Mass Scale Hijacking Threatens Rentable IoT
Tsinghua's Black Hat Asia 2026 demo showed how weak IDs and shared keys let attackers disable EV chargers citywide from an app.
8 min read

Visual TL;DR
Public devices trigger physical actions like unlock and start-charge on backend command
From the article 3 mentionsTsinghua University hardware researcher Hu Tian Shu, who goes by Mori Shu, showed how rentable IoT systems for shared bikes, scooters and EV chargers can be hijacked remotely at city scale.
Backend cannot tell real devices from spoofed ones, enabling forged unlock commands
From the articleThe team re-implements the device protocol in Python and reuses recovered credentials to build phantom clients.
Short numeric device identifiers are predictable and reused across the entire fleet
Single vulnerability replicates across every device sharing the same ID scheme
From the articleBlackHat Asia 2026 brought a blunt warning on Mass Scale Hijacking.
Tsinghua demo at Black Hat Asia 2026 cut power to shared chargers from an app
From the articleHu selected Shanghai near People's Square in a Chinese charging provider's app, copied an available charger's ID into a script, and its map icon flipped from green to gray, indicating a disabled port.
Public devices trigger physical actions like unlock and start-charge on backend command
From the article 3 mentionsTsinghua University hardware researcher Hu Tian Shu, who goes by Mori Shu, showed how rentable IoT systems for shared bikes, scooters and EV chargers can be hijacked remotely at city scale.
Short numeric device identifiers are predictable and reused across the entire fleet
Hardcoded keys and shared secrets in apps let attackers impersonate legitimate clients
From the articleHu's team found exposed debug interfaces, extractable firmware, recoverable network traces and shared authentication keys hardcoded in firmware.
Backend cannot tell real devices from spoofed ones, enabling forged unlock commands
From the articleThe team re-implements the device protocol in Python and reuses recovered credentials to build phantom clients.
Single vulnerability replicates across every device sharing the same ID scheme
From the articleBlackHat Asia 2026 brought a blunt warning on Mass Scale Hijacking.
Tsinghua demo at Black Hat Asia 2026 cut power to shared chargers from an app
From the articleHu selected Shanghai near People's Square in a Chinese charging provider's app, copied an available charger's ID into a script, and its map icon flipped from green to gray, indicating a disabled port.
From the article 9+ mentionsThe work covers 17 physical devices and 92 related mobile apps and mini apps, including 81 Chinese Android and WeChat mini programs plus 11 European iOS apps.
Bikes, scooters, and EV operators face mass-scale service disruption from one bug
Contents(6)
© 2026 StartupHub.ai. All rights reserved. Do not enter, scrape, copy, reproduce, or republish this article in whole or in part. Use as input to AI training, fine-tuning, retrieval-augmented generation, or any machine-learning system is prohibited without written license. Substantially-similar derivative works will be pursued to the fullest extent of applicable copyright, database, and computer-misuse laws. See our terms.