A new and customized software version for the popular Flipper Zero multi-tool device is reportedly capable of bypassing the rolling code used in most modern vehicles, potentially putting millions of cars at risk of theft.
See also: Flipper Zero panic spreads outside Australia

Posts from the YouTube channel “Talking Sasquach” reveal that the software, which is said to be circulating on the dark web, can clone keyfob with just a brief signal recording.
Rolling code security, the industry standard for keyless entry in vehicles for decades, was designed to prevent so-called “replay attacks.” The system works using a synchronized algorithm between the keyfob and the vehicle. Each time a button is pressed, a new, unique, and unpredictable code is generated. An old code, once used, is discarded by the vehicle, rendering simple signal recording and retransmission useless.
Previous known attacks on this system, such as “RollJam”, were technically complex and difficult to execute in the real world. RollJam required jamming the vehicle receiver to prevent the first signal from being received by the legitimate keyfob, while simultaneously recording the unexploited code for future use.
This new exploit, however, is much more dangerous because of its simplicity. According to the demonstrations, an attacker using a Flipper Zero equipped with this custom software only needs to be within range to record a single button press from the target's keyfob, for example, as the owner locks or unlocks their car. No interference is required.
See also: The creators of Flipper Zero react to its cancellation
From that one recorded signal, the device can apparently reverse the encryption process, allowing it to emulate all of the keyfob's functions, including locking, unlocking, and releasing the trunk, effectively creating a "master-key.".

A major consequence of this attack is that the original, legitimate keyfob is immediately disassociated from the vehicle and ceases to function. This could be the first sign to an owner that their vehicle's security has been compromised
There seem to be two dominant theories about how the software achieves this. Talking Sasquach suggests that the method involves reversing the rolling code encoding process, which may have been made possible by previous leaks of manufacturer algorithms or extensive brute-force attacks on known code lists.
However, other security experts point to a known vulnerability described in an academic paper titled “RollBack.” This attack method involves recording several codes and then repeating them to the vehicle in a specific, manipulated order. This tricks the vehicle’s synchronization counter, causing it to “roll back” to a previous state, which the attacker can then exploit to gain control. Regardless of the exact method, the result seen in the videos is the same: one recording grants full access.
The list of affected manufacturers is extensive and includes many popular brands: Chrysler, Dodge, Fiat, Ford, Hyundai, Jeep, Kia, Mitsubishi and Subaru.
See also: Want to steal a Tesla? Try a Flipper Zero
For consumers and manufacturers, the implications are severe. As the vulnerability lies deep within the vehicle’s receiver firmware, there is no easy fix like a simple software update. Experts warn that the only comprehensive solution would be a mass recall to replace the physical components in the affected vehicles, a logistical and financial nightmare for the auto industry.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
