Exploiting Bluetooth from your car to the bank account
Vladyslav Zubkov, Martin Str
DEF CON 32 Creator Stage · Day 1 · Creator Stage
Overview
This talk, "Exploiting Bluetooth from your car to the bank account," presented at DEF CON 32, delves into the pervasive security vulnerabilities inherent in Bluetooth technology, spanning from automotive systems to potentially critical financial applications. Delivered by Martin Str of the Swiss Cyber Defense Campus, with the primary technical insights from Vladyslav Zubkov (known as YSO and Schwytz) provided via video due to visa issues, the presentation highlighted how common Bluetooth implementations and even underlying standards are fundamentally insecure. The research was motivated by a crucial mandate: to ensure the Swiss military and federal government procure secure IT systems, including vehicles, by identifying vulnerabilities as early as possible in the acquisition lifecycle.

Key moments
- 0:00 Talk start, speaker introduction and context
- 4:00 Vlad's successful intro: bug bounty approach to Bluetooth
- 5:00 Martin's self-introduction and wireless security background
- 6:00 Research motivation: secure procurement for Swiss military
- 7:00 Challenges in security procurement due to long life cycles
Exploiting Bluetooth from your car to the bank account
Speakers: Vladyslav Zubkov (YSO and Schwytz), Bug Bounty Hunter; Martin Str, Security Researcher & Scientist, Swiss Cyber Defense Campus
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=JL7a_oLoXHY
Overview
This talk, "Exploiting Bluetooth from your car to the bank account," presented at DEF CON 32, delves into the pervasive security vulnerabilities inherent in Bluetooth technology, spanning from automotive systems to potentially critical financial applications. Delivered by Martin Str of the Swiss Cyber Defense Campus, with the primary technical insights from Vladyslav Zubkov (known as YSO and Schwytz) provided via video due to visa issues, the presentation highlighted how common Bluetooth implementations and even underlying standards are fundamentally insecure. The research was motivated by a crucial mandate: to ensure the Swiss military and federal government procure secure IT systems, including vehicles, by identifying vulnerabilities as early as possible in the acquisition lifecycle.
The talk underscores the critical need for proactive security measures in procurement, moving beyond reactive post-deployment pen testing. By applying a bug bounty hunting mindset to an area previously unexplored by the lead researcher – Bluetooth and automotive systems – the team uncovered significant findings that challenge the perceived security of widely deployed wireless technologies. The implications extend beyond just convenience features in cars, suggesting a broader risk profile for any system relying on Bluetooth, emphasizing the potential for exploitation that could impact operational security and even personal financial data, as hinted by the talk's provocative title.
The core message is a stark warning to manufacturers, procurement agencies, and end-users alike: the convenience of Bluetooth often comes at a significant security cost. The research aimed to not only expose these weaknesses but also to provide tools and insights that can help shape more robust security requirements in future tenders and encourage a wider industry shift towards more secure design and implementation practices for Bluetooth-enabled devices.
Background
▶ Watch: Talk start, speaker introduction and context (0:00)
The research presented by Martin Str and Vladyslav Zubkov is rooted in a unique and critical mission of the Swiss Cyber Defense Campus, the procurement agency for the Swiss military and federal government. Their primary objective is to guarantee that the systems acquired by the government and military are inherently secure. This is particularly challenging given the vast array of IT and other systems, such as vehicles, procured in high volumes. Such large-scale procurement offers significant negotiation leverage with manufacturers, a leverage the Campus aims to utilize effectively to enhance security.
Traditional security approaches often fall short in this context. Public procurement typically involves distinct stages: pre-tender, actual tender contract, and post-procurement deployment. Conducting simple penetration testing after systems have been purchased and deployed is frequently too late. At this stage, the negotiation leverage with manufacturers is diminished, and insecure systems are already operational, posing unacceptable risks to national security and government operations. This reactive approach forces agencies to operate vulnerable systems, which is far from ideal for an organization with such high security requirements.
