Published Product3 min read
A $100 part, an unlocked hatch, 60 seconds: the 737's exposed surface is physical
Academic researchers hijacked the link between two Boeing 737 flight computers with a coin-sized board. The constraint was never budget or code. It was who can reach the nose bay.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Researchers at the University of California San Diego and Oberlin College built a small, coin-sized device that can take over communications between two key flight computers on Boeing 737 aircraft.
- The prototype costs less than $100 to build and can be plugged into a maintenance port inside an electronics bay underneath the plane's nose.
- The electronics bay can be accessed from the ground through an exterior hatch that is not locked and is routinely accessible to maintenance workers and other airport staff.
- The researchers estimate that an attacker would only need 60 seconds to install the device.
- The findings were presented in a paper at the USENIX Security Symposium in Baltimore this week.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
Researchers at the University of California San Diego and Oberlin College built a coin-sized device that costs under $100 and can take over communications between two key flight computers on Boeing 737 aircraft, plugged into a maintenance port in the electronics bay under the nose [1][2]. That bay is reached from the ground through an exterior hatch that is not locked and is routinely accessible to maintenance workers and other airport staff, and the researchers estimate installation takes 60 seconds [3][4].
The paper, presented this week at the USENIX Security Symposium in Baltimore, lands against an industry habit: much of aviation cybersecurity attention goes to network-based threats, while this attack needs little time and little money [5][6]. The researchers wrote that their goal is to alert the aviation community to this class of risk so it can be mitigated "well before they become dangerous" [7].
What sits on the wire matters more than the wire. The device interposes between the Flight Management Computer, which manages the flight plan and supplies information used during takeoff, and the Multipurpose Control Display Unit that pilots use to control it [8]. That position lets it change a flight plan while suppressing the change on the pilot's display [9]. The described scenarios include the autopilot diverting the aircraft into another country's airspace or simply flying off course [10]. The researchers also demonstrated manipulation of weight, balance and outside air temperature values, the inputs that make a takeoff safe or unsafe [11]. The prototype is Wi-Fi enabled, which the researchers say could theoretically let it join the aircraft's in-flight Wi-Fi and be driven remotely over the internet [12].
The scale is not marginal. UC San Diego puts roughly 8,000 737s in service, and the type accounts for about 25 percent of Delta's fleet, 38 percent of American's, 53 percent of United's and the whole of Southwest's [13][14]. Across those four carriers the exposure runs from a quarter of the fleet to all of it [15]. The researchers frame the finding as pointing to a broader industry-wide risk rather than one manufacturer's defect [16].
The disclosure timeline is the part operators should read twice. The researchers first alerted Boeing in 2020 and kept working with the company for several years after, and they say they do not know whether Boeing has fixed the vulnerability [17][18]. Five-plus years of engagement have ended without confirmed remediation [19]. Boeing did not immediately respond to Gizmodo but told Wired it had reviewed the findings and considers existing safeguards sufficient, saying its technical experts are confident that "the layers of protection in place on the airplane, including within the system design and the operating environment, provide sufficient mitigation to significantly limit the feasibility and risk of real-world attacks" [20][21].
The researchers do not oversell it. They concede the attack would require significant planning and engineering expertise, and that an attentive pilot could recover from most of what they tested; all of the authors say they routinely fly on 737s and will continue to [22][23]. Their proposed fixes are unglamorous and cheap: tighter control over who can reach a parked aircraft, or filling the vulnerable port with epoxy, or removing it entirely [24].
Watch whether any airline or regulator treats ramp access as a security boundary rather than a logistics problem, and whether the epoxy fix shows up in a service bulletin. A remedy that costs a few dollars per airframe and never appears is the clearest signal of where this actually sits on the priority list.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Researchers at the University of California San Diego and Oberlin College built a small, coin-sized device that can take over communications between two key flight computers on Boeing 737 aircraft.
- [2]
The prototype costs less than $100 to build and can be plugged into a maintenance port inside an electronics bay underneath the plane's nose.
ReportedView cited source - [3]
The electronics bay can be accessed from the ground through an exterior hatch that is not locked and is routinely accessible to maintenance workers and other airport staff.
ReportedView cited source - [4]
The researchers estimate that an attacker would only need 60 seconds to install the device.
ReportedView cited source - [5]
The findings were presented in a paper at the USENIX Security Symposium in Baltimore this week.
ReportedView cited source - [6]
While much of aviation cybersecurity focuses on network-based threats, the researchers showed that a physical attack on an airplane may require surprisingly little time or money.
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- gizmodo.comBruce GilAug 14Researchers Built a Coin-Sized Device That Can Hack a Boeing 737’s Electronics
Additional citations
- Gizmodo, reporting on a USENIX Security Symposium paper
- the researchers, in their USENIX paper
- the researchers
- UC San Diego
- Gizmodo, citing Boeing's statement to Wired
- Boeing, in a statement to Wired



