Coin-Sized Device Hacks Boeing 737 Autopilot in 60 Seconds
On August 13, 2026, researchers from the University of California, San Diego and Oberlin College will present at the Usenix Cybersecurity Conference a hacking technique that can commandeer a Boeing 737’s autopilot using a coin-sized, Wi-Fi-enabled device.
The device, built for under $100, can be installed in under a minute through an externally accessible port on the plane. Once connected, it sends electrical signals on the plane’s internal network to spoof commands to the Flight Management Computer and Multipurpose Control Display Unit.
This allows an attacker to redirect the autopilot’s navigation or falsify variables like weight and outside air temperature, while hiding the changes from the pilot’s screen. Such false data could cause a runway overrun during takeoff or divert a flight into another country’s airspace, potentially leading to a crash.
The research, led by UCSD professors Stefan Savage and Aaron Schulman, began over a decade ago. The team bought tens of thousands of dollars’ worth of secondhand 737 components to build an avionics test bed called Triton, assembled by 2019. Student Sam Crowe later found a specific port—protected only by an unlocked hatch—that connects to a critical data bus. By sending higher-current electrical signals, Crowe could override legitimate commands, a technique dubbed “Bus Driver.”
Boeing was first alerted in spring 2020 and worked with the researchers, even allowing testing in its lab. However, Boeing’s statement to WIRED downplayed the risk, saying its layers of protection “provide sufficient mitigation to significantly limit the feasibility and risk of real-world attacks.” The researchers say Boeing has not disclosed any technical fix, and they speculate updates may not come for years due to infrequent aircraft redesigns.
The researchers suggest immediate fixes like plugging the port with epoxy or removing it, and long-term solutions such as software defenses, electrical isolation, or cryptographic authentication. They emphasize they will continue flying on 737s and do not call for grounding planes, but stress the need for improved operational security.
Cybersecurity consultant Beau Woods, who reviewed the work and serves as an adviser to the Cybersecurity and Infrastructure Security Agency and a member of Boeing’s Industry Cyber Technical Council, said the paper provides “solid empirical evidence about some realistic scenarios for high-capability adversaries.” Woods added that threat models must evolve with advancing technology.
Sources
- WiredSecondary
Related
Uber Freight probes data breach claim by Helix hackers
Researcher defies Microsoft, releases Windows zero-day ShieldBreak
Zoom flaws let attackers hijack devices via screen sharing
Hackers vishing financial firm staff to extort victims, Google says
LightSpy spyware targets victims in 13 countries, including US
Hacker pleads guilty to stealing data from 165+ Snowflake customers
Hackers target 30 US water systems via exposed controllers
Meta AI model hacks outside system during cybersecurity test
Trending now
- US inflation eases to 3.4% as food costs cool
- CPI rises 0.1% in July, annual inflation at 3.4%
- Fungus kills African armyworm, offering hope to farmers
- Uber Freight probes data breach claim by Helix hackers
- Google Pixel 11 starts at $899 with doubled storage
- Tesla plans $10B solar factory in Texas
- Hydrogen car breaks land speed record at 406 mph
- NASA Astronaut Mike Fincke Departs After 30 Years, 549 Days in Space
Comments
No comments yet. Be the first.