Another avenue often explored is research into standards. While identifying flaws in foundational protocols and technologies, such as those used in aviation, can be valuable, the lifecycle of these standards is often extraordinarily long. Even demonstrating major vulnerabilities might take decades to translate into practical changes, rendering this approach unsuitable for immediate procurement needs. For instance, in sectors like aviation or automotive, a technology adopted today might remain in use for twenty or thirty years, making rapid adaptation to security findings extremely difficult. This inherent inertia in critical infrastructure and transportation systems means that incremental improvements to standards offer little near-term benefit for current procurement cycles.
Given these limitations, the Swiss Cyber Defense Campus recognized the necessity for a more proactive strategy: performing concrete vulnerability research as early as possible in the procurement process. The goal is to influence security requirements during the pre-tender and tender stages, thereby shaping the final specifications to mandate higher security standards from the outset. This approach involves collaboration with manufacturers, leveraging expertise from academia both within Switzerland and internationally, to collectively enhance the security posture of systems for all users, not just the military or government. This early intervention model allows for security considerations to be baked into the design and contractual obligations rather than being bolted on as an afterthought.
The speakers themselves brought diverse backgrounds to this research. Martin Str, a security researcher and scientist at the Swiss Cyber Defense Campus, has a strong foundation in wireless security, with numerous publications in major academic systems security conferences. His work spans various transportation security domains, including aviation (where he's presented at the Aerospace Village), space, cars, and trains. Notably, he mentions prior work on electric vehicle charging processes at brokenwire.fail, highlighting his experience in critical infrastructure security. Despite this extensive background, Martin stated he had "never looked at Bluetooth before this work," bringing a fresh perspective to the technology. Similarly, Vladyslav Zubkov, a seasoned bug bounty hunter specializing in web, mobile, and infrastructure pen testing, also confessed to having "never attacked Bluetooth or cars before." This unique combination of a generalist bug bounty hunter and a wireless security expert, both approaching Bluetooth with fresh eyes, proved instrumental. Their methodology involved applying generalized bug bounty hunting techniques – which typically focus on identifying common patterns of vulnerabilities, misconfigurations, and logic flaws – to the Bluetooth ecosystem, yielding "interesting results" that challenge conventional assumptions about the technology's resilience.
Key Findings
▶ Watch: Vlad's successful intro: bug bounty approach to Bluetooth (4:00)
The central and most overarching key finding of this research, as explicitly stated by Martin Str in his concluding remarks, is that "much of Bluetooth is fundamentally insecure, both the standards and implementations." This comprehensive statement serves as the primary takeaway, indicating that the vulnerabilities discovered are not merely isolated bugs in specific products, but rather systemic weaknesses present at multiple layers of the Bluetooth ecosystem. This implies that the problem is not just poor coding by individual vendors, but potentially flaws in the very design and specifications that govern Bluetooth communication, alongside widespread issues in how those specifications are translated into real-world products.
While the provided transcript, unfortunately, does not contain the granular details of specific exploits, CVE numbers, or detailed technical results from Vladyslav Zubkov's video segment, the broad nature of this finding is significant. It suggests that the application of a bug bounty hunting methodology—a technique typically focused on discovering new and innovative ways to bypass security controls in web, mobile, and infrastructure environments—to the Bluetooth domain proved highly effective in uncovering these deep-seated insecurities. The fact that researchers, relatively new to the specifics of Bluetooth and car hacking, could achieve "interesting results" by applying these generalist techniques highlights a potentially low bar for entry for malicious actors.
The lack of specific examples in the transcript prevents a detailed enumeration of the types of vulnerabilities found (e.g., authentication bypasses, denial-of-service, data exfiltration, remote code execution). However, the talk's title, "Exploiting Bluetooth from your car to the bank account," strongly implies that the findings demonstrate attack paths that could lead to significant real-world impact. In the context of "cars," this could range from unauthorized access to vehicle systems, remote control of certain functions, or exfiltration of sensitive data from in-car infotainment systems. The ambitious "bank account" reference suggests that these Bluetooth vulnerabilities could potentially be chained with other exploits to compromise financial transactions, access banking applications on mobile devices, or otherwise interact with sensitive financial data through a compromised Bluetooth connection. Although the specific mechanisms for such a "bank account" compromise are not detailed in the provided text, its inclusion in the title underscores the severe potential consequences of the identified Bluetooth insecurities. The overarching message is that the attack surface presented by Bluetooth is far more critical and less protected than often assumed, necessitating a fundamental re-evaluation of its security posture across various applications.
