Coin-Sized Device Can Hack Boeing 737 Autopilot
Original: This Coin-Sized Device Can Hack a Boeing 737
Why This Matters
Exposes a critical physical-access attack vector in commercial aviation security with low-cost, readily available hardware.
Researchers from UC San Diego and Oberlin College will present at Usenix 2026 a sub-$100, coin-sized Wi-Fi device that, when plugged into an exterior port of a Boeing 737 in under 60 seconds, can redirect autopilot and falsify pilot displays.
Security researchers from the University of California San Diego and Oberlin College have developed a coin-sized, Wi-Fi-enabled hardware implant costing under $100 that can compromise a Boeing 737's critical flight systems. The device fits into an externally accessible port on the aircraft's exterior — reachable without special tools in approximately 15 seconds — and, once inserted, sends electrical signals over the plane's internal network to commandeer the autopilot or silently alter takeoff and fuel calculations while spoofing correct values on the pilot's display. The researchers warn such manipulation could cause runway overruns, unplanned airspace diversions, or catastrophic crashes. The project spanned over a decade and involved purchasing tens of thousands of dollars of aircraft components for testing. Professor Stefan Savage of UCSD, who led the research, summarized the threat: 'You can shove in a piece of electronics a little bigger than a quarter that lets you basically tell the autopilot what to do and lie to the pilot about changes to the flight plan.' The team will formally present their findings at the Usenix Cybersecurity Conference, arguing that physical-access hacking of aircraft represents a significant and underappreciated blind spot in aviation security, offering attackers greater control, stealth, and deniability compared to traditional sabotage methods.