Hackers get $886,250 for 49 zero-days at Pwn2Own Automotive 2025
bleepingcomputer.com
bleepingcomputer.com
We really should be funding exploit teams to break everything they can so that we have secure infrastructure.
> Two months later, during the Pwn2Own Vancouver 2024 competition, ZDI awarded another $1,132,500 for 29 zero-day bugs. Synacktiv went home with $200,000 and a Tesla Model 3 after hacking its ECU with Vehicle (VEH) CAN BUS Control in under 30 seconds.
If they offered 20x the price there would likely be so many reported defects that they would go out of business.
You can not “patch and fix” your way to a materially higher level of security “quality” or buy your way to zero defects. Offering prices significantly higher than your security “quality” just gets you a endless stream of reports for real defects.
To put it another way, a bug bounty program is not a mechanism for achieving higher quality, it is a mechanism for public security auditing. It is set at a level where it should almost never trip and should be viewed, publicly, as a initial estimate of security “quality”. A company offering a bounty of X should be viewed as saying: “We are confident that our security is no better than X worth of effort”. That should tell you everything you need to know about the “quality” of these systems.
Not that all, or even most, people with those skills would abuse them. But it doesn't take that many, and things might be worse if you start attracting people with insanely big sums.
There are plenty of security consultants and penetration testing houses out there getting paid already.
Turns out people put a lot of value on not having to launder black market earnings or deal with opsec of hiding their participation.
Companies could choose to outbid the black market on every single one of them if they wanted to, they just don't.
I think this analogy would only fit if the hackers could somehow "breed" bugs, but as they don't work at the corporations making the buggy software I don't see how that would be possible — but then, I'm British by birth, so perhaps I have a blind spot for creating perverse incentives ;)
I hope these security efforts don't lock legitimate owners out of access to their vehicles.
Well that's the thing with cars. Anything the legitimate owner can do because they have physical access, a thief can also do... and even if you force manufacturers to provide a "rooting mode" aka you enter some PIN that you get at purchase into the car's infotainment and it will relax restrictions on the CAN bus, now you open up the gates for thieves as well.
And on top of that come the actual reasons for the security theatre: people modifying their ECUs to tune up their engines for higher power or speed limiters in trucks than is stated in the vehicle papers (at least in Europe, if you tune your vehicle and don't have the papers updated you're in legit felony territory), doing shit mods like "rolling coal" or otherwise tampering with emission controls (say to avoid having to refill adblue)... governments really REALLY do not like this and so regulations get tightened ever closer.
All it takes to pwn a Volkswagen T4 from the mid-90s is to rake the lock, pry open or smash the door, and then about half a minute to hot-wire three pins on the ignition switch (one for the main power and one for the starter motor), although I think that you should be able to motor-rake the ignition switch as well.
Source: owned and heavily worked on one for a few years. Reliable as fuck but thank god Europe doesn't have much of a "joyride" scene.
And column shifters still exist- hell, even the Tesla Model 3 has one- so any gen z kid who knows how a manual transmission works can shift it into gear.
Sure, a few folks get paid out but probably plenty of participants walked away with nothing after 3 days/72 hrs.
So the prizes were paid in cars?
They were thoroughly compromised and even card swaps generally didn’t last long.
I’m not even convinced the latest card swaps actually “fixed” the problem, but rather home internet speeds and streaming caught up and it was easier to p2p pirate or gasp pay!