High-end bicycles used in elite road races, like the Tour de France, are facing cybersecurity threats that could compromise their wireless gear-shifting systems. As bicycle manufacturers have transitioned to wireless technology for gear shifting, riders benefit from smoother and more efficient gear changes compared to traditional mechanical systems. However, this advancement has introduced significant security flaws. Researchers from the University of California San Diego and Northeastern University have identified these critical vulnerabilities.
The researchers explain that “flaws in wireless gear-shifting systems can jeopardize rider safety and performance, especially in professional cycling events.” They warn that attackers could exploit these vulnerabilities to manipulate gear shifts, potentially causing crashes or injuries, or to gain an unfair advantage in races.
Currently, the researchers are collaborating with Shimano, a major player in the bicycle component industry, to address these security issues. Shimano was chosen due to its dominant position in the wireless gear-shifter market. The findings will be presented at the 18th USENIX WOOT Conference in Philadelphia on August 12 and 13.
The wireless gear-shifting system operates through a network of signals between the gear shifters controlled by the rider and the derailleur, which adjusts the chain between gears.
The team identified three major vulnerabilities:
- Replay Attacks: Attackers can record and retransmit gear-shifting commands, manipulating the bike’s gear shifts without needing to authenticate via cryptographic keys. This can be done from up to 10 meters (approximately 30 feet) away using common software-defined radios, with no additional amplification required. The recorded commands can be reused as long as the bike components stay paired.
- Jamming Attacks: Attackers can easily disrupt the gear-shifting system on a particular bike, affecting only that bike while leaving others unaffected, which poses substantial risks to the rider’s safety.
- Information Leakage: The communication protocol ANT+ used in these systems can inadvertently disclose operational data, enabling attackers to monitor real-time activities of their target.
The researchers note that the history of cycling’s issues with performance-enhancing drugs highlights the potential for such covert attacks to undermine the sport’s integrity. They emphasize the need for robust security measures to protect against determined adversaries in the competitive world of professional cycling.
To address these vulnerabilities, the researchers have proposed several countermeasures, including methods to thwart replay attacks, minimize jamming risks, and prevent information leakage. Shimano has begun implementing these solutions, with a broader rollout expected soon.



