Hi-tech

A Chinese EV app stopped Delhi’s traffic. The same code runs in Tokyo, Dubai, Singapore.

An electric rickshaw in India, where unsecured battery management systems recently exposed a cybersecurity vulnerability.
An electric rickshaw in India, where unsecured battery management systems recently exposed a cybersecurity vulnerability. (Photo via Biswarup Ganguly/Wikimedia Commons)

Key ideas

  • Delhi's e-rickshaw incident exposed unsecured battery management systems, not just a malicious app.
  • Modern EVs continuously collect location, vehicle, and driver data through connected battery and telematics systems.
  • Experts warn EV deployment is outpacing cybersecurity standards across India and much of Asia.

The video lasted less than thirty seconds. A man on a pavement in Delhi holds up his phone, opens an app, taps a button, and an e-rickshaw moving through traffic stops dead. The driver looks confused. He checks the vehicle, but nothing appears broken. He does not know, and has no way of knowing, that a stranger ten meters away just cut the power to his battery with a single tap.

Last Friday, India’s Ministry of Electronics and Information Technology ordered the removal of three apps from Google Play and the Apple App Store, including BAT-BMS, Lossigy, and Epoch-i-ion. IT Secretary S. Krishnan confirmed the action at a CII Cybersecurity Summit, describing the apps as harmful and saying the government would work with app store operators to prevent similar applications from entering the public domain.

The government acted quickly, and its reasoning seemed logical. It believed the apps caused the problem, so it thought removing them would make it disappear. However, the apps were not the real issue.

The battery management system

Every lithium-ion battery pack in e-rickshaws, electric buses, and passenger cars has a battery management system (BMS). The BMS continuously monitors the battery’s voltage, temperature, charge level, and discharge rate. It also decides if the battery should supply power to the motor. Without the BMS, a lithium-ion battery can overcharge, overheat, degrade quickly, or even catch fire. Every electric vehicle on the road, in every country, relies on it.

Because fleet operators need to monitor dozens or hundreds of vehicles simultaneously, from tracking charge levels and scheduling maintenance to watching for faults, modern BMS units are built with wireless connectivity as standard. Bluetooth for close-range monitoring and cellular connectivity for remote fleet management. This feature is designed to make running an electric fleet more cost-effective.

But the feature becomes a vulnerability the moment the wireless interface has no security layer. The battery systems from China used in Delhi’s e-rickshaws lack secure Bluetooth connections. They lack a pairing code, password, or any cryptographic handshake. It goes against standard security practices for wireless devices like phones, speakers, and sensors, which typically require a pairing code to connect.

The popular apps did not hack anything; they connected to a system that had no security. The Indian government has removed access keys, but the system remains open.

The scale that makes this more than a prank

Delhi’s e-rickshaws are the small end of a very large fleet. India has ordered more than 50,000 electric buses for deployment across its cities under various central and state schemes. Delhi alone has more than 1,500 electric buses either operating or on order. The battery systems in those buses are not fundamentally different from those in the e-rickshaws. They are more sophisticated, more expensive, and connected to fleet management systems that can be accessed remotely over cellular networks rather than Bluetooth.

MG Motor is one of the fastest-growing car brands in India and is owned by China’s SAIC Group. BYD provides electric buses to cities in India, including Bengaluru and Hyderabad, and has begun selling passenger cars. Contemporary Amperex Technology (CATL) supplies battery cells to India’s electric vehicle market. The Pentagon listed CATL in June 2026 as an entity linked to China’s military and defense industry.

BYD has also integrated DeepSeek, China’s AI model, into ten of its vehicle models. The data collection and processing architecture in those vehicles is end-to-end Chinese, from the battery cells to the AI assistant that responds to the driver’s voice commands.

This information is not a secret; it is all available to the public. The e-rickshaw incident showed, in just 30 seconds of smartphone video, how a theoretical risk can play out in real life, even on a small, visible scale.

