The action follows the circulation of multiple viral videos showing people switching off moving e-rickshaws by using mobile applications. The misuse left several vehicles stranded on roads, highlighting a security vulnerability in certain battery management systems used in unbranded lithium battery packs.
The issue centers on BAT-BMS, a battery management application developed by a Chinese technology company for monitoring Bluetooth-enabled lithium batteries. The app allows users to check battery health, voltage and other operating parameters. However, it also includes a battery discharge control feature that can turn the battery’s power output on or off.
The vulnerability stems from low-cost, unbranded e-rickshaw batteries that are supplied without password protection. This allows anyone within a Bluetooth range of around 10 to 15 meters to pair with the battery and disable its power output using the app.
The flaw has raised concerns beyond inconvenience, as remotely shutting down an e-rickshaw in the middle of traffic could significantly increase the risk of road accidents, particularly when the vehicle is carrying passengers.
The government has stepped in to curb the misuse. The Ministry of Electronics and Information Technology (MeitY) has ordered the removal of three Chinese battery management applications linked to the remote shutdown capability and is working with app stores to prevent similar applications from becoming available.
The vulnerability appears to be limited to inexpensive, unbranded battery packs commonly used in e-rickshaws. Electric scooters, motorcycles and cars sold by established manufacturers are generally not affected because they use encrypted and secure battery management systems with stronger authentication mechanisms.
Drivers who encounter the issue can restore battery operation by switching off the battery’s main circuit breaker (MCB), waiting a few seconds and turning it back on. They then need to reconnect to the battery management application, re-enable the battery discharge function and change the default Bluetooth password to prevent unauthorized access in the future.
The incident has once again highlighted the importance of cybersecurity standards in connected electric vehicle components, particularly in the rapidly expanding e-rickshaw segment, where low-cost hardware and inadequate security measures can expose users to operational and safety risks.




