Abdolmadjid Masoomi

Keyless Car Theft: Relay Attacks and What Actually Stops Them

A signal-blocking pouch works only on the nights you remember it; layers the relay cannot reach work every night.

Signed
Abdolmadjid Masoomi
Published
2026-09-14
Length
9 min read · 1,951 words
Status
opinion

A keyless car theft relay attack does not break cryptography; it lies about distance. Habit-based defences like pouches fail when forgotten. Robust security requires removing the signal by default or adding physical barriers the relay cannot carry.

Most modern vehicles use passive keyless entry systems that allow drivers to unlock and start their cars without removing the key fob from a pocket or bag. The system relies on short-range radio signals to confirm the fob is near the vehicle. This convenience introduces a specific class of vulnerability where the distance between the key and the car is artificially extended.

A keyless car theft relay attack exploits this proximity check by amplifying the signal between the key inside a home and the car parked outside. The thieves do not need to break the cryptographic protocol. They simply stretch the communication range so the car believes the authorised key is right beside the door. The car then unlocks and allows the engine to start.

This mechanism is straightforward and effective against systems that rely solely on signal presence. It highlights a fundamental trade-off in security design. Convenience often reduces the friction of authentication, but it also expands the attack surface for physical interception. Defending against this requires understanding that signal amplification is a physical layer problem, not a digital one.

How a relay attack tricks the car about distance

The attack operates by intercepting and repeating radio frequency signals. One device, held by a thief near the car, listens for the authentication challenge sent by the vehicle. Another device, held by an accomplice near the key fob inside a house, receives this challenge and forwards it to the first device. The first device then sends the challenge to the fob.

The fob responds to the challenge as if it were next to the car. This response is captured by the second device and relayed back to the first. The first device transmits the response to the car. The car receives a valid cryptographic response and assumes the key is within range. The system does not measure the time of flight accurately enough to detect the delay introduced by the relay devices.

This process relies on the car trusting the signal strength or timing as a proxy for distance. Modern implementations attempt to mitigate this by measuring the round-trip time of signals. However, many existing vehicles on the road lack this countermeasure. The vulnerability exists because the system prioritises seamless user experience over rigorous distance verification.

Understanding the physical nature of this threat is essential. It is not a hack of the software running on the car. It is an interception of the wireless link. For a deeper look at how physical layers interact with digital security, see understanding physical attack vectors. The car is effectively tricked into believing a remote object is in its immediate vicinity.

Why the car's encryption does not help

Encryption ensures that the communication between the key fob and the car cannot be read or replayed by a third party who simply records the signal. It prevents a simple replay attack where a thief records the unlock signal and plays it back later. However, encryption does not prevent the signal from being amplified and forwarded in real-time.

The cryptographic protocol verifies the identity of the key. It does not inherently verify the physical location of the key. As long as the response is mathematically correct, the car accepts it. The relay attack preserves the integrity and authenticity of the message while altering the context in which it is received. The car sees a valid key, but the key is not where it thinks it is.

This distinction is critical for defence strategies. Adding stronger encryption to the protocol will not stop a relay attack. The attack succeeds because the protocol lacks a robust distance-bounding mechanism. Many vehicles rely on signal strength indicators, which are easily manipulated by amplifiers. Others rely on timing, which can be bypassed with low-latency relay hardware.

The security model assumes that if the key is authenticated, it is close. This assumption is flawed in environments where radio signals can be extended. The vulnerability lies in the protocol design, not the strength of the cipher. Addressing this requires changes to how distance is verified, not just how identity is confirmed. For more on the broader context of these issues, read security vulnerabilities in connected cars.

Pouches and boxes: effective, and dependent on habit

Faraday pouches and signal-blocking boxes are designed to block radio frequency signals. They create a shield that prevents the key fob from transmitting or receiving signals. If the key is inside such a pouch, the relay devices cannot intercept the challenge or the response. The attack fails because there is no signal to amplify.

These devices are technically effective. They work reliably when the key is placed inside them. The physics of signal attenuation in conductive materials is well understood. A properly constructed Faraday cage will block the frequencies used by most key fobs. This makes them a practical defence for many owners.

However, their effectiveness is entirely dependent on user behaviour. The pouch only works if the owner remembers to use it every night. It fails on the one night when the key is left on a kitchen counter or in a jacket pocket. Human memory is fallible, and security systems that rely on perfect compliance are inherently weak. A single lapse in habit renders the defence useless.

This dependency on habit is the primary weakness of passive shielding. It shifts the burden of security from the system to the user. For many, this is an acceptable trade-off for the simplicity of the solution. For others, it is an unacceptable risk. The choice depends on the owner's willingness to maintain a strict routine. It is a defence that works only when you remember it.

