A viral social media trend has uncovered a serious cybersecurity flaw in many Bluetooth-enabled e-rickshaws across India, allowing users to remotely switch off vehicles mid-journey using smartphone apps. Videos of the prank have spread widely on Instagram, YouTube, Reddit, and X, raising concerns about passenger safety and the lack of security in connected vehicle technology.

The apps, BAT-BMS and Lossigy, reportedly connect to unsecured Bluetooth-enabled Battery Management Systems (BMS) found in certain lithium-ion battery packs. Since many of these systems lack password protection, anyone nearby can connect to the battery and disable the vehicle with a single tap.

Drivers say the issue has existed for months but has become more frequent after the prank videos went viral. Many have reported their e-rickshaws suddenly stopping in the middle of traffic, creating safety risks for both passengers and motorists.

Experts warn that the incident highlights the growing cybersecurity challenges associated with low-cost connected devices. They stress that many battery systems were designed for maintenance access but lack basic authentication features, making them vulnerable to misuse.

The Delhi Transport Department has begun verifying the claims after receiving complaints, while the Union Ministry of Electronics and Information Technology (MeitY) is also examining the issue. Authorities are expected to assess whether additional safeguards or regulations are needed to prevent similar vulnerabilities in connected vehicles.

Cybersecurity specialists have urged stronger security standards for imported electronic components, warning that any connected consumer device without proper authentication can become a potential target for misuse.