Technical Deep Dive
▶ Watch: Martin's self-introduction and wireless security background (5:00)
Due to the circumstances described in the talk's introduction—where the main technical speaker, Vladyslav Zubkov, presented his detailed findings via a pre-recorded video that is not extensively transcribed in the provided text—a comprehensive technical deep dive into specific exploits, code, protocols, or architectures is not possible within the confines of this article. The transcript primarily covers the motivation, background, and high-level findings presented by Martin Str.
However, based on the context, the methodology employed by Vladyslav Zubkov involved applying bug bounty hunting techniques to the Bluetooth ecosystem. This approach typically focuses on:
- Reconnaissance and Enumeration: Identifying all discoverable Bluetooth devices, their services, advertised characteristics, and supported protocols. This often involves tools for scanning and profiling Bluetooth Low Energy (BLE) and classic Bluetooth devices.
- Protocol Analysis: Deep inspection of the Bluetooth stack, including layers like L2CAP, RFCOMM, GATT (Generic Attribute Profile) for BLE, and SDP (Service Discovery Protocol). Attackers look for deviations from standard specifications or misconfigurations.
- Fuzzing: Sending malformed or unexpected data to Bluetooth services to identify crashes, unexpected behavior, or memory corruption vulnerabilities (e.g., buffer overflows). This can be applied at various layers of the Bluetooth stack.
- Logic Flaws: Identifying weaknesses in the application-layer logic built on top of Bluetooth. This could involve bypassing authentication mechanisms, unauthorized access to privileged functions, or manipulating data flows that assume trusted connections.
- Reverse Engineering: Analyzing firmware or companion mobile applications that interact with Bluetooth devices to understand proprietary protocols, encryption schemes, or hidden functionalities.
The research's emphasis on "both the standards and implementations" being insecure suggests a multi-faceted attack surface. Vulnerabilities in Bluetooth standards could refer to cryptographic weaknesses, pairing process flaws, or insecure default configurations defined by the Bluetooth Special Interest Group (SIG). For example, older Bluetooth versions or specific pairing modes might be susceptible to known attacks like BlueBorne (CVE-2017-0781, CVE-2017-0785), KNOB (Key Negotiation of Bluetooth) attack, or impersonation attacks if not properly mitigated.
Implementation flaws, on the other hand, would relate to how manufacturers or developers integrate Bluetooth into their products. This could include:
- Incorrectly handling pairing requests.
- Weak or hardcoded PINs.
- Lack of proper input validation in custom Bluetooth services.
- Insecure data handling or storage of sensitive information transmitted over Bluetooth.
- Vulnerabilities in the operating system's Bluetooth stack (e.g., Android's BlueFrag CVE-2020-0022).
The talk's title mentioning "cars" indicates that specific attention was paid to the automotive Bluetooth attack surface. Modern vehicles incorporate Bluetooth for various functions, including hands-free calling, media streaming, keyless entry systems, and diagnostic tools. Exploiting these could involve gaining access to the infotainment system, potentially interacting with CAN bus (Controller Area Network) systems through vulnerabilities in the head unit, or even performing actions like unlocking doors or starting the engine if critical vehicle functions are exposed over Bluetooth, even indirectly. The mention of "bank account" suggests a potential pivot from a compromised vehicle or mobile device connected via Bluetooth to accessing sensitive financial data or applications.
While the specifics are not detailed, the general approach involved leveraging the versatility of bug bounty techniques to uncover vulnerabilities across different Bluetooth profiles and applications, demonstrating that even a widely adopted and seemingly mature technology like Bluetooth harbors significant, exploitable weaknesses. The research likely utilized publicly available Bluetooth analysis tools, potentially custom scripts, and a keen eye for unusual behavior or unprotected services.
Demo / Proof of Concept
▶ Watch: Research motivation: secure procurement for Swiss military (6:00)
The talk included a demonstration or proof of concept (PoC) as an integral part of Vladyslav Zubkov's video segment, which contained the technical details of the research. While the provided transcript does not capture the specifics of what was demonstrated or how the exploits were executed, the context strongly implies that the "interesting results" mentioned by Vlad and the "fundamentally insecure" nature of Bluetooth were concretely illustrated through these demonstrations.
