Yahoo
Skip to main content
Advertisement
Advertisement
Advertisement
Advertisement

Hackers just proved no satellite terminal is unbreakable, not even Starlink’s newest

Hackers just proved no satellite terminal is unbreakable, not even Starlink’s newest
Hackers just proved no satellite terminal is unbreakable, not even Starlink’s newest

A cybersecurity team says it has broken into the latest generation of Starlink satellite dishes. Researchers had been chasing that milestone since SpaceX locked down the previous design years ago. Darknavy, an independent research institute based in Singapore and Shanghai, announced the claim in a post on X on Tuesday. The team said it gained full administrative control over a current Starlink user terminal.

The team said it used sophisticated hardware attacks to achieve that access, allowing it to run custom code directly on the device. Darknavy framed the breakthrough as reopening a long-closed entry point for researchers studying the security of SpaceX's satellite network , rather than as an exploit intended for malicious use.

The group said its work builds on a Starlink Standard Actuated terminal it purchased in Singapore last March, which it disassembled and began analyzing at the firmware level. In a blog post at the time, Darknavy described the challenge poetically. Developers and hackers contend not only in the digital realm, the company wrote, but also against the constraints of cosmic physics.

A years-long standoff

Security researcher Lennert Wouters of Belgium's KU Leuven first demonstrated a working attack against Starlink's original, circular terminal design. He presented the work at the Black Hat USA conference in 2022, using a technique called voltage fault injection. SpaceX responded by hardening later hardware generations, and for several years afterward, independent research teams reportedly found no way past those protections.

Advertisement
Advertisement

https://twitter.com/DarkNavyOrg/status/2092179827487027299?s=20

Darknavy said its new work targets the newer, square-shaped terminal design, calling it, to the team's knowledge, the first full exploit of that hardware since Wouters' original attack. The group credited SpaceX's security team directly, saying the strength of the newer protections left hardware attacks as the only viable path forward. Darknavy praised the difficulty of the challenge even while claiming to have overcome it.

How the terminal works

A Starlink terminal consists of two main parts: a router and an antenna unit that also functions as the dish's radio transceiver. Terminals connect users to satellites in low Earth orbit, which relay data back to the ground through gateway stations.

Newer satellites equipped with laser links can also communicate directly with each other, reducing dependence on ground stations while improving both transmission speed and global coverage. That capability lets Starlink terminals maintain internet access even in places with no nearby ground gateway. That includes parts of the Ukrainian battlefield, where signals route through satellites connected to gateways in neighboring countries instead.

An opening for research

Gaining administrative control over a terminal could let researchers legally examine how the devices interact with satellites in far greater depth. That level of access goes well beyond what external testing alone allows. Darknavy said the access could support simulating, injecting, intercepting, and analyzing the network's communication protocols to help uncover vulnerabilities across the entire satellite system.

Advertisement
Advertisement

The South China Morning Post reported it had contacted SpaceX for comment on Darknavy's claims. The case illustrates that even under a system's latest and strongest protections, security weaknesses can still surface.

Darknavy said further technical details of the research could not be disclosed at this stage. Its official website, the company added, would serve as the main source of future information on the work.

Advertisement
Advertisement
Mobilize your Website
View Site in Mobile | Classic
Share by: