Keyless Car Hacking: How Thieves Get In and the Fixes That Keep Them Out
Relay attacks, jamming, and code-cloning are being used to steal cars with keyless entry. Here are the specifics of each threat and the countermeasures that actually work.
How does a relay attack actually steal my keyless car?
A relay attack uses two devices to capture and retransmit the signal from your key fob. One device is placed near the car, typically by the driveway or on the road, while the other is held close to you — outside your home, in a café, or at your workplace. The device near you picks up the fob's low-power signal and forwards it to the second device next to the car, which rebroadcasts it. The car's Passive Keyless Entry and Start (PKES) system accepts this as the legitimate key and unlocks the doors, allowing the thief to press the start button and drive away. The entire process takes seconds and leaves no physical trace. Because the signal is relayed in real time, it doesn't need to be decoded or decrypted. Modern relay devices can work from several hundred meters away, and improvements in amplification mean the attack can be launched without you noticing, even with the fob inside your home, garage, or office. This method is now the single most common way keyless cars are stolen.
Why can't encryption and rolling codes stop relay attacks?
Encryption and rolling codes are designed to prevent an attacker from replaying a previously recorded signal or injecting a fake one. But a relay attack doesn't do either of those things. It captures the live, genuine signal that your key fob is already broadcasting and moves it over a longer distance to the car. The car receives the exact same encrypted rolling code it expects from a legitimate key, so it validates it without question. Rolling codes change every time you use the fob, but because the relay attack transmits the current code in real time, the code is always the one the car is waiting for. As a result, even the strongest encryption cannot block a relay attack — the security layer is bypassed entirely because the communication looks completely normal. This is why automakers are moving to ultra-wideband, which uses timed distance measurement, as it resists signal relaying at the physical layer rather than relying on cryptographic counters.
What is a jamming attack and how can I tell if my car failed to lock?
A jamming attack works by broadcasting a powerful radio signal on the same frequency that your key fob uses to send the lock command. The car's receiver is overwhelmed by the jammer, so it never receives the lock signal; the doors stay unlocked even though you pressed the button. The fob gives you no warning because it doesn't know the signal was interrupted — it simply sent the command. Thieves wait for you to walk away, then open the door silently. Many key fobs operate on easily jammed frequencies, and compact jamming devices are readily available. To detect a jamming attack, you must look for a physical confirmation from the car: watch for the side mirrors folding in, a flash of the hazard lights, or a locking beep. If you see none of those, the lock signal didn't get through. A quick tug on the door handle is the final check. This is the only method that works when jamming is used.
How does a Faraday pouch protect my key fob, and does it work?
A Faraday pouch is a small case made from woven metal fibers that create a continuous conductive shield around your key fob. When the fob is inside a sealed pouch, electromagnetic signals cannot pass in or out, so a relay device nearby receives nothing to amplify. The pouch essentially acts as a portable version of the Faraday cage used in electronics labs. For the pouch to work, it must be properly closed — any gap in the fabric or an open flap can leak signal. The protection is absolute while the fob is inside, which is why it's recommended to keep your fob in the pouch overnight or when you're away from the car. It's an inexpensive, zero-maintenance countermeasure, though it requires the discipline to actually use it every time.
Can I turn off my key fob's wireless signal to prevent hacking?
Yes — if your vehicle has this feature. Several automakers now include a menu setting or a specific button sequence that puts the key fob into a dormant mode, disabling its transmitter. When activated, the fob stops broadcasting the low-power signal that relay attacks rely on, so there is nothing to capture or amplify. The exact procedure varies by make and model: some require a long press on the lock button, others need you to access the car's infotainment menu, and a few will automatically enter this state after a period of inactivity. Once the fob is in this mode, you'll need to press a button or hold it near a marked spot on the steering column to wake it up before driving. This is a free and built-in solution, but it's not universal — older and economy models typically lack it.
What is CR key hacking and how does it differ from a relay attack?
CR key hacking — often called code grabbing or rolling-code interception — involves capturing the digital data your key fob sends when you unlock or lock the car, then using that data to create a clone of the fob. Thieves place a covert receiver near your car and wait for you to press the unlock button. The receiver records the radio frequency transmission, which contains the current rolling code. After capturing one or more codes, the thief can replay them to a blank key fob and unlock the car at a later time. This differs from a relay attack in two key ways: relay attacks work in real time with the original fob, while CR hacking creates a separate copy; relay attacks amplify a live signal, while CR hacking extracts and replays a recorded one. CR hacking requires the thieves to actually break or exploit the rolling-code algorithm, which is why it's less common than relay attacks, but it is a growing threat as more sophisticated tools become available.
What is ultra-wideband (UWB) and how does it stop relay attacks?
Ultra-wideband (UWB) is a radio technology that measures the precise time it takes a signal to travel from the key fob to the car. Because radio waves travel at light speed, this timing lets the car calculate the distance to the key with centimeter-level accuracy. In a relay attack, the thieves' devices add a delay while the signal is amplified and retransmitted. With a narrowband system, that delay is undetectable; the car simply sees the signal and unlocks. But with UWB, the car measures the round-trip time and notices that the signal took much longer than it would from a key actually standing nearby — often by microseconds — and refuses to authenticate. This makes relay attacks essentially impossible because the added latency is always detectably. Automakers are now integrating UWB into newer models, often for phone-as-key systems, and the technology is being standardized for future vehicles. It does not block jamming or code-rabbing attacks, but it directly addresses the most common theft method.