A car sitting in a locked driveway, its owner asleep upstairs with the key fob resting on a hallway table, can be driven away in under a minute without a window broken or an alarm triggered. The method behind it does not require picking a lock or hacking a computer. It exploits a basic design assumption in keyless entry systems: that if the car can hear the key’s signal, the key must be nearby.
A theft that hinges on distance, not encryption
Keyless entry and passive-start systems work by constantly listening for a low-power radio signal broadcast by a nearby key fob. When the car detects that signal within a short range, typically a meter or two, it unlocks the doors and allows the engine to start with the push of a button, no physical key insertion required. A relay attack exploits that proximity check rather than breaking the encryption behind it: instead of cracking the signal, thieves simply extend its effective range by relaying it electronically from wherever the key actually is to wherever the car is parked, tricking the vehicle into believing the key is close enough to unlock.
How two people and two devices pull it off
The attack typically requires two people working in coordination, each carrying a small radio device. One thief stands near the house, close enough for their device to pick up the faint signal constantly emitted by the key fob sitting inside, often just past a front door or window. That device relays the captured signal to a second device held by an accomplice standing next to the car. The car’s own systems detect what appears to be the genuine key signal arriving at normal strength and respond exactly as they would if the key were sitting in the driver’s pocket, unlocking the doors and permitting the ignition to start. Because the relay simply forwards the real signal rather than forging a fake one, no code needs to be broken or guessed, and the entire process, from first signal capture to driving away, typically takes well under a minute.
Why manufacturers have struggled to close the gap
The vulnerability is a consequence of a convenience feature working exactly as designed. Passive keyless systems were built to let drivers unlock and start a car without ever touching the fob, which means the underlying technology cannot easily distinguish between a key that is genuinely two feet from the car and a key that is two feet from a relay device sitting on the other side of a wall. Some automakers have introduced countermeasures such as motion sensors that put the fob to sleep when it has been stationary for a period, limiting the window in which it broadcasts a relayable signal, along with ultra-wideband systems designed to measure the actual time a signal takes to travel and flag relayed signals as suspicious. Adoption of these fixes has been inconsistent across brands and model years, leaving large numbers of older keyless vehicles on the road with no built-in defense against the technique.
Brands most frequently named in relay theft reports
Reports of relay-based thefts have named a wide range of manufacturers whose vehicles use passive keyless systems, including Ford, BMW, Mercedes-Benz, Audi, Land Rover and Tesla. The common thread across affected models is not a particular brand’s engineering failure so much as the underlying passive-entry technology nearly all major automakers adopted for driver convenience over the past two decades, which means the exposure is closer to industry-wide than confined to any single manufacturer’s lineup.
The low-cost fix owners actually use
The most widely recommended defense does not involve any change to the car at all. Storing a key fob inside a signal-blocking pouch, often called a Faraday pouch or Faraday bag, wraps the fob in a material that prevents its radio signal from reaching outside the pouch, so there is nothing for a relay device to capture in the first place. These pouches are inexpensive and require no technical setup beyond remembering to use one consistently, which security researchers note is the main practical weakness: the defense only works on the nights an owner actually reaches for it. Some owners also rely on simply moving the fob further from exterior walls and windows, since even a small increase in distance can put it outside the range at which cheaper relay devices can pick up its signal.
The same technique shows up far beyond car theft
Relaying a proximity signal to fool a device into thinking something is closer than it actually is is not unique to car keys. The same underlying weakness applies to any system that grants access based on short-range wireless proximity rather than a code the user actively enters, including contactless payment cards and building access badges that use near-field communication or similar radio protocols. A relay attack against a payment card, for instance, can in principle let an attacker complete a contactless transaction using a card that is still sitting in its owner’s pocket or wallet several rooms away, by relaying the brief handshake between card and reader through two linked devices exactly as with a car key, the same proximity-spoofing method documented in the broader technical overview of relay attacks. Financial institutions and access-control manufacturers have introduced their own countermeasures, including transaction limits and distance-bounding protocols that measure signal timing precisely enough to flag an artificially extended relay, but the fundamental proximity-based trust model behind the technology remains the same one car manufacturers have spent years trying to patch.
Estimates of how much relay theft contributes to overall vehicle theft vary depending on the source, since police reports do not always record the specific method a thief used to gain entry, and a car recovered without forced damage to locks or windows is not automatically confirmed as a relay theft rather than some other keyless exploit. Insurers in markets with high keyless-vehicle ownership have nonetheless pointed to relay attacks as a meaningful driver of theft claims tied to vehicles that show no sign of forced entry, prompting some to require additional security measures, such as a tracking device or a mechanical steering lock, before offering full coverage on certain higher-risk models.
This article was produced with the assistance of AI and reviewed by an editor.
More from Morning Overview
- Early Tesla Model S owners are hitting battery and screen failures no one warned them about
- Dietary supplements now rank among the leading causes of drug-linked liver failure
- 11 engines built to run well past 200,000 miles
- Card skimmers hidden on gas pumps are draining accounts, and there’s a quick way to spot them