Tesla security issues: what a kid did

The German teenager discovered the defect of an open source piece of software.

The 19-year-old German cybersecurity researcher, who accessed several Tesla cars remotely through a third-party defect, has a new trick: he hacks the email addresses of car owners to notify them that I am in danger.

Earlier this month, David Colombo discovered a malfunction in a piece of third-party open source software that allowed him to remotely hijack some functions on about two 24 Tesla models, including opening and closing doors or honking. In an attempt to notify the affected car owners, he then found a flaw in Tesla’s digital car key software that allowed them to learn their email addresses.

Read:  Top 10 Netflix Best Productions This Week: What to Watch at the End of the Day

A serious problem

Colombo said the flaw was in a Tesla or API programming interface. Following the public announcement, a Twitter user suggested that the contact details of the affected owners could be found in the code that allows two software components to communicate with each other, also known as an API endpoint.

“Once I was able to figure out the end point, I was able to see the email address associated with the Tesla API key, the car’s digital key,” Colombo said in an interview with Bloomberg. “You should not be able to carry sensitive information, such as an email address, using access that is already expired or revoked.”

Read:  The blow of the year for billionaire Soros: how his empire will grow, while you can't pay your bills

The teenager from Dinkelsbühl, Germany, said he shared the additional vulnerability with Tesla, and the company’s engineers wrote a fix to prevent it from happening in the future.

Colombo said his additional discovery should be eligible for an “error reward” from Tesla – according to company policy – but officials there have not confirmed an amount with him. He joked that he hoped the amount was high enough to cover the coffee bill he had accumulated working on the original defect in the past two weeks.

The Best Online Bookmakers March 04 2026

Cloudflare rayID 9d6df1cd68bffad4

dcKey 02dffd611f1bee7cd827459be29cc2f0

Legendplay Sports

Legendplay Sports

Bonus

CA$375

Royalistplay Sports

Royalistplay Sports

Bonus

CA$150

DirectionBet Sport

DirectionBet Sport

Bonus

CA$100

  18+ | New players only |  Wagering, banking, T&C apply.  | www.gambleaware.org

Â