Cybersecurity

Coin-Sized Device Hacks Boeing 737 Autopilot in 60 Seconds

Published Aug 12, 2026, 12:17 PM2 min readNewUJ Editorial Desk

Coin-Sized Device Hacks Boeing 737 Autopilot in 60 Seconds
Photo: Shahadat Rahman · Unsplash
0 0
XWhatsAppTelegramLinkedIn

On August 13, 2026, researchers from the University of California, San Diego and Oberlin College will present at the Usenix Cybersecurity Conference a hacking technique that can commandeer a Boeing 737’s autopilot using a coin-sized, Wi-Fi-enabled device.

The device, built for under $100, can be installed in under a minute through an externally accessible port on the plane. Once connected, it sends electrical signals on the plane’s internal network to spoof commands to the Flight Management Computer and Multipurpose Control Display Unit.

This allows an attacker to redirect the autopilot’s navigation or falsify variables like weight and outside air temperature, while hiding the changes from the pilot’s screen. Such false data could cause a runway overrun during takeoff or divert a flight into another country’s airspace, potentially leading to a crash.

The research, led by UCSD professors Stefan Savage and Aaron Schulman, began over a decade ago. The team bought tens of thousands of dollars’ worth of secondhand 737 components to build an avionics test bed called Triton, assembled by 2019. Student Sam Crowe later found a specific port—protected only by an unlocked hatch—that connects to a critical data bus. By sending higher-current electrical signals, Crowe could override legitimate commands, a technique dubbed “Bus Driver.”

Boeing was first alerted in spring 2020 and worked with the researchers, even allowing testing in its lab. However, Boeing’s statement to WIRED downplayed the risk, saying its layers of protection “provide sufficient mitigation to significantly limit the feasibility and risk of real-world attacks.” The researchers say Boeing has not disclosed any technical fix, and they speculate updates may not come for years due to infrequent aircraft redesigns.

The researchers suggest immediate fixes like plugging the port with epoxy or removing it, and long-term solutions such as software defenses, electrical isolation, or cryptographic authentication. They emphasize they will continue flying on 737s and do not call for grounding planes, but stress the need for improved operational security.

Cybersecurity consultant Beau Woods, who reviewed the work and serves as an adviser to the Cybersecurity and Infrastructure Security Agency and a member of Boeing’s Industry Cyber Technical Council, said the paper provides “solid empirical evidence about some realistic scenarios for high-capability adversaries.” Woods added that threat models must evolve with advancing technology.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.