A new relay trick against the plug-and-charge payment system used in European DC fast charging could let a thief fill their battery while another driver’s account takes the hit. Researchers at Technische Hochschule Ingolstadt demonstrated the exploit chain at VehicleSec ’26 in Baltimore this week, with a proof of concept they built from scratch.
The scheme turns a fake charging unit into a man in the middle. When a victim plugs in, the rogue station captures the vehicle’s cryptographic identity during the authentication handshake and relays it onward to a real charger, which completes the session against the victim’s contract certificate. The driver of the vehicle never sees an authorization prompt.
The weakness sits in two places. The plug-and-charge signature carries no station-identifying information, so the billing system cannot tell which unit actually delivered the power. On top of that, the researchers found gaps in how the standard handles TLS certificates on the charging side.
The team, made up of Jakob Low, Vishwa Vasu, Thomas Hutzelmann, and Hans-Joachim Hof, argues the flaw will become more dangerous as plug-and-charge rolls out beyond Europe. Their suggested fixes include binding station identity into the payment signature and making certificate validation stricter on the vehicle side.
For owners the immediate risk is paying for somebody else’s session. For the industry, the work adds to a growing list of ISO 15118 findings and points to a standard that still treats the station as a trusted endpoint.