
Tokyo, Japan—Security researchers participating in the Pwn2Own Automotive 2025 hacking contest achieved significant breakthroughs on its second day by exploiting Tesla’s Wall Connector electric vehicle (EV) charger twice and discovering 23 zero-day vulnerabilities in various EV chargers and in-vehicle infotainment (IVI) systems.
The hacking event, held from January 22 to January 24 in Tokyo as part of the Automotive World conference, spotlights vulnerabilities in automotive technologies, including EV chargers, IVI systems, and car operating systems. All devices targeted during the contest run on their latest firmware with full security updates, adhering to strict contest rules.
On the second day, the team PHP Hooligans made history as the first to crash Tesla’s Wall Connector successfully. They leveraged a previously unknown Numeric Range Comparison Without Minimum Check zero-day vulnerability to gain control of the device. Soon after, Synacktiv followed with an innovative hack of Tesla’s EV charger, using an entirely new Charging Connector exploit that had never been publicly demonstrated.
Notably, two additional attempts to hack the Tesla Wall Connector resulted in bug collisions, meaning researchers independently discovered the same vulnerabilities. PCAutomotive and Summoning Team’s Sina Kheirkhah each exploited previously known bugs to demonstrate their attacks.
Beyond Tesla, researchers uncovered critical vulnerabilities across other devices, including the ChargePoint Home Flex, Autel MaxiCharger, Phoenix Contact CHARX, WOLFBOX, and EMPORIA EV chargers. Key infotainment systems such as the Alpine iLX-507, Kenwood DMX958XR, and Sony XAV-AX8500 were also successfully compromised.
The competition awarded $335,500 on the second day, highlighting leading researchers like Sina Kheirkhah, who now leads the race for the coveted "Master of Pwn" title. The achievements followed an equally notable first day, which saw 16 unique zero-day exploits disclosed and $382,750 awarded.
Trend Micro’s Zero Day Initiative (ZDI), which organizes the Pwn2Own contests, requires hacked device vendors to release patches within 90 days after the competition ends. This ensures that the disclosed vulnerabilities are responsibly reported and rectified before public disclosure.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543