Security researchers have developed an exploit that allows for the breach and full control of Boosted electric skateboards.
Researchers Richard Healey and Mike Ryan developed an attack called Faceplant, which allows an attacker to gain control of the speed, direction, and braking system of vulnerable skateboards, even allowing arbitrary code to be uploaded to the skateboard's firmware.
Researchers discovered that manufacturer Boosted does not encrypt connections between skateboards and remote controls when Healey's electric skateboard randomly stopped in an area flooded with Bluetooth interference. This inspired the researchers to investigate whether they could hack the skateboard, concluding that the hack was possible by breaching unencrypted Bluetooth systems.
“Once this is achieved, attackers can stop the skateboard abruptly, ejecting the rider, send a malicious exploit that causes the wheels to change direction, sending the board in the opposite direction at breakneck speed, or disable the brakes. Attackers can also block communication between the remote control and the skateboard while the rider is on a steep hill, causing the brakes to disengage,” the researchers report.
Healey and Ryan reported their findings to Boosted last September, but the company has yet to issue a patch to fix the vulnerability.
Researchers have also found critical vulnerabilities in skateboards from Revo and Yuneec, which also result from a lack of encryption, but have not yet created exploits to exploit them.

