Vulnerability Alert: 2.2 Million Cars at Risk from Bluetooth Anti-Theft Systems
A recent study reveals that over 2 million cars equipped with Bluetooth anti-theft systems are vulnerable to remote hacking, raising concerns for car owners and manufacturers alike.

The automotive landscape is rapidly evolving, with advanced technology integrated into vehicles to enhance security and convenience. However, a recent study from the University of California San Diego has unveiled a troubling vulnerability affecting over 2.2 million cars equipped with Bluetooth-based anti-theft systems. This significant finding raises alarms among car owners and the automotive industry, shedding light on the potential risks associated with these seemingly beneficial devices.
At the core of the vulnerability are devices installed by dealerships, which allow remote locking and unlocking of vehicle doors, as well as immobilizing engines through a smartphone app. Unfortunately, this innovation has a dark side, as cybercriminals can exploit the very technology designed to protect vehicles. The implications of this vulnerability are far-reaching, affecting not just car owners, but also dealerships and manufacturers who must address the security lapses in their products.
Understanding the Vulnerability
The study highlights that the vulnerable vehicles, primarily purchased from Honda, Toyota, Mazda, Ford, and Jeep dealerships in Southern California between 2017 and 2026, are susceptible to remote attacks via Bluetooth connections. Thieves can compromise these vehicles from as far as five yards away, allowing them to unlock doors and immobilize engines without any physical interaction. The KARR and SWDS devices, which are often marketed as anti-theft upgrades, have a common flaw: they use a single secure key across multiple units. This means that if the key is cracked, all connected vehicles become easy targets.
To put this risk into perspective, imagine a thief standing just outside a parking lot, using a smartphone to unlock a car's door. Once inside, they can start the engine using tools readily available to locksmiths. This method is less conspicuous than traditional car theft methods, such as breaking windows, making it particularly concerning for car owners.

The Scope of the Issue
As the study reveals, at least 1.4 million vehicles were initially identified as vulnerable, but subsequent analysis pushed this figure to an estimated 2.2 million. This number could include several hundred thousand cars that have been resold on the second-hand market, expanding the risk to numerous unsuspecting owners across the United States, Canada, and even Japan. Vehicles displaying a sticker with the words “KARR” or “SWDS” on the driver’s-side window are particularly at risk.
Researchers from UC San Diego have shared their findings in anticipation of upcoming presentations at the DEF CON and USENIX Security conferences. Their work underscores the need for car manufacturers and dealerships to be proactive in addressing these vulnerabilities before they lead to widespread thefts.
Who is Affected?
The implications of this vulnerability extend beyond individual car owners. Dealerships that install these Bluetooth anti-theft systems may face liability issues if vehicles equipped with these devices are stolen due to their negligence in providing secure technology. More broadly, the automotive industry must grapple with the reputational damage that could result from widespread thefts linked to their products.
- Car Owners: Those who own vehicles equipped with vulnerable systems need to be aware of their risks and take steps to protect their investments.
- Dealerships: Dealerships that sell these vehicles may face backlash from customers and could be held accountable for failing to adequately inform buyers about potential vulnerabilities.
- Automotive Manufacturers: Companies like Acrisure and Rockledge, which produce these devices, must act swiftly to enhance security measures and mitigate risks.

Addressing the Vulnerability
Fortunately, the company behind the KARR and SWDS devices, Acrisure, has released a firmware update to address the security flaw. This update, which was made available on July 20, 2026, requires vehicle owners to download the latest version of the KARR app. However, many car owners remain unaware of their vehicle's vulnerability, emphasizing the need for widespread communication and education surrounding the issue.
For those who own affected vehicles, the best course of action is to download the firmware update as soon as possible. Additionally, the researchers recommend incorporating a physical interaction, such as pressing a button within the car, when a new smartphone connects to Bluetooth-based security systems. This added layer of security would help prevent unauthorized access from potential thieves.
The Journey to Discovery
The discovery of this vulnerability traces back to 2018 when researchers first encountered unknown Bluetooth fingerprints while investigating credit card skimmers. Their investigation led them to the devices manufactured by Acrisure and Rockledge, prompting them to assess the security of these systems. Interestingly, they also found that public databases could expose location information about vehicles equipped with these devices, allowing attackers to track specific targets for theft.
This research was supported in part by a grant from the National Science Foundation and highlights the ongoing need for vigilance in the realm of cybersecurity, particularly as it applies to the automotive industry.

Key Takeaways
- Over 2.2 million cars equipped with Bluetooth anti-theft systems are at risk of remote theft.
- Vulnerable vehicles can be unlocked and immobilized from up to five yards away.
- A firmware update is available to fix the vulnerability; vehicle owners should act immediately.
- Dealerships and manufacturers need to prioritize vehicle security to protect their customers.
Frequently Asked Questions
How can I tell if my vehicle is affected by this vulnerability?
If your vehicle was purchased from a dealership that installs KARR or SWDS devices and displays a sticker on the driver’s-side window, it may be vulnerable. To confirm, check with your dealership or refer to the manufacturer's website for guidance on identifying affected models.
What should I do if I own a vulnerable vehicle?
Immediate action is recommended. Download the latest firmware update from the KARR app to secure your vehicle against potential theft. Additionally, consider reaching out to your dealership for further advice on enhancing your vehicle's security.
Are there other anti-theft systems that may be vulnerable?
Yes, the researchers also identified that devices produced by Rockledge may have similar vulnerabilities, though they are more difficult to exploit. These devices require an attacker to intercept and replay digital interactions, making them less accessible than the KARR and SWDS systems.
What steps are manufacturers taking to improve vehicle security?
Manufacturers are being urged to incorporate stronger security measures in their products, including requiring physical interactions for Bluetooth connections. As awareness of these vulnerabilities grows, it is expected that the industry will respond by implementing more robust safety protocols to protect consumers.
Comments
Court Ruling: Driver Misrepresentation Nullifies Coverage, Impacts Victims
A New York appeals court ruled that misrepresentations on an auto insurance application can void coverage, affecting innocent crash victims. This decision raises important questions about consumer protections in auto insurance policies.

Related articles
Popular in Car Insurance
- Consumer Sues GEICO and LexisNexis Over Identity Theft Claims Data Error
- Addressing Self-Driving Cars' Interference with Emergency Services
- Florida Court Reverses PIP Ruling, Favoring State Farm in Key Dispute
- Honda Recalls 325,588 Odyssey Vehicles Due to Rearview Camera Issues
- Honda Insurance Solutions Pauses Operations: What This Means for Consumers
