Before heading out for a bike ride, cyclists typically check their gear: water bottles, tire pressure, and route. What often doesn’t cross their minds is the risk of their bikes being hacked while they’re riding. However, as bicycles become more technologically advanced, this risk is increasing, according to recent research from Northeastern University.
Aanjhan Ranganathan, a professor at Northeastern’s Khoury College of Computer Sciences, is among several cybersecurity experts who have uncovered significant security issues in the wireless gear-shifting systems of high-end bicycles used by both professionals and enthusiasts. Alongside Ranganathan, Maryam Motallebighomi, a doctoral student specializing in wireless security, contributed to this research.
Wireless gear-shifting technology, introduced in 2015, has been praised for its enhanced precision and ease of use compared to traditional mechanical or wired systems. These systems use radio signals to communicate between the bike’s shifter and derailleurs. However, the research reveals that these signals are vulnerable to interception. Hackers can exploit this vulnerability to manipulate the bike’s gears without the rider’s consent or even disrupt the shifting system entirely.
The research team, in collaboration with Shimano—one of the leading manufacturers of these systems—is working to address these security flaws. Shimano is currently rolling out a software update to mitigate the risks identified by Ranganathan and his team.

Ranganathan notes that Shimano’s response has been swift and positive. “When Shimano’s CEO reviewed our findings, he was eager to implement a solution quickly,” Ranganathan says.
One specific vulnerability discovered was the risk of “replay attacks.” For example, if a hacker is near a cyclist, they could capture and later replay gear-shifting signals to force unintended gear changes. These attacks can be executed with high precision from up to 10 meters away.
“The impact is significant,” Ranganathan explains. “In a race with multiple bikes close together, a hacker could selectively disable certain bikes.”
These vulnerabilities pose a serious threat in competitive cycling, where cheating isn’t unheard of. Similar to how anti-doping measures are employed, cycling officials are now using scanners and X-ray devices to detect hidden motors in bikes—a practice known as “motor doping.”
“There’s an increasing adversarial element in competitive cycling,” Ranganathan observes.
To enhance security, Ranganathan’s team has proposed several measures to Shimano. One effective solution involves implementing a “rolling code” system, which would regularly change the transmission signal to prevent the use of recorded signals for attacks. This method, while effective, requires precise synchronization between the bike’s shifter and derailleurs, which can be challenging.
Another approach suggested is to ensure that signals activating the gear-shifting system must come from a very close range to the bike, adding an extra layer of security.



