Security researchers reported serious Bluetooth security weaknesses in personal mobility devices that allow unauthorized control at close range. An Estonian researcher reverse-engineered Äike’s app-controlled e-scooters after the company’s bankruptcy and alleged the scooters shipped with a single default/private “master” key rather than unique per-device secrets, enabling anyone who derives the key to generate valid challenge-response authentication and unlock/control any scooter model the company sold.
Separately, researchers demonstrated remote control of WHILL wheelchairs over Bluetooth, prompting a CISA advisory stating the devices did not enforce authentication for Bluetooth connections. An attacker within Bluetooth range could pair without credentials or user interaction and then control movement, override speed restrictions, and alter configuration profiles—highlighting a broader risk pattern where weak or missing Bluetooth authentication in mobility/IoT products can translate directly into physical safety impacts.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Moorats reported the e-scooter key-management problem to the hardware supplier, which replied that managing the cryptographic keys was the manufacturer's responsibility. With Äike bankrupt, the report indicated there was no clear remediation path for affected scooter owners.
After Äike's bankruptcy left scooters dependent on failing backend services, researcher Rasmus Moorats reverse-engineered the Android app and Bluetooth traffic and found that scooters appeared to use the same placeholder/default private key rather than unique per-device secrets. He demonstrated that a short proof-of-concept could unlock any Äike scooter within Bluetooth range.
CISA issued an advisory for certain WHILL wheelchairs stating they did not enforce authentication for Bluetooth connections. An attacker within Bluetooth range could pair without credentials or user interaction and then control movement, override speed restrictions, and alter configuration profiles.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.