BLERP Attacks Break BLE Re-Pairing at Scale
BLERP attacks exploit six BLE re-pairing flaws to overwrite pairing keys and hijack 22 of 22 tested devices, with no spec fix since 2024.
7 min read

Visual TL;DR
Researchers at EURECOM found six protocol flaws in Bluetooth Low Energy re-pairing
From the article 2 mentionsResearchers Tommaso Sacchetti and Daniele Antonioli of EURECOM demonstrated re-pairing flaws that let any nearby attacker overwrite the pairing key.
Overwrite pairing keys by tricking already paired devices into running pairing again
From the article 2 mentionsBlackHat Asia 2026 showed how BLERP attacks turn a forgotten BLE feature into a universal bypass.
Attackers overwrite the long term key PK1 without authentication on nearby devices
From the article 4 mentionsRe-pairing lets two already-paired devices run pairing again and replace that key with PK1.
Every tested phone, laptop, mouse, watch, car, and medical device fell to the demo
From the article 5 mentionsIt is in billions of phones, laptops, mice, watches, cars and medical devices.
Researchers at EURECOM found six protocol flaws in Bluetooth Low Energy re-pairing
From the article 2 mentionsResearchers Tommaso Sacchetti and Daniele Antonioli of EURECOM demonstrated re-pairing flaws that let any nearby attacker overwrite the pairing key.
Bluetooth core 6.2 is 3,000+ pages and mentions re-pairing only four times
From the articleThe spec treats re-pairing as just a new pairing.
Sacchetti and Antonioli showed BLERP bypassing security on billions of BLE devices
From the articleBlackHat Asia 2026 showed how BLERP attacks turn a forgotten BLE feature into a universal bypass.
Four new flaws enable unauthenticated central, peripheral, and downgrade attacks on re-pairing
Overwrite pairing keys by tricking already paired devices into running pairing again
From the article 2 mentionsBlackHat Asia 2026 showed how BLERP attacks turn a forgotten BLE feature into a universal bypass.
Attackers overwrite the long term key PK1 without authentication on nearby devices
From the article 4 mentionsRe-pairing lets two already-paired devices run pairing again and replace that key with PK1.
Every tested phone, laptop, mouse, watch, car, and medical device fell to the demo
From the article 5 mentionsIt is in billions of phones, laptops, mice, watches, cars and medical devices.
No spec fix shipped since 2024 despite coordinated disclosure with manufacturers
Contents(8)
© 2026 StartupHub.ai. All rights reserved. Do not enter, scrape, copy, reproduce, or republish this article in whole or in part. Use as input to AI training, fine-tuning, retrieval-augmented generation, or any machine-learning system is prohibited without written license. Substantially-similar derivative works will be pursued to the fullest extent of applicable copyright, database, and computer-misuse laws. See our terms.