A security research lab operating out of Singapore and Shanghai says it has seized control of the newest Starlink user terminals, describing hardware attacks that delivered full administrative access and free rein to run custom code on the dishes.
Darknavy posted the results on social media this week and told the South China Morning Post the work reopens a door into Starlink’s security that has been shut for years. SpaceX hardened its antenna designs after KU Leuven researcher Lennert Wouters demonstrated a voltage fault injection attack at Black Hat in 2022, and multiple top teams have failed to crack the updated hardware since. The lab bought a Standard Actuated terminal in Singapore in March, stripped down the antenna, and worked through its firmware.
The terminal is the node where ground meets constellation. It acts as antenna and router, and in conflict zones with no local gateway it can still reach the internet by hopping through satellites that connect to gateways in neighboring countries. Full control of that device, the researchers argue, lets them simulate, inject and intercept the protocols running between Starlink ground equipment and satellites to hunt for flaws across the network.
Skeptics want proof before treating the claim as a real break. UK security firm CyPro noted the announcement carries no affected model number, firmware version, attack method or proof-of-concept code, and no response from SpaceX, which the South China Morning Post said it had contacted for comment. CyPro also stressed that control of one user terminal would not by itself expose the satellites or Starlink’s central network. Darknavy says full technical details will come later.