Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

IoT Security

Pwn2Own Automotive: Hackers Earn Over $700k for Tesla, EV Charger, Infotainment Exploits

On the first day of Pwn2Own Automotive participants earned over $700,000 for hacking Tesla, EV chargers and infotainment systems.

Pwn2Own Automotive

On the first day of the Pwn2Own Automotive hacking contest, participants earned over $700,000 for hacking a Tesla, electric vehicle chargers and infotainment systems.

Trend Micro’s Zero Day Initiative (ZDI), the organizer of the event taking place January 24-26 alongside the Automotive World conference in Tokyo, Japan, said it awarded a total of $722,500 for 24 unique exploits on the first day.

The biggest reward went to the Synacktiv team, which earned $100,000 for hacking the Tesla modem. The same team earned an additional $195,000 for exploits targeting Ubiquiti Connect, ChargePoint Home Flex, JuiceBox 40 and Autel MaxiCharger EV charging stations.

Rewards of $60,000 were earned for two charger exploits, by Sina Kheirkhah for a ChargePoint Home Flex hack, and RET2 Systems for a Phoenix Contact CHARX SEC-3100 hack. Another charger exploit, targeting the Phoenix Contact product, earned the NCC Group team $30,000.

Rob Blakely from Cromulence earned $47,500 for an Automotive Grade Linux exploit in the operating system category. The amount would have been higher, but one of the vulnerabilities he exploited had already been known.

Rewards of $40,000 each were earned for Alpine Halo9 iLX-F509, Pioneer DMH-WT7600NEX and Sony XAV-AX5500 exploits in the infotainment system category. Four other infotainment system hacks earned Pwn2Own Automotive participants $20,000 each. 

Advertisement. Scroll to continue reading.

Several ChargePoint exploits that involved previously known flaws earned participants $16,000 each. 

A majority of the hacking attempts scheduled for the two remaining days of Pwn2Own will target chargers and infotainment systems, but there will be one more attempt to target a Tesla, specifically its infotainment system with an exploit that involves a sandbox escape. 

This is the first edition of the automotive-focused Pwn2Own. ZDI shared some interesting details about the event with SecurityWeek in October. 

Related: VMware Patches Critical Vulnerability Disclosed at Pwn2Own Hacking Contest

Related: Hackers Earn $180,000 for ICS Exploits at Pwn2Own Miami 2023

Related: Over $1 Million Offered at New Pwn2Own Automotive Hacking Contest

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

James Phillips has been promoted to the role of Vice President, Cybersecurity Risk Management at AT&T.

Rafal Los has joined Binary Defense as Chief Strategy Officer.

Tracey Mustacchio has joined Everfox as Chief Marketing Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.