Fob settings and newer keys that switch off when still

Some manufacturers have introduced features that reduce the attack surface by limiting signal transmission. One common approach is a sleep mode that activates after a period of inactivity. The key fob stops broadcasting its presence or responding to challenges after a set time. This reduces the window of opportunity for a relay attack.

Other newer key designs incorporate motion sensors. The fob only transmits when it detects movement. If the key is sitting still in a pocket or on a table, it remains silent. This makes it difficult for a relay device to establish a connection. The attacker must physically move the key to trigger the signal, which is often impractical during a stealthy theft attempt.

These features represent a shift in design philosophy. They prioritise security by default rather than requiring user intervention. The system actively reduces its visibility to potential attackers. This is a more robust approach than relying on the user to place the key in a shielded container.

However, not all vehicles support these features. Older models and some budget brands may lack motion sensors or configurable sleep timers. Owners should check their vehicle's manual or infotainment settings to see if such options are available. Enabling these settings can significantly raise the bar for attackers. It removes the easy target that a constantly listening fob presents. For strategies on building systems that assume compromise, see defenses against signal relay attacks.

Barriers the relay cannot carry

Physical locks provide a defence that radio signals cannot bypass. A steering wheel lock or a pedal lock is a visible deterrent and a physical barrier. Even if the thieves unlock the car and start the engine, they cannot drive away with the steering locked. This adds a layer of security that is independent of the electronic system.

These devices are effective because they address the outcome of the theft, not just the entry. They force the thieves to spend more time and effort to steal the car. This increases the risk of detection. Many thieves prefer quick, easy targets and will move on if they encounter a physical lock.

The presence of a physical lock also serves as a psychological deterrent. Thieves can see the device from the outside. They know that even if they bypass the electronic security, they will not get far. This can discourage them from attempting the attack in the first place.

Physical locks are not a substitute for electronic security, but they complement it well. They provide a defence in depth. If the electronic system is compromised, the physical lock remains. This layered approach ensures that no single point of failure leads to the loss of the vehicle. It is a simple, low-tech solution that remains highly effective against modern digital threats.

What to check before buying a keyless car

Prospective buyers should investigate the security features of a vehicle before purchasing. Not all keyless entry systems are created equal. Some use advanced distance-bounding protocols that measure the time of flight of signals. These are much harder to relay than systems that rely on signal strength.

Check if the key fob has a motion sensor or a configurable sleep mode. These features significantly reduce the risk of relay attacks. Vehicles that allow the owner to disable the key fob's wireless transmission via the car's settings are preferable. This gives the owner control over the attack surface.

Research the specific model's vulnerability to relay attacks. Some manufacturers have issued recalls or software updates to address known weaknesses. Look for reviews or technical analyses that discuss the security of the keyless system. Avoid vehicles that rely solely on simple signal amplification without any countermeasures.

Consider the long-term security of the vehicle. A car is a long-term asset. Its security features should remain effective over many years. Vehicles that receive regular software updates to patch security flaws are better investments. This ensures that new threats can be mitigated without replacing the hardware.

Questions people ask

How do relay attacks on cars work?

Relay attacks work by amplifying the radio signal between a key fob and a car. One device near the car receives the challenge signal and forwards it to another device near the key. The key responds, and the response is relayed back to the car. The car receives a valid response and unlocks, believing the key is nearby.

Do Faraday pouches stop car theft?

Faraday pouches stop relay attacks by blocking the radio signals from the key fob. If the key is inside a properly shielded pouch, the signal cannot reach the relay devices. This prevents the car from receiving the authentication signal. However, they only work if the owner consistently uses them.

Can keyless cars be stolen without the key?

Yes, keyless cars can be stolen without the physical key being taken. The thieves use relay devices to trick the car into thinking the key is present. They can unlock the door and start the engine using the amplified signal from the key, even if the key is inside a house. The car does not require the key to be in the ignition, only within range.

Close

The convenience of keyless entry comes with a tangible security cost. Relay attacks exploit the gap between digital authentication and physical proximity. They do not break the code; they stretch the signal. This distinction matters because it determines the appropriate defence.

Habit-based solutions like pouches are useful but fragile. They fail when memory fails. Robust security requires measures that work regardless of user behaviour. Features like sleep modes, motion sensors, and physical locks provide defences that are always active. They remove the signal or block the theft by default.

Security is not about eliminating risk entirely. It is about raising the cost of attack until it is no longer viable. By combining electronic and physical defences, owners can protect their vehicles from the most common methods of theft. The goal is to make the car a hard target, not an easy one.