Premium

Your battery is watching: The cybersecurity warning for India in stalled e-rickshaws

Imported hardware can be allowed after rigorous testing and verification of secure software development practices. These will move the conversation from the origin of technology to its demonstrable trustworthiness

e rickshawE-rickshaw outside the INA market Metro Station in New Delhi. (Express Photo by Praveen Khanna)
5 min readJul 16, 2026 01:49 PM IST First published on: Jul 16, 2026 at 01:49 PM IST
Written by Deep Pal and Sukanya Thapliyal

Recently, e-rickshaws on Delhi’s streets suddenly began stalling in the middle of the road. It turned out that one could use certain Chinese apps to disable their batteries by exploiting their Battery Management Systems (BMS). The Ministry of Electronics and Information Technology (MeitY) swiftly had Google and Apple remove the errant apps, but not before the familiar debate about the threat from Chinese technology was reignited.

However, such a framing misses a more important lesson. The apps in question were diagnostic tools for technicians to remotely monitor battery health, diagnose faults, and perform maintenance. Certain BMS units accepted Bluetooth connections with weak or default credentials, allowing unauthorised users to access critical functions. This means that the real issue is not where the software originated, but that batteries are now software-defined, connected systems.

Latest Comment
Post Comment
Read Comments