Two Accenture researchers will show at DEF CON 34 on Saturday how a parked EV can be turned into a free power bank. Fabien Guillebot and Stepan Konicek plan to charge a phone directly from a locked vehicle’s traction battery with no authorization, no keys, and no official vehicle-to-load features involved.
The demo is built on new research into the security of vehicle-to-grid communication. As automakers push V2G capabilities, the charging link between car and grid is growing into an attack surface with destructive potential for high-voltage systems. The pair mapped the high-voltage charging architecture and found logic weaknesses hiding inside the battery management system ECUs that govern when and how energy leaves the pack.
To turn the findings into something testable, the researchers built ChargeSploit, a custom hardware and software toolkit for EV charging security testing. It can simulate both vehicles and chargers or sit between them as a physical man-in-the-middle, letting testers intercept, manipulate, and inject payloads into live communication flows. The live demonstration exploits V2G protocols and BMS weaknesses to force an unauthorized discharge, drawing real power out of the locked car.
The implications go beyond a party trick. Unauthorized discharge drains battery capacity, and flawed V2G logic could allow repeated drain cycles or grid-side abuse as bidirectional charging spreads across fleets and homes. The researchers are releasing ChargeSploit as a tool for the wider security testing community, giving OEMs and charger vendors a concrete way to probe their own high-voltage stacks before attackers do.