Morning Overview

Your key fob signal can be cloned from outside your locked house

The convenience of a modern car that unlocks and starts as the driver simply approaches with a key fob in a pocket has a hidden cost. The same short-range radio system that makes keyless entry effortless can be quietly exploited by thieves standing outside a house, who can trick a vehicle into believing its key is nearby when it is actually sitting on a kitchen counter indoors. The method, known as a relay attack, has become one of the more common ways high-tech car thefts are carried out.

What makes the technique unsettling is that it requires no physical break-in and leaves no obvious trace. The car is not hacked in the traditional sense and the fob is never touched; instead, the vehicle’s own security handshake is stretched across a distance it was never meant to cover.

How passive keyless systems work

Modern keyless vehicles use what engineers call a passive entry, passive start system. Rather than requiring a button press, the car continuously listens for its paired fob and unlocks or allows starting when it detects that the key is close by. The remote keyless system judges that closeness largely by the strength of a low-power radio signal exchanged between the car and the fob, on the assumption that a strong, clear signal means the key is within a meter or two.

That assumption is the vulnerability. The system was designed to measure proximity by signal strength, not to verify the true physical distance between key and car, and it has no built-in way to tell whether a strong signal is genuine or artificially carried over from far away.

Relaying the signal

A relay attack typically takes two people working together with portable radio equipment. One stands near the house or building where the key is kept — often close to a front door, window or wall — using a device that picks up the faint signal the parked car is broadcasting and captures the fob’s response. That signal is then relayed electronically to an accomplice standing beside the target vehicle, whose device rebroadcasts it so the car receives what looks like a normal, close-range reply from its key.

Fooled into thinking the fob is right next to it, the car unlocks and, in many cases, allows the engine to start, letting the thieves drive away. Security researchers describe the approach as a signal-amplification relay attack, and analyses of how a relay attack works note that the whole sequence can take only seconds and works even through the walls of a home if the key is left near an exterior door.

Why the car cannot tell the difference

The core weakness is that traditional keyless systems infer distance rather than measure it directly. Because they rely on the strength of a relayed radio signal, they can be fooled by equipment that simply carries that signal further than intended. The car has no reliable way to distinguish a fob that is genuinely close from one whose signal has been captured and rebroadcast from many meters away.

Automakers have begun deploying countermeasures. Newer systems increasingly use ultra-wideband technology, which can more precisely gauge the actual distance to the fob and is far harder to spoof, and some fobs now include motion sensors that put the key to sleep when it has been still for a while, so a fob left overnight stops transmitting a signal for thieves to grab.

Practical defenses

Until precise-ranging technology is universal, security advisories point to simple physical safeguards. Storing a fob in a signal-blocking pouch or metal container — a small Faraday enclosure — prevents its signal from being detected and relayed, and keeping keys away from exterior doors and windows reduces the chance of a capture. Guidance from insurers on avoiding relay-attack car theft recommends these low-cost steps alongside conventional deterrents such as steering-wheel locks.

Vehicle-theft data has tracked the rise of these electronic methods, and law-enforcement agencies in several countries have reported that keyless cars are stolen at higher rates than models that still require a physical key to be turned. That pattern has pushed some insurers to factor keyless vulnerability into premiums and to recommend specific protective measures for owners of affected models, adding a financial dimension to what began as a purely technical flaw. Certain manufacturers have responded by offering software updates or replacement fobs with motion-sensing sleep functions, an acknowledgment that the original convenience feature shipped with a weakness that needed to be patched after the fact.

The broader lesson is that convenience features carry security trade-offs that owners are rarely told about. A system engineered to save a few seconds at the car door also created a new avenue for theft, and closing it has required both better radio technology and a return to the old-fashioned habit of thinking carefully about where the keys are kept.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview