The popularity of electric scooters has grown in recent years, both for personal use and through rental apps. E-scooters are typically managed via a mobile app and powered by internal components, such as the battery, the battery management system (BMS), the driving system (DRV), and the Bluetooth Low Energy system (BTS). Despite their safety implications, there is little research on the security and privacy of these proprietary and undocumented internals and their associated attacker models. To fill this gap, we present the first security and privacy assessment of the internal components of two popular Xiaomi e-scooters. We cover the M365 (2016) and Mi3 (2023) e-scooters, and their Mi Home companion app. Via reverse-engineering (RE), we uncover four critical design vulnerabilities on the e-scooter internals, such as arbitrary code execution on the BMS. Based on these issues, we develop E-Trojans, five novel attacks that flash a malicious BMS firmware to exploit the e-scooter’s internal components. The attacks can be performed physically via the debug port of the BMS, wirelessly over Bluetooth Low Energy (BLE), and remotely from a malicious app on the victim’s phone. They have a critical and real-world impact as they violate the safety, security, availability, and privacy of e-scooters and their users. For instance, they can permanently damage the e-scooter battery by undervolting it below the safety threshold or track the user by utilizing e-scooter internal values as a fingerprint. We implement our attacks and RE findings in a modular and low-cost toolkit. Our toolkit binary patches BMS firmware by adding malicious capabilities, such as disabling battery safety thresholds, which enables our attacks and the creation of new ones. We test our attacks on real M365 and Mi3 e-scooters, empirically confirming their effectiveness and practicality. We propose four practical countermeasures that improve the security, privacy, and safety of the Xiaomi e-scooter ecosystem and its millions of users. We responsibly disclosed our findings to Xiaomi, which acknowledged and addressed them.
E-Trojans: Ransomware, tracking, DoS, and data leaks on the Xiaomi e-scooter ecosystem
VEHICLESEC 2026, 4th Usenix Symposium on Vehicle Security and Privacy, 10-11 August 2026, Baltimore, MD, USA
Type:
Conférence
City:
Baltimore
Date:
2026-08-10
Department:
Sécurité numérique
Eurecom Ref:
8892
Copyright:
Copyright Usenix. Personal use of this material is permitted. The definitive version of this paper was published in VEHICLESEC 2026, 4th Usenix Symposium on Vehicle Security and Privacy, 10-11 August 2026, Baltimore, MD, USA and is available at :
See also:
PERMALINK : https://www.eurecom.fr/publication/8892