LOGBOOK

HELP

Quiz Entry - updated: 2026.09.18

How did researchers turn networked light bulbs into a self-spreading worm, and which assumption did the attack break?

By recovering the shared symmetric firmware-protection key shared by every lamp of one model, they could authenticate malicious over-the-air updates — and because lamps accept updates from nearby lamps over ZigBee, the infection spread by physical proximity alone, with no internet involved.

Extracting a shared firmware key enables malicious updates; nearby infected lamps propagate the worm over Zigbee across controller boundaries, without an Internet path.

* Extracting a shared firmware key enables malicious updates; nearby infected lamps propagate the worm over Zigbee across controller boundaries, without an Internet path. *

The setup: Philips Hue smart lamps deployed across a city, each speaking ZigBee (a low-power mesh radio built on IEEE 802.15.4) to a bridge and to one another. Researchers built a worm that jumps from lamp to lamp using that radio and nothing else.

Three elements made it work:

  1. A correlation power analysis attack recovered the shared firmware key. A device's power consumption varies with the data it processes, so measuring the power trace while it performs cryptography leaks the key bits — this is differential and correlation power analysis, a side-channel attack. That broke the boot loader's protection and let the researchers encrypt, authenticate and upload firmware the lamps would accept. The fatal design decision was that a single key was shared between all lamps of a given model: recover it once, own the entire product line.
  2. Control from a distance without custom hardware, using the lamps' own unmonitored and unprotected ZigBee communication rather than any internet path.
  3. Spread by physical proximity alone, disregarding the established network structure of lamps and controllers. A lamp does not need to be on the attacker's network — it only needs to be near an already-infected lamp.

The assumption that broke was the perimeter itself. Defences here watch the internet-facing bridge, but the worm never used the internet: it propagated through an air gap of a few metres, across a city, as a chain reaction. (IoT Goes Nuclear: Creating a ZigBee Chain Reaction, Ronen et al., IEEE Security & Privacy 2017.)

Tip: two transferable lessons. Never share one key across a product line — per-device keys turn a catastrophe into an incident. And remember that in a dense deployment, proximity is a network, whether or not you modelled it as one.

Go deeper:

  • doc Wikipedia — Zigbee — the radio the worm travelled on: a 128-bit-keyed mesh with a trust centre, and the weaknesses later versions had to close.

  • doc Wikipedia — Power analysis — how measuring a device's current draw recovers key bits, from simple visual inspection to the differential and correlation variants, plus the countermeasures.

  • doc Ronen et al. — IoT Goes Nuclear — the original researchers explain proximity propagation and recovery of the shared firmware key.

From Quiz: SIOT / IoT Networking and Security | Updated: Sep 18, 2026