Researchers will show at DEF CON 34 how a popular aftermarket rolling code system can be cracked to clone key fobs, a finding that earned three CVEs this year.
A widely sold aftermarket security system built its reputation on blocking fob cloning and unauthorized access, researcher Danilo Erazo explains. Erazo reversed the protocol to map its frame structure and cryptographic design, surfacing weaknesses that had never been documented.
The attack methodology couples a rollback flaw with a practical brute force of the rolling code stream. Valid codes fall out of the process, giving attackers everything they need to duplicate a real fob and operate the target vehicle. The year 2026 has already seen three CVE identifiers attached to the research, and the affected hardware is spread across numerous countries.
The presentation, “Unlocking Vehicles by Brute-Forcing Rolling Code Systems,” runs Sunday morning at the Car Hacking Village’s Creator Stage.
Rolling codes are supposed to defeat replay attacks by changing the transmitted code on every press. The research is a reminder that assumptions about rolling code security can fail in practice: cryptographic weaknesses and rollback behavior can turn a decades-old protection mechanism into a gate that opens for attackers.
For owners of vehicles using aftermarket security products, the findings reinforce the value of checking whether a system’s flaws are patched and whether vendors respond to coordinated disclosure.