adoption of common ports, protocols, and data formats, applicable across different continents and regulatory frameworks. While standardization is crucial for interoperability and consumer convenience, it simultaneously expands the attack surface of vehicles. The digital communication required during charging, which connects the vehicle to an external charging station and potentially the wider grid, introduces entirely new attack vectors that were non-existent in traditional internal combustion engine vehicles.
The speakers emphasized that this expansion of the attack surface, while not entirely groundbreaking in the context of general cybersecurity, represents a significant and "barely touched topic" within the realm of automotive security research. Modern vehicles are essentially complex networks of interconnected Electronic Control Units (ECUs), each responsible for diverse functionalities, ranging from managing a single headlight to orchestrating sophisticated DC-DC power conversion. Historically, these ECUs and the vehicle's internal network (like the CAN bus) were relatively isolated from the external world. However, the introduction of an "externally accessible port" for charging fundamentally alters this isolation. This direct connection to a charging station, and by extension potentially the electrical grid, creates a substantial "room for error." If these new interfaces and their underlying communication protocols are not designed, implemented, and secured with the utmost rigor, the potential for unexpected and detrimental security incidents is dramatically increased.
Key Findings
▶ Watch: Talk's main goals, EV architecture, and V2GEvil tool (0:25)
The introductory segment of the "V2GEvil: Ghost in the Wires" presentation, as captured in the provided transcript, primarily focused on establishing the critical context and outlining the ambitious scope of the talk. Consequently, specific "key findings," detailed vulnerability disclosures, or novel attack chain demonstrations were not yet presented within this initial portion. The speakers, Pavel Khunt and Thomas Sermpinis, were in the process of setting the stage for what was clearly intended to be a deep dive into the nascent field of EV charging cybersecurity.
However, based on the talk's title, its stated objectives, and the problems articulated in the introduction, it is evident that the full presentation would have aimed to reveal significant insights into the vulnerabilities inherent in the electric vehicle charging ecosystem. The core "findings" would likely revolve around the identification of specific weaknesses within the communication protocols used for EV charging – an area explicitly highlighted as "barely touched" by researchers. This could include, but is not limited to, vulnerabilities in authentication mechanisms between the vehicle and charging station, integrity flaws in charging command exchanges, or privacy concerns related to data transmitted during the charging process. The speakers' mention of the "big room for error" due to improperly implemented and designed systems strongly suggests that their findings would have pinpointed common pitfalls in current EV and charging station designs, potentially leading to security and safety compromises. The development and introduction of the V2G evil tool further implies that the talk would have showcased practical demonstrations of these findings, illustrating how an attacker could exploit these weaknesses to manipulate charging behavior, impact grid stability, or compromise vehicle functionality.
Technical Deep Dive
▶ Watch: Automotive industry struggles with new technology security (1:00)
While the provided transcript segment primarily served as an introduction, it laid a clear foundation for the technical depth that the full "V2GEvil: Ghost in the Wires" presentation would undoubtedly have explored. The speakers explicitly stated their intention to "explore and understand the communication protocols used in EV charging today" and provide an "in-depth look on the EV architecture." This commitment signifies a deep dive into the intricate technical mechanisms that underpin the interaction between electric vehicles and their charging infrastructure.
At the heart of modern EV charging is a complex interplay of hardware and software, orchestrated through various digital communication protocols. The most prominent of these, though not explicitly named in the provided snippet, is the ISO 15118 standard, which defines the communication interface for Vehicle-to-Grid (V2G) and Plug & Charge functionalities. This standard typically relies on Power Line Communication (PLC) for data exchange over the same physical cable used for power delivery, enabling sophisticated features like smart charging, automated authentication, and bidirectional power flow. A technical deep dive would likely have dissected the layers of these protocols, from the physical layer (e.g., HomePlug Green PHY) up to the application layer (e.g., EXI, XML), identifying potential points of failure or manipulation.
The talk would likely have elaborated on how the vehicle's internal Electronic Control Units (ECUs), specifically those responsible for battery management, charging control, and communication gateways, interact with the external charging station. This involves understanding the firmware running on these ECUs, the security mechanisms (or lack thereof) implemented at the hardware level, and how data integrity and authenticity are maintained during charging sessions. Vulnerabilities could arise from insecure firmware updates, weak cryptographic implementations, or design flaws in the state machine logic that governs charging. For instance, an attacker might aim to inject malicious commands to overcharge a battery, disrupt charging cycles, or even potentially leverage the charging connection as an ingress point into the vehicle's internal network, bypassing traditional automotive security measures. The speakers' emphasis on the "externally accessible port" highlights the critical nature of securing this direct interface, moving beyond the traditional focus on internal bus systems like CAN or LIN, and addressing the new challenge of external network exposure.
Demo / Proof of Concept
▶ Watch: EV charging standards expand vehicle attack surface (2:00)
The speakers, Pavel Khunt and Thomas Sermpinis, explicitly introduced their self-developed security tool, V2G evil, which Pavel constructed as part of his university thesis. This tool serves as the central proof of concept for their research into EV charging security. While the provided transcript did not include a live demonstration or a detailed technical breakdown of V2G evil's operational mechanics, its very existence and naming strongly imply its purpose as an active research and exploitation platform for vulnerabilities within the Vehicle-to-Grid (V2G) communication ecosystem.
