Overview
- Viral videos that circulated in late June and early July showed people using battery‑management apps such as BAT‑BMS to connect over Bluetooth and stop moving e‑rickshaws by switching off a battery’s discharge function.
- Investigators say the problem is insecure design on some low‑cost lithium Battery Management Systems (BMS) that ship with Bluetooth enabled and weak or no authentication, not deliberate malware in the apps themselves.
- Central and local authorities have launched probes, MeitY asked app stores to remove BAT‑BMS and related apps as a precaution, and police in Ujjain registered an FIR and made at least one arrest over alleged extortion tied to shutdowns.
- Reality checks found mixed results: BAT‑BMS now often prompts for a password but other compatible apps can still cut power on unsecured BMS units, so the vulnerability persists only in a subset of lithium‑battery e‑rickshaws while lead‑acid vehicles and password‑protected systems remain unaffected.
- Technicians and experts advise changing default passwords, disabling unused Bluetooth modules or fitting authorised BMS units, and officials and industry voices are urging mandatory EV battery security standards and stronger app‑store vetting to prevent further harms to drivers and road safety.