What connected vehicles collect

The vulnerability that allows someone to shut down a vehicle remotely is the most eye-catching part of this issue, but not the most important. Modern connected vehicles do not just follow commands; they also send out data.

The GPS continuously and accurately tracks your location. In-cabin microphones capture audio for voice-command systems. External and in-cabin cameras provide video feeds. The car logs and sends information about your driving behavior, such as speed, braking, and acceleration. When you connect your mobile phone to the vehicle using Bluetooth or a USB cable, the vehicle can access your contacts, call logs, messages, and device details.

According to China’s 2017 National Intelligence Law, Chinese companies worldwide must cooperate with state intelligence services upon request. This requirement applies to all types of companies, including technology firms, car manufacturers, and battery suppliers. It covers the company itself, its subsidiaries, and the data they hold.

What other countries concluded

Israel has banned the use of Chinese electric vehicles for government and military staff. The government is worried about data collection through built-in communication systems and sensors. Israeli cybersecurity experts warned that these vehicles could pose espionage risks, including transmitting audio, video, location, and biometric data to remote servers.

Poland’s armed forces have banned Chinese EVs entirely. The policy also prohibits government and military officials from connecting mobile phones to the infotainment systems of Chinese-made vehicles.

The United Kingdom’s Ministry of Defence has instructed staff to park Chinese EVs at least two miles from sensitive workplaces. BAE Systems, Rolls-Royce, Raytheon, Lockheed Martin, and Thales have all directed employees not to connect phones to Chinese-manufactured vehicles, describing the sector as taking a cautious, belt-and-braces approach to the possibility of the Chinese state accessing information through vehicle systems.

India has done none of this. India currently has no cybersecurity certification requirement for vehicle battery management systems. No data localization requirement for EV telematics. No security audit requirement for connected vehicle systems. No guidance to government or defense personnel about the data risks of Chinese-manufactured vehicles.

The architecture has no borders

The story is about architecture rather than politics, and it goes beyond just Delhi and India. Battery management systems, fleet telematics, and connected vehicle platforms are intended for use worldwide, not just in a single location. The same battery management systems that power e-rickshaws in Delhi also run electric buses in Bangkok, electric taxis in Singapore, delivery fleets in Dubai, and logistics vehicles in Japan’s industrial supply chain.

In each of those cities, the same question applies. The electric vehicle transition across the Indo-Pacific and the Gulf is outpacing the regulatory frameworks that govern vehicle security. Singapore, Japan, South Korea, the UAE, and Saudi Arabia are all deploying electric fleets at significant scale.

Most of this deployment relies on battery technology and vehicle platforms from China. So far, none of these countries has created vehicle cybersecurity standards that would require independent security checks of battery management systems or require data to remain within the country for vehicle telematics.

The prank that was not

The viral videos from Delhi showed that people were disabling e-rickshaws in traffic. These were not skilled attackers; they were bystanders using smartphones and apps. They took advantage of a very simple problem that required no technical skill. Anyone could do it easily.

This detail is important for anyone concerned about the security of connected vehicles. The incident in Delhi showed that no special resources, equipment, or expertise were needed, just a phone and an app. If a state actor had access to cellular fleet management systems instead of just local Bluetooth, the potential risks would be much greater.

On Friday, India’s government removed three apps from two app stores. New apps that do the same job can be created in just a few hours. The batteries in Delhi’s e-rickshaws still lack secure connections to their wireless systems.

Electric buses in Delhi, Bengaluru, and Hyderabad use fleet management systems that have not been security-tested. Passenger vehicles that collect location, audio, and behavioral data still send this information to servers that comply with Chinese law. The apps may be gone, but the problems still exist.

Avatar photo
Kapil Kajal

Kapil Kajal is an award-winning journalist with over a decade of experience covering defense, aerospace, and technology. His work has been recognised with the South Asian Journalists Association Award 2023,.

View full profile →