Modern cars that unlock and start without a physical key have quietly created one of the most efficient theft opportunities in decades. The vulnerability is not a picked lock or a smashed window but a radio trick that lets two people with inexpensive equipment stretch the invisible conversation between a key fob and its vehicle across dozens of feet. The result looks like magic on a security camera: a thief walks up to a locked car in a driveway or parking lot, opens the door, and drives away without ever touching the owner’s keys.
The method has a name that has become familiar to police, insurers, and automakers alike. It exploits the convenience feature at the heart of passive keyless entry, the same feature that lets a driver leave the fob in a pocket and simply grab the door handle to get in.
How a passive keyless entry system talks to its fob
A keyless entry system works by having the car continuously listen for a nearby fob. As described in reference material on the relay attack, the vehicle emits a short-range signal, and when a legitimate fob is close enough it answers, prompting the car to unlock or allow the engine to start. The system is designed around the assumption that if the fob can answer, the fob must be physically near the car. That single assumption is what attackers turn against the owner.
Crucially, the fob and the car exchange a wireless challenge and response rather than a simple always-on broadcast, and the exchange is meant to work only over a very short distance, typically a meter or two. The whole design trades away a margin of security for the comfort of never digging for keys.
What the relay hardware actually does
A relay attack does not break the encryption or copy the secret inside the fob. Instead, according to a technical overview from the Identity Management Institute, it uses two devices working as a pair: one placed near the fob, often just outside a house or beside a shopper in a store, and one placed near the target vehicle. The first device captures the car’s signal and the fob’s reply and forwards them to the second device, which rebroadcasts them at the vehicle. The car receives a valid response and behaves exactly as if the fob were resting on the door handle.
The equipment is neither exotic nor expensive. Security researchers have repeatedly demonstrated that off-the-shelf radio components can extend a fob’s effective range far beyond its intended limit, and the same overview notes that researchers at the University of Birmingham demonstrated relay attacks against production keyless systems, unlocking and starting vehicles without possessing the key. Because the technique simply extends a real signal, it defeats systems that rely on proximity alone as proof of possession.
Why a parking lot or driveway is the ideal setting
The attack thrives wherever a fob and a car sit within radio reach of an accomplice. A home is a common target because owners often leave keys near the front door, only steps from a vehicle parked in the driveway. A parking lot works just as well, since one operator can trail a fob owner into a shop while a second waits by the car. The two devices bridge whatever gap separates them, so the practical range is limited mainly by how far the relayed transmission can travel between the pair rather than by the fob’s own weak output.
Speed is part of what makes the crime attractive. The entire sequence of unlocking and starting can unfold in well under a minute, and it leaves no broken glass or forced lock to signal a break-in, which can complicate both police investigations and insurance claims.
The countermeasures automakers and owners rely on
The defenses fall into two categories: engineering fixes built into the car and habits or accessories adopted by owners. On the engineering side, a granted U.S. patent for relay attack prevention illustrates the industry’s main strategy, which is to stop trusting proximity by measuring it directly. Newer systems use ultra-wideband ranging and precise timing so the car can gauge the true distance to the fob; because a relay adds a tiny but detectable delay as it forwards the signal, a system that measures round-trip time can recognize that the fob is farther away than it claims and refuse to unlock.
Some vehicles also let the fob go dormant when it has been still for a set period, so a fob left overnight on a hall table stops answering until it moves again. Manufacturers layer in rolling codes and stronger cryptography as well, though those measures address copying and replay rather than the relay itself, which forwards a live exchange rather than a recorded one.
For owners, the simplest protection is to keep the fob from radiating at all when it is not in use. Storing it in a signal-blocking pouch or a metal container acts as a shield that prevents the fob from answering a relay device, and parking within a garage or keeping keys away from exterior walls and windows adds distance that a relay must overcome. Physical deterrents such as steering-wheel locks and aftermarket immobilizers remain useful because they force a thief to defeat a second, mechanical barrier even after the electronic one has been bypassed.
A convenience feature that keeps rewriting its own rules
The relay attack endures because it targets a design choice rather than a defect, and every gain in convenience tends to reopen the same question of how a car should prove that its owner is truly present. As distance-measuring radios spread through new models, the balance may tilt back toward the vehicle, but tens of millions of older cars on the road still rely on proximity alone, keeping a cheap pair of radios a viable tool for theft for years to come.
This article was produced with AI assistance and reviewed by Morning Overview editors.
More from Morning Overview