It is reasonable to infer that V2G evil is designed to interact with both electric vehicles and charging stations, simulating various scenarios to test the robustness and security of their communication protocols. Such a tool would likely possess capabilities for:
- Protocol Analysis and Fuzzing: Intercepting, analyzing, and manipulating the digital communication between an EV and a charging station, potentially identifying unexpected behaviors or unhandled edge cases in protocol implementations.
- Malicious Command Injection: Simulating unauthorized charging commands, such as altering charging voltage, current limits, or initiating/terminating charging sessions without proper authentication.
- Authentication Bypass: Attempting to circumvent authentication mechanisms (e.g., those used in Plug & Charge) to gain unauthorized access or control over charging processes.
- Data Exfiltration/Injection: Probing for ways to extract sensitive vehicle data during charging or inject malicious data that could affect vehicle diagnostics or performance.
- Denial-of-Service (DoS) Attacks: Flooding charging stations or vehicles with malformed packets to disrupt charging services or render equipment inoperable.
The creation of V2G evil underscores the practical, hands-on nature of the speakers' research. It acts as a concrete example of how researchers can emulate and explore the "ghost in the wires" – the unseen digital vulnerabilities lurking within the EV charging infrastructure. The tool's development as a university thesis project also highlights the growing academic interest and need for dedicated resources to tackle this emerging cybersecurity domain.
Defensive Implications
▶ Watch: EV charging security: a barely touched topic, new external port risk (2:40)
Although the introductory segment of the "V2GEvil: Ghost in the Wires" talk did not delve into specific attack vectors or detailed vulnerabilities, the overarching message from Pavel Khunt and Thomas Sermpinis clearly articulated a critical and pervasive gap in the cybersecurity posture of the electric vehicle charging ecosystem. Their emphasis on the "big room for error" stemming from externally accessible charging ports and the general lack of security maturity within the traditional automotive sector points to several crucial defensive implications that manufacturers, charging infrastructure providers, and consumers must address.
Firstly, a fundamental shift in security-by-design principles is imperative for both EV manufacturers and charging station developers. Security must be an inherent consideration from the earliest stages of product development, not an afterthought. This includes rigorously securing the Electronic Control Units (ECUs) involved in charging, implementing robust firmware signing and verification mechanisms, and ensuring secure boot processes. All communication protocols, especially those interacting with external entities like charging stations and the grid, must incorporate strong cryptographic authentication and integrity checks to prevent unauthorized command injection or data manipulation.
Secondly, the standardization of charging protocols, while beneficial for interoperability, necessitates a uniform and high level of security implementation across the board. Defenders must focus on secure protocol implementation, ensuring that common standards like ISO 15118 are not only adhered to but also implemented without introducing weaknesses. This includes proper certificate management for Plug & Charge functionality, secure key exchange mechanisms, and robust error handling to prevent protocol-level attacks. Regular penetration testing and security audits, potentially utilizing tools like V2G evil, are essential to proactively identify and remediate vulnerabilities before they can be exploited in the wild.
Finally, user awareness and operational security practices play a vital role. Charging station operators must ensure their infrastructure is regularly patched, securely configured, and physically protected. Consumers should be educated on potential risks, such as the dangers of using unverified or suspicious charging stations. The entire supply chain, from component manufacturers to software developers, must adhere to stringent security standards to mitigate the risk of malicious hardware or software being introduced into the ecosystem. By addressing these defensive implications comprehensively, the automotive industry can move towards a more secure and resilient electric vehicle future.
Key Takeaways
- Emerging Attack Surface: Electric vehicle charging introduces a significant and largely unexplored attack surface to modern vehicles, fundamentally altering their cybersecurity posture by connecting previously isolated internal systems to external charging infrastructure.
- Industry Cybersecurity Gap: The automotive industry, particularly traditional manufacturers, struggles with integrating robust cybersecurity practices into the rapid adoption of new connected technologies, creating a "big room for error" in EV charging systems.
- Standardization Creates Uniform Risk: While beneficial for interoperability, the standardization of EV charging ports and communication protocols creates a uniform attack surface, meaning a single vulnerability could potentially affect a wide range of vehicles and charging stations.
- Critical Need for Research Tools: Dedicated security research and specialized tools like V2G evil are crucial for exploring, identifying, and understanding vulnerabilities in EV charging communication protocols, which are currently "barely touched" by the cybersecurity community.
- Security-by-Design Imperative: To mitigate risks, EV manufacturers and charging infrastructure providers must adopt a security-by-design approach, focusing on secure protocol implementation, robust authentication, firmware integrity, and continuous security testing from the outset.
About the Speaker(s)
Pavel Khunt is a Cyber Security Researcher currently working at Auxilium Pentest Lab. He is recognized for his hands-on approach to automotive security, having developed the specialized security tool V2G evil as part of his university thesis. His work focuses on uncovering and analyzing cybersecurity issues within the evolving landscape of electric vehicle charging.
Thomas Sermpinis, also known by his alias Cr0wTom, serves as the Technical Director of Auxilium Pentest Labs. With extensive experience in cybersecurity, he guides research initiatives, including those focused on the automotive industry. Sermpinis is a proponent of in-depth analysis of emerging attack vectors and advocates for creating reference points for security research and evaluation in critical, underexplored domains such as EV charging.