US lab cracks open Chinese lidar for security flaws
The Idaho National Laboratory is taking apart Chinese lidar units to find security holes — a vulnerability scan paid for by companies in the electric and autonomous vehicle space. The work is a government security review, not a product test, and it targets hardware that feeds sensors to self-driving systems and AVs.
Lidar sends laser pulses to map a vehicle's surroundings. When those sensors are made by foreign vendors and shipped into the US supply chain, the question isn't just whether the beams work — it's whether the firmware, the comms, or the firmware update path can be abused. A bad actor could spoof a sensor, feed a false object, or brick the unit remotely. The review is meant to surface those attack surfaces before the parts make it into fleet vehicles.
This is one of a growing set of hardware scans the US government is running on Chinese components used in transportation, communications, and defense. The electric and AV companies funding it are the ones who'd buy the parts, so the review feeds directly into their procurement decisions and compliance checklists.
Why this matters for us: if you're running a fleet or buying sensors for autonomous vehicles, this scan tells you which Chinese lidar units are likely to be cleared for US use — and which ones are sitting in customs because a lab found a back door.
“When the sensor is the eyes, the firmware is the brain — and the brain is what gets hacked.”