Car Hacking Village at DEF CON 34 | Las Vegas | August 9, 2026
PCA Cyber Security is proud to sponsor Car Hacking Village at DEF CON 34.
Join our Security Researcher, Danilo Erazo, as he presents his latest research on Unlocking Vehicles by Brute-Forcing Rolling Code Systems, demonstrating how weaknesses in widely used aftermarket rolling code systems can be exploited and what this means for the security of modern vehicles.
Date and time: Aug 9th, Sunday at 10:30
Location: Las Vegas Convention Center, DEFCON34 / Car Hacking Village Creator Stage 1
Unlocking Vehicles by Brute-Forcing Rolling Code Systems
Many vehicles worldwide rely on a popular aftermarket rolling code system that has long been trusted to protect against key fob cloning and unauthorized access. This talk unveils the reverse engineering journey that uncovered the protocol’s frame format, cryptographic design, and previously undocumented weaknesses. By combining a rollback vulnerability with a practical rolling code brute force attack, we demonstrate how an attacker can recover valid codes and clone a legitimate key fob. The research resulted in three CVEs assigned in 2026 and impacts products deployed across multiple markets. Attendees will learn how assumptions about rolling-code security can fail in practice and how these failures can be exploited in the real world.
DURATION: 00:30
Danilo Erazo
Security Researcher