Two DEF CON 34 talks took apart keyless entry, from rolling codes to relay tools
Two Car Hacking Village sessions on August 9 described cloning a fob from a brute-forced rolling code, and operating a commercially available relay attack tool against a car.
Two Car Hacking Village sessions at DEF CON 34 on the morning of August 9 addressed remote keyless entry from opposite directions.
In the first, Danilo Erazo described reverse engineering an aftermarket rolling-code system that the published abstract said had long been trusted to protect against key fob cloning and unauthorized access. The talk set out the protocol’s frame format and cryptographic design, and combined a rollback vulnerability with a brute-force attack on the rolling code to recover valid codes and clone a legitimate fob. The abstract said the research resulted in three CVEs assigned in 2026 and affects products deployed across multiple markets.
The second, from Robbie Galfrin, dealt with passive keyless entry and start, in which vehicle and key exchange a challenge and response automatically whenever the two are close together. Galfrin described sourcing and operating a commercially available relay attack tool, showed a video of the attack carried out against a vehicle, and set out how the tool relays the signal across distance to defeat the assumption that proximity means legitimacy. The session closed on mitigation strategies.
Both ran on DEF CON’s Creator Stage 1 rather than inside the village itself. The abstracts published by the village are the only detailed record of either talk that SDV Sector could locate; no slides or paper had been posted for either at the time of writing.
Source: Car Hacking Village, DEF CON 34 program. Both sessions also appear on DEF CON’s Creator Stage schedule.