E-Rickshaw BMS Hack Exposes Major EV Security Risk

July 4, 2026
Written By Harish

Harish believes great content should be both insightful and easy to understand. He writes about technology, startups, digital trends, telecom, apps, gadgets, and spirituality, transforming complex information into reliable, reader-friendly stories that help people stay informed and make better decisions.

A viral social media trend has exposed a serious security problem in thousands of electric rickshaws and electric scooters across India. The trend, popularly called “Tirri Control,” showed people using mobile apps to remotely switch off moving electric vehicles by connecting to their Battery Management System (BMS) through Bluetooth.

Many videos showed e-rickshaws suddenly stopping in the middle of the road after someone nearby connected to the battery using a smartphone. While some people treated it as a prank, cybersecurity experts say the issue is much more serious. They warn that the weakness could put drivers, passengers, and even the batteries themselves at risk.

How the Bluetooth BMS Hack Worked

The incident involved battery monitoring apps such as BAT-BMS, Lossigy, Epoch Li-ion, and Smart BMS. These apps were created to help battery owners and technicians check battery details like voltage, charging cycles, temperature, and overall battery health.

The problem started because many low-cost lithium-ion Battery Management Systems used in budget electric vehicles came with Bluetooth turned on by default. In many cases, these systems did not require a password, PIN, or any kind of security check before allowing someone to connect.

Anyone standing within a Bluetooth range of around 10 to 30 metres could connect to the battery using one of these apps. After connecting, they could turn off the battery’s discharge function, which cuts the power supply from the battery to the motor. As a result, the vehicle stopped immediately, even though the battery still had charge.

Cybersecurity researchers also found more serious problems inside some of these battery systems. They discovered factory passwords, default administrator passwords, and hidden commands that could easily bypass the limited security available. This made it much easier for anyone with the app to access battery controls.

Experts also warned that attackers could do more than just stop a vehicle. They could change important battery settings, including temperature and voltage limits. These changes could stay saved inside the battery even after the vehicle is switched off, increasing the risk of overheating or battery damage in the future.

Drivers Suffered Losses as Government Stepped In

The biggest impact was felt by e-rickshaw drivers, many of whom depend on daily income to support their families. Several drivers were left stranded after their vehicles suddenly stopped working while carrying passengers.

Many drivers did not even know that their battery packs had Bluetooth features. Dealers reportedly never explained how the Bluetooth system worked or how to protect it with a password.

Some mechanics also took advantage of the situation. Reports said they charged around ₹300 just to reconnect the battery using the same mobile app and switch it back on. The process only took a few seconds, but many drivers had no other option. Some also lost several hours of work, and reports suggested that daily earnings dropped from around ₹1,000 to nearly ₹600 for affected drivers.

After the issue gained attention, the Ministry of Electronics and Information Technology (MeitY) ordered Google and Apple to remove seven battery management apps from their app stores using emergency powers under Section 69A of the Information Technology Act, 2000.

Cyber law experts also said that accessing or controlling someone else’s vehicle without permission is a criminal offence. Those found guilty could face up to three years in prison along with a fine of up to ₹5 lakh. Police and transport authorities have also started investigating the incidents.

Security Experts Say the Real Problem Still Exists

Although the apps have been removed from app stores, cybersecurity experts believe the main problem has not been solved. The vulnerable battery hardware is still being used in thousands of electric vehicles across India.

Experts say removing an app does not fix the security weaknesses inside the Battery Management System itself. Unless manufacturers improve the hardware by adding encryption and proper authentication, similar apps or tools could still be used to access these batteries.

Following public criticism, the developers of one of the affected apps reportedly released an update that now asks for the owner’s password before anyone can change battery settings. While this is a step forward, experts believe stronger hardware security is still necessary.

Electric vehicle owners are being advised to turn off Bluetooth if they do not use it, create strong passwords wherever possible, keep battery software updated, and secure the battery compartment to prevent unauthorised access.

The incident has also increased the need for stronger cybersecurity rules for connected vehicles. India is working on new standards, including AIS-189 and AIS-190, which are expected to make encryption and secure authentication compulsory for connected vehicle components in the future.

At the same time, experts have dismissed social media claims comparing the e-rickshaw incident with Electronic Voting Machines (EVMs). They explained that EVMs do not have Bluetooth, Wi-Fi, or internet connectivity, making such comparisons incorrect.

The Bluetooth BMS hack has become an important reminder that as electric vehicles become more common in India, cybersecurity must be treated as an essential part of vehicle safety. Stronger security measures will help protect drivers, passengers, and the country’s growing electric mobility sector from similar incidents in the future.