The latest piece of tech that can unexpectedly be hacked: a 'nutrunner' wrench, which had over 20 vulnerabilities that'll be patched out in January

A cyberpunk landscape from Cyberpunk 2077 under an image of a smart nutrunner wrench built by Bosch.
(Image credit: Bosch / CD Projekt Red)

I really feel like we're nudging towards the Cyberpunk: 2077-style future where netrunner hackers will basically become wizards, able to explode just about anything with a few lines of rogue code. Okay—the reality may be far more boring, but considering they put DRM in trains a while back I'm crossing my fingers for cyber sorcerers in the next few decades.

The latest in this list of surprisingly hackable tech? The Bosch Rexroth NXA015S-36V-B—also called a nutrunner, which is a type of torque wrench that came into use nearly 100 years ago and just so happens to share a lot of letters with 'netrunner'. We live in a world of beautiful coincidences.

As detailed in a report by the security firm Nozomi. A squad of security experts found a whopping 25 different vulnerabilities in the wrench, which wirelessly connects to a manufacturer's internal network. Also, it runs on Linux—or, well, the Linux-based NEXO-OS.

Unlike the superfluous anti-competitive nonsense applied to those Polish trains, the Nutrunner's always-online wrench software is actually there for a good reason. Having access to an application allows engineers to adjust the final torque levels of fastenings to a granular degree, which is important for everyone's safety. 

"As an example," the report reads, "bolts, nuts and fixtures used in electrical switchboards must be torqued appropriately to ensure that connections between current carrying components, such as high voltage busbars, maintain a low resistance. A loose connection would result in higher operating temperatures and could, over time, cause a fire."

While the sentence 'there's a hackable wrench' is very funny, the potential security risks here are serious to a harrowing degree. There's the business side of things, of course—Nozomi thinks that these vulnerabilities could be used for ransomware attacks. 

An image of a wrench that has been hacked as part of a security study by Nozomi Networks, demanding its user pay bitcoin.

(Image credit: Nozomi Networks)

A more disturbing possibility is that these weak spots would "allow the threat actor to hijack tightening programs while manipulating the onboard display, causing undetectable damage to the product being assembled or making it unsafe to use."

It's a worst-case nightmare scenario and supervillain-tier levels of evil, but the concept of a rash of invisibly-caused industrial accidents happening months after the attack is genuinely a little scary. This isn't just a theory they have, either—the security team fully pulled it off:

"We managed to stealthily alter the configuration of tightening programs, such as by increasing or decreasing the target torque value. At the same time, by patching in-memory the GUI on the onboard display, we could show a normal value to the operator, who would remain completely unaware of the change."

In an email statement highlighted by Ars Technica, Bosch Rexroth "immediately took up this advice and is working on a patch to solve the problem", which it says will be released at the end of January 2024. There's patches for wrenches, now—what a time to be alive.

Harvey Randall
Staff Writer

Harvey's history with games started when he first begged his parents for a World of Warcraft subscription aged 12, though he's since been cursed with Final Fantasy 14-brain and a huge crush on G'raha Tia. He made his start as a freelancer, writing for websites like Techradar, The Escapist, Dicebreaker, The Gamer, Into the Spine—and of course, PC Gamer. He'll sink his teeth into anything that looks interesting, though he has a soft spot for RPGs, soulslikes, roguelikes, deckbuilders, MMOs, and weird indie titles. He also plays a shelf load of TTRPGs in his offline time. Don't ask him what his favourite system is, he has too many.

Read more
Nvidia RTX 4090 Founders Edition graphics card
A single RTX 4090 managed to brute force crack an Akira ransomware attack in just 7 days
Mister Fantastic giving a thumbs up
A Marvel Rivals player has uncovered 'one of the most dangerous vulnerabilities a game can have' that'll let cheaters take over your PC and find your passwords
Three Magikarp Pokémon
The FBI used self-destruct on malware infecting over 4,000 US computers, it's super effective
Neuralink
In 2024 Elon Musk predicted that 'hundreds of millions' of people will have his brain chips within the next 20 years, so don't forget to hold him to it
PC Gamer new products box illustration
PC Gamer's biggest hardware stories of 2024: Elon Musk, the rise and rise of AI, brilliant builds, the humbling of big tech giants, orb pondering aplenty, and much more
A goblin with sharp teeth, wearing goggles, lets out a mischievous cackle in WoW's latest patch: Undermine(d).
The hooligan hacker guild that tore up WoW's newest raid (twice) just posted video evidence of the whole thing, and it's got me feeling weirdly nostalgic
Latest in Hardware
Crucial X9 external SSD on blue background
You can pick up the 2 TB version of my favorite budget external SSD for less than $0.06 per GB, transfers 300+ GB of data in 6 minutes
AMD Strix Point APU chip, held in a hand, with the reflected light showing the various processing blocks in the chip die
AMD's next-gen 'Gorgon Point' APU outted and seemingly sticks with RDNA 3.5 graphics which is disappointing for handheld gaming PCs if accurate
The Lenovo Legion LOQ gaming laptop on a blue background
Okay, so it's not technically in the Amazon Big Spring Sale, but this is the cheapest RTX 4070 gaming laptop you'll find today
A close-up photo of an Nvidia RTX 4070, with its heatsink removed, showing the AD104 GPU die and the surrounding Micron GDDR6X VRAM chips
With Nvidia Ace taking up 1 GB of VRAM in Inzoi, Team Green will need to up its memory game if AI NPCs take off in PC gaming
A collage of Radeon RX 9000 series graphics cards, as shown in AMD's promotional video for the launch of RDNA 4 at CES 2025
AMD's CEO claims 9070 XT sales are 10x higher than all previous Radeon generations but that's just for the first week of availability
Samsung 3D monitor
Samsung has a crack at ye olde glasses-free 3D monitor thing but its new cheaper 49-inch ultrawide OLED is far more interesting
Latest in News
Ciri in The Witcher 4
The Witcher 4 won't be out until sometime in 2027 at the soonest, CD Projekt says
Dwarf Fortress adventure mode art
After 23 years of making Dwarf Fortress, even its creator is still 'terrified' of drowning all his dwarves with aquifers: 'Part of the problem is we are just not good at videogames'
A unique aspect of Japanese architecture turned out to be a key reason the Like a Dragon games can reuse assets so effectively—and deliver more compact, memorable open worlds than western cities
Pacific Drive Endless Expeditions spring 2025 update trailer still - a sexy, tricked-out 1980s station wagon being blasted with magic healing electricity
Pacific Drive developers change their mind: A year after refusing to give it mid-run saves, it's getting mid-run saves
Starfield's companion robot giving a thumbs-up
Former Bethesda dev who quit Starfield to go solo says it's 'much less stressful as an indie' without daily meetings or 'office politics': it's 'very refreshing to just care about the game'
Schedule I drug deal going down
Forget REPO, Monster Hunter Wilds and Assassin's Creed Shadows, Steam's current global top seller is an early access game about managing a drug empire