Attackers compromised Bluetooth-enabled pedestrian crosswalk buttons in multiple US cities, replacing standard walk prompts with unauthorized political and celebrity-impersonation audio. Roughly 20 intersections in Silicon Valley, including Menlo Park, Redwood City, and Palo Alto, were affected, while similar incidents were later reported in Seattle and Denver. In Denver, two newly installed crosswalks were altered to broadcast anti-Trump messages instead of normal pedestrian instructions.
Reporting indicates the intrusions were enabled by weak or factory-default credentials on Polara Enterprises devices, including the widely cited default password 1234, combined with a publicly available configuration app. City officials in Denver changed passwords after the incident and police opened investigations, but authorities in other cases were unable to identify the perpetrator because the devices did not log audio uploads and surveillance footage provided little value. The incidents have intensified scrutiny of cybersecurity requirements for public infrastructure used by visually impaired pedestrians and exposed gaps in municipal oversight of connected safety systems.

Map this exposure pattern across your cloud, code, and identities.
5 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting and expert analysis indicated the attacker likely exploited weak default passwords, including '1234,' together with a publicly available configuration app used for Polara Enterprises crosswalk buttons. The disclosures also highlighted missing logging and weak municipal cybersecurity requirements around the devices.
After the Silicon Valley incidents, similar concerns reached Seattle and Denver as officials examined whether comparable pedestrian crossing devices had been compromised. The cases were reported as part of the same broader pattern of abuse involving insecure crosswalk audio systems.
In April 2026, an attacker altered Bluetooth-enabled pedestrian crosswalk buttons at roughly 20 intersections in Menlo Park, Redwood City, and Palo Alto. Standard walk prompts were replaced with spoofed recordings imitating Mark Zuckerberg and Elon Musk.
Following the Denver incident, city officials changed the passwords on the affected crosswalk devices and police opened an investigation. The response focused on unauthorized access enabled by default credentials.
Two pedestrian crosswalks in Denver, Colorado, were reportedly compromised and made to play a political message instead of standard walk instructions. The affected devices were described as newly installed and still using factory-default credentials when accessed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.