
Researchers at UCSD and Oberlin College have built a gadget roughly the size of a coin that can take control of a Boeing 737’s flight management systems after just a minute of physical access to the aircraft. The work, reported by Wired on August 12, is set to be unveiled at the Usenix Security Conference. The device costs under $100 and connects to a port hidden behind an exterior hatch that can be opened without tools in about 15 seconds.
The attack is not a remote exploit. It is the physical-access playbook of spies applied to aviation: spend sixty seconds alone beside the wrong hatch, plug in an implant, and let it silently inject messages into the aircraft’s internal network. Once installed, the gadget can interfere with the bus that links the flight management computer to the multipurpose control display unit, the cockpit screen where pilots enter routes and monitor the flight plan.
The team calls the underlying technique Bus Driver. By transmitting precisely timed electrical pulses carrying more current than ordinary bus traffic, the device drowns out legitimate messages and injects its own. Sam Crowe, a student on the project, came up with the approach. The researchers are deliberately withholding the identity of the exact port and other technical details, to keep the work out of reach of anyone inclined to copy it.
What the device can do, in the researchers’ testing, goes beyond display tricks. It can rewrite waypoints in the autopilot’s flight plan, which in principle lets an attacker steer the aircraft off its intended route. It can also alter inputs such as aircraft weight and outside air temperature, values that feed takeoff performance calculations, while the pilot’s screen continues to show the original numbers. Tom’s Hardware, which also covered the research, says the gadget can even be reached over a 737’s in-flight Wi-Fi once installed.
The research grew out of a decade of work on a ground test rig. The team assembled Triton, a bench full of real 737 avionics bought secondhand, to probe what could be done without touching a live airplane; the setup was complete by 2019. The underlying weakness, a bus design that trusts any device that speaks on it, was flagged years ago: the Department of Homeland Security and Rapid7 warned about the CAN bus class of flaws in 2019, and similar attacks have been demonstrated against cars through physically accessible ports.
Boeing, asked about the work, said the protections built into the aircraft and the way it is operated in the real world are enough to substantially reduce the feasibility and danger of such an attack in practice. The researchers counter that the company has not offered a technical fix. They first told Boeing about the vulnerability in 2020 and later demonstrated it in a Boeing test facility. Their suggested mitigations are blunt: physically remove the connector or seal the port with epoxy, and in the longer term add electrical isolation, software that detects Bus Driver-style interference, and cryptographic authentication for bus messages.
Certification is the hard part. Consumer software can be patched in a day; a change to certified avionics has to go through testing, recertification and fleet-wide rollout across an aircraft family that has been in service for decades. The researchers also note the practical safety nets: a pilot who suspects tampering can take manual control, and other cockpit displays may still show correct values. The deeper question the team raises is whether ground-level access, maintenance ports and decades-old avionics buses are treated as the security boundary they have become.
Sources: This Coin-Sized Device Can Hack a Boeing 737 (Wired, Aug 2026); A Coin Sized Device Can Feed a Boeing 737 False Flight Data (Startup Fortune, Aug 2026); Coin-sized device can hack a Boeing 737’s Flight Management Computer (Tom’s Hardware, Aug 2026); Researchers hacked an airplane using a $100 device (dev.ua, Aug 2026)

