Student Hacks Taiwan Rail with $50 Radio: 4 Trains Stopped

Key Takeaways

- A student bypassed 7 security layers using software-defined radio equipment
- The TETRA radio system's encryption keys hadn't been rotated since installation 19 years ago
- The incident has triggered a national review of rail and airport communication security
A 23-year-old college student in Taiwan brought four high-speed trains to a standstill last month using little more than a laptop and some radio equipment. The student, identified only as Lin, remotely broadcast a General Alarm signal that triggered emergency braking procedures across the line.
The trains sat idle for 48 minutes while operators verified the alarm was false. No hard stops were executed, and no injuries were reported. But the breach exposed something far more troubling than one student's reckless experiment.
Seven Security Layers, Zero Key Rotation
Lin sailed through seven verification layers designed to protect the rail system's communications. The reason? The TETRA (Terrestrial Trunked Radio) system controlling train communications hadn't had its cryptographic keys changed since installation. That's 19 years of using the same digital locks.
RTL-SDR, a community focused on software-defined radio technology, speculates the system used TEA1 encryption. TEA1 has known vulnerabilities. But the more likely explanation is simpler: key rotation requires configuration at installation. The Taiwan rail system apparently never set it up.
Software-defined radios are widely available consumer devices. They can cost as little as $20 to $50 for basic models. Combined with freely available software, they can intercept and transmit on radio frequencies that older systems assumed were secure through obscurity.
How Lin Got Caught
The trail back to Lin was short. When the rail network detected the false alarm, operators attempted to verify its source over radio. Lin apparently answered in an awkward manner and hung up. That was enough to trigger a full review.
The rail network checked all beacons in use, then reviewed CCTV footage. Working with police, investigators followed the signal trail to Lin's home in Taichung. There they found a laptop and several radios.
Lin is currently out on bail of approximately $3,200. He faces up to 10 years in prison. His defense? He claims he accidentally pressed a button on a radio in his pocket. Investigators are not buying it.
The Bigger Problem
Lin's laptop reportedly contained information on how to access communications for the New Taipei Fire City Department and the Taoyuan International Airport MRT Line. The discovery has triggered a national security review extending well beyond the rail system.
“If a college student could hack into a system as sophisticated as that of the high-speed rail system, what would happen if the same thing happened with the Taiwan Railway Corp's system?”
— Ho Shin-chun, Democratic Progressive Party Legislator
The incident has sparked political finger-pointing over who bears responsibility for the security lapse. A formal review of all affected radio systems is now underway.
A Missed Opportunity for Responsible Disclosure
Taiwan has a progressive attitude toward security research. The country's g0v (gov-zero) movement has built a culture of civic hacking, where citizens identify government vulnerabilities and report them through proper channels. Lin could have disclosed his findings responsibly and potentially been thanked rather than prosecuted.
Instead, he chose to test his discovery on live infrastructure. The 48-minute delay affected thousands of passengers. And Lin now faces a decade behind bars for what amounts to a preventable stunt.
Infrastructure Security Cannot Age in Place
The core lesson here is not about one student's poor judgment. It's about what happens when critical infrastructure security is configured once and never revisited. Encryption key rotation exists for a reason. Attackers get 19 years of opportunities to crack static keys. Computing power increases. Vulnerabilities in encryption schemes are discovered and published.
TETRA systems are used worldwide for emergency services, public transportation, and critical infrastructure. Many were installed in the early 2000s. Taiwan is unlikely to be the only country where key rotation was skipped at installation.
Logicity's Take
Frequently Asked Questions
What is a software-defined radio (SDR)?
An SDR is a radio system where components traditionally implemented in hardware are instead handled by software. This makes them flexible, cheap, and capable of operating across many frequencies. Basic SDR receivers cost $20 to $50.
What is TETRA and why is it used for rail systems?
TETRA (Terrestrial Trunked Radio) is a professional mobile radio standard used globally by emergency services, transportation, and critical infrastructure. It offers group communication, encryption, and reliable coverage in challenging environments.
What is cryptographic key rotation?
Key rotation is the practice of regularly replacing encryption keys. This limits the damage if a key is compromised and makes it harder for attackers to crack keys through long-term analysis. Most security standards recommend rotating keys annually or more frequently.
Could this attack happen on other rail systems?
Potentially. Many TETRA systems worldwide were installed in the same era. If key rotation was not configured at installation, similar vulnerabilities may exist. The Taiwan incident has prompted calls for global review of legacy radio infrastructure.
What penalties does Lin face?
Lin is out on $3,200 bail and faces up to 10 years in prison. The exact charges have not been fully detailed, but they relate to disrupting critical infrastructure.
Another look at how major systems handle user data and security
Need Help Implementing This?
Source: Latest from Tom's Hardware
Huma Shazia
Senior AI & Tech Writer
Related Articles
Browse all
Alienware AW2726DM Review: The $350 QD-OLED Gaming Monitor That Changes Everything
Dell's Alienware AW2726DM shatters the OLED gaming monitor price barrier at just $350, delivering 27-inch QHD resolution, 240Hz refresh rate, and Quantum Dot color that rivals monitors costing twice as much. This isn't an incremental price drop. It's a complete reset of what budget-conscious gamers can expect.

iPhone Fold Launch 2026: Apple's First Foldable Could Capture 19% Market Share Instantly
Apple's long-awaited foldable iPhone is finally coming, and analysts predict it'll rocket the company to third place in the foldable market behind Samsung and Huawei. The secret weapon? Some seriously clever material science that could solve the crease problem that's plagued every foldable phone so far.

FAA Approves Military Laser Weapons for Drone Defense: What the New Airspace Rules Mean for Border Security
The FAA has given the Pentagon full approval to use high-energy laser systems against drones in US airspace, ending a two-month standoff that started when lasers shot down party balloons mistaken for cartel drones. The decision comes after safety assessments concluded these weapons don't pose increased risk to civilian aircraft.

China Chip Subsidies Reach $142 Billion: 3.6x More Than US Spent on Semiconductor Manufacturing
A new CSIS report reveals China has poured $142 billion into semiconductor subsidies over the past decade, dwarfing US spending by a factor of 3.6. But here's the twist: despite this massive investment, Chinese chipmakers still lag years behind TSMC and struggle with abysmal yields at advanced nodes.
Also Read

Claude Design vs ChatGPT vs NotebookLM: Infographic Test
A tech writer tested three AI tools on the same task: creating a detailed Raspberry Pi 4 infographic. Claude Design, ChatGPT Images 2, and NotebookLM each took different approaches. Only one produced accurate, usable results.

Qualcomm Launches Snapdragon 6 Gen 5 and 4 Gen 5 Chips
Qualcomm extends its Gen 5 lineup to budget and mid-range phones with two new processors. Both chips promise better battery life and smoother interfaces, though some features from the previous generation have been cut.

Anthropic Adds 'Dreaming' to Claude Agents for Error Learning
Anthropic is rolling out three new features for its Claude Managed Agents platform. The headline addition is 'Dreaming,' which reviews past agent sessions to identify patterns and share insights across future interactions. Two other features, Outcomes and Multiagent Orchestration, are moving from research preview to public beta.