Waymo Prank Exposes Robotaxi Fleet Weak Spot in California

URL has been copied successfully!

Fifty people standing on one San Francisco dead-end street, each tapping the ride button at the same moment, were enough to take a slice of Waymo’s fleet out of service for the night. The total cost to them was about $250.

That is the incident now driving a much larger conversation about who really controls a driverless fleet. The stunt itself was pulled in July of last year by a San Francisco tech prankster named Riley Walz, who publicized it that October and jokingly called it the world’s first Waymo denial-of-service attack. What is new is the scrutiny it is drawing this week from cybersecurity specialists and the questions it raises about California’s rules for autonomous vehicle operators.

Here is what happened, in plain terms. Fifty participants gathered on the city’s longest dead-end street and ordered rides simultaneously. Fifty driverless cars did exactly what they were built to do and came. None of the riders got in. The vehicles clustered at the dead end, blocked traffic, idled for roughly ten minutes and then left. Each no-show triggered a $5 fee, which is where the $250 figure comes from. Waymo responded by shutting off pickups and drop-offs in that area until the following morning.

No one hacked anything. That is the point. The system was not broken into — it was simply used as designed, all at once, and it buckled. Fifty ordinary phone taps, at five dollars apiece, redirected a working commercial fleet and forced the operator to take a neighborhood offline. For an American reader trying to size up the risk, the ratio is the story: roughly one dollar of cost for every ten dollars a single Waymo ride might generate, and a service area dark until morning.

That is what has security professionals uneasy. Louay Abdelkader, director of product management at QNX, told Fortune that lawmakers should treat vehicle cybersecurity as a primary design requirement in the way airbags are, rather than as something bolted on afterward. His concern is not pranksters. It is that generative AI has collapsed the time and expertise a real attacker needs. Finding vulnerabilities, automating attacks and writing exploits used to take significant resources; tools now available compress that work dramatically, and a bad actor would not stop at a $5 no-show fee.

The reason robotaxis are more exposed than an ordinary car comes down to how many parts are talking to each other. A driverless vehicle runs on dozens of interconnected electronic control units plus high-speed networking, cloud connectivity, GPS, cameras, lidar, radar and AI models continuously reading the road. Every one of those is a door. Security people call the total number of doors the attack surface, and a robotaxi has far more of them than a car with a steering wheel.

Hollywood imagines someone seizing the wheel remotely. Specialists say the realistic threat is the ecosystem around the car — the booking system, the mapping and positioning feeds, the communications links. An attacker who never touches the driving software can still degrade what the vehicle knows about the world around it, or, as fifty people with phones demonstrated, decide where the fleet goes.

California already has rules on the books. The state requires autonomous vehicle manufacturers to show they can safely monitor, update and maintain their fleets while complying with federal vehicle cybersecurity guidance. Waymo runs commercial service in both San Francisco and Los Angeles under that framework. The prank happened anyway. Waymo and the California Department of Motor Vehicles did not respond to requests for comment.

Other states have moved in the same direction. Arizona has folded cybersecurity planning into its broader autonomous vehicle deployment policy, and Michigan has stood up cybersecurity initiatives through partnerships with industry and research institutions. International regulators have gone further still, with United Nations vehicle cybersecurity rules that require manufacturers to manage cyber risk across a vehicle’s life.

The scale involved is why this is now a commercial question rather than a curiosity. Alphabet-owned Waymo has grown from its Arizona start to 11 major American cities, partnering with Uber in several of them, and the company says it delivers hundreds of thousands of fully autonomous trips a week across a fleet of more than 2,000 vehicles.

The fix is not complicated, and parts of it are standard practice in every other online business. Booking systems need the same abuse controls that airlines, ticketing sites and payment processors already run: rate limits on simultaneous requests to a single location, verification that flags a coordinated surge, and dispatch logic that refuses to send an entire neighborhood’s worth of cars to one address. Beyond the app, the harder work is what Abdelkader is arguing for — writing cybersecurity into the vehicle and fleet design at the start, and having regulators check it the way they check crash protection, rather than discovering the gap after somebody films it.

JBizNews Desk | San Francisco

© JBizNews.com All Rights Reserved. Reproduction or distribution without written permission is prohibited.

Please follow us:
Follow by Email
X (Twitter)
Whatsapp
LinkedIn
Copy link