Typically, such demonstrations in a live conference setting would involve:
- Scanning and Discovery: Showing how easily vulnerable Bluetooth devices can be identified in an environment.
- Exploitation: Executing a specific attack (e.g., an unauthenticated command, data exfiltration, or a denial-of-service) against a target device, such as an automotive system or a common consumer Bluetooth product.
- Impact Visualization: Clearly showing the consequences of the exploit, whether it's gaining unauthorized control, accessing sensitive information, or disrupting functionality.
Martin Str mentioned the release of a toolkit that is available online for attendees and the wider security community. This toolkit is designed to allow individuals to "check your cars, your Bluetooth products, any of them." The existence of such a toolkit strongly suggests that the demonstrations were based on reproducible methods and tools developed during the research. While the toolkit's name is not explicitly stated in the provided text, its availability via a QR code (linked to a GitHub repository) on the final slide implies it contains the scripts, tools, or methodologies used to identify and potentially exploit the vulnerabilities discussed. Such toolkits often include:
- Bluetooth scanners (e.g., modified
hcitool,bluetoothctl, or custom Python scripts usingpybluezorscapy). - Fuzzing utilities targeting Bluetooth services.
- Exploit modules for specific identified vulnerabilities.
- Analysis scripts to parse Bluetooth traffic or device characteristics.
The purpose of sharing this toolkit is twofold: to enable others to verify the findings and to empower defenders to assess the security posture of their own Bluetooth-enabled devices. The disclaimer that the researchers are "not liable for anything you do with it" is standard practice for releasing security tools, emphasizing their intended use for legitimate security research and auditing. The practical application of this toolkit would likely involve connecting to a target Bluetooth device, enumerating its services, and then attempting to trigger known or newly discovered vulnerabilities through automated or manual means.
Defensive Implications
▶ Watch: Challenges in security procurement due to long life cycles (7:00)
The findings presented in "Exploiting Bluetooth from your car to the bank account" carry significant defensive implications, particularly given the conclusion that Bluetooth is "fundamentally insecure, both the standards and implementations." Defenders must move beyond a superficial understanding of Bluetooth security and adopt a proactive, multi-layered defense strategy.
- Proactive Security in Procurement: For organizations like the Swiss military and federal government, the primary lesson is the critical need for early vulnerability research and security requirement integration into the procurement process. Waiting until systems are deployed for pen testing is too late. Instead, security teams must engage with manufacturers during the pre-tender and tender stages, demanding robust security specifications, independent audits, and proof of secure Bluetooth implementations. This includes specifying minimum Bluetooth versions (e.g., Bluetooth 4.2 LE Secure Connections or Bluetooth 5.0 and newer for stronger encryption), mandatory pairing modes (e.g., Numeric Comparison, Just Works with Out-of-Band for BLE), and strict requirements for input validation and authentication in all Bluetooth-enabled features.
- Comprehensive Bluetooth Asset Inventory and Risk Assessment: Organizations need to identify all Bluetooth-enabled devices within their environment, from corporate laptops and mobile devices to IoT sensors, automotive systems, and specialized equipment. For each device, a detailed risk assessment should be conducted, considering the sensitivity of data transmitted, the criticality of functions controlled, and the potential impact of compromise. This inventory should include the Bluetooth version, supported profiles, and known vulnerabilities associated with the specific hardware and software implementations.
- Harden Bluetooth Configurations:
- Disable Unnecessary Services: Many devices enable Bluetooth services that are not strictly required for their function. Defenders should disable any non-essential Bluetooth profiles or services to reduce the attack surface.
- Secure Pairing: Always use the most secure pairing methods available (e.g., Secure Simple Pairing with Numeric Comparison or Out-of-Band (OOB) for Classic Bluetooth, and LE Secure Connections for BLE). Avoid "Just Works" pairing whenever possible, as it offers no man-in-the-middle protection.
- Strong Authentication: Implement multi-factor authentication for any critical functions accessible via Bluetooth. Ensure that Bluetooth connections are not the sole means of authenticating to sensitive systems.
- Regular Updates: Keep Bluetooth drivers, firmware, and operating systems up to date. Manufacturers frequently release patches for known Bluetooth vulnerabilities (e.g., BlueBorne, BlueFrag, KNOB).
- Physical Security: Limit the physical proximity of Bluetooth devices in sensitive areas, as Bluetooth's range makes it susceptible to attacks from nearby adversaries.
- Network Segmentation and Isolation: Critical systems that use Bluetooth should be logically or physically separated from other sensitive network segments. A compromised Bluetooth connection on an infotainment system, for instance, should not provide a direct pivot into the vehicle's critical control units or the corporate network. Implement strict firewall rules and access controls to limit lateral movement from Bluetooth-connected devices.
- Employee Training and Awareness: Educate employees about the risks associated with Bluetooth. This includes warning against connecting to unknown Bluetooth devices, being wary of unsolicited pairing requests, and understanding the implications of sharing personal data over Bluetooth. Emphasize the importance of secure device configurations and avoiding public Bluetooth connections for sensitive tasks.
- Utilize Security Toolkits: The toolkit released by the researchers serves as a valuable resource. Defenders should leverage such tools to perform internal security assessments and penetration tests on their own Bluetooth-enabled products and infrastructure. This allows for proactive identification of vulnerabilities specific to their deployments before malicious actors exploit them. Regular scanning and auditing of Bluetooth environments should become a standard practice.
- Supply Chain Security: Given the widespread nature of Bluetooth insecurities, organizations must scrutinize their supply chain. This involves requiring vendors to provide evidence of robust security testing for Bluetooth components, disclosing any known vulnerabilities, and committing to timely patch delivery. For automotive systems, this means working closely with car manufacturers to understand the Bluetooth implementation details and their associated risks.
By adopting these defensive strategies, organizations can significantly mitigate the risks posed by the fundamental insecurities within Bluetooth, moving towards a more resilient security posture in an increasingly connected world.
Key Takeaways
- Pervasive Bluetooth Insecurity: Bluetooth technology, across both its underlying standards and real-world implementations, harbors fundamental and widespread security vulnerabilities.
- Proactive Procurement is Essential: For critical infrastructure and government systems, security must be integrated into the procurement process from the earliest stages (pre-tender) rather than relying on post-deployment testing.
- Bug Bounty Methodology's Effectiveness: Applying a generalist bug bounty hunting approach can effectively uncover significant vulnerabilities even in seemingly mature and previously un-audited technologies like Bluetooth in automotive systems.
- Significant Real-World Impact: The vulnerabilities discussed have the potential for severe consequences, ranging from compromising vehicle systems to potentially impacting financial data, as implied by the talk's title.
- Toolkit for Defenders: A dedicated toolkit has been released to enable security professionals and users to assess the Bluetooth security of their own devices and vehicles.
- Continuous Vigilance Required: Defenders must maintain an up-to-date inventory of Bluetooth assets, implement secure configurations, perform regular updates, and educate users on Bluetooth risks to mitigate the ongoing threat.
About the Speaker(s)
Vladyslav Zubkov (YSO and Schwytz) is a highly accomplished bug bounty hunter with a primary focus on web, mobile, and infrastructure pen testing. He also has a strong background in code reviews and the development of security tools and frameworks. Vladyslav is actively seeking new opportunities, holds additional certifications and awards, and possesses a master's degree. A crucial aspect of his contribution to this research is that, despite his extensive cybersecurity experience, he had never attacked Bluetooth or cars before. This fresh perspective, combined with his expertise in applying generalized bug bounty hunting techniques, allowed him to uncover significant and "interesting results" in this new domain.
Martin Str is a distinguished security researcher and scientist at the Swiss Cyber Defense Campus, which serves as the procurement agency for the Swiss military. He possesses a robust background in wireless security and has published his research in numerous major academic systems security conferences. Martin leads research efforts not only on cars but across various facets of transportation security, including aviation (having previously presented at the Aerospace Village), space, and trains. While he has extensive experience in car security, notably through his work on hacking electric charging processes at brokenwire.fail, he, like Vladyslav, had never specifically focused on Bluetooth prior to this research. His role in the Swiss Cyber Defense Campus underscores the practical, mission-driven motivation behind investigating such vulnerabilities to ensure secure systems for the federal government and military.