Source-led article
MeitY Orders App Stores to Remove E-Rickshaw Disabling Apps Amidst Security Scare

In a significant move to safeguard public safety and the livelihoods of e-rickshaw drivers, India’s Ministry of Electronics and Information Technology (MeitY) has ordered Google Play and the Apple App Store to remove mobile applications capable of remotely switching off electric rickshaws. This directive, issued on July 3, 2026, comes after viral social media videos demonstrated a severe security vulnerability where individuals could halt moving e-rickshaws using their smartphones via Bluetooth.
The incident has brought to light critical software-level protections needed for India’s rapidly expanding electric vehicle (EV) fleet, particularly in the low-cost transport sector. MeitY officials confirmed that two such applications have already been pulled, with further actions anticipated to prevent potentially damaging apps from surfacing.
The Viral Prank That Triggered Action
The trigger for MeitY’s intervention was a series of short video clips circulating on social media. These videos showed individuals pairing their smartphones with the battery systems of moving e-rickshaws in Delhi and then cutting their power, leaving drivers stranded. This prank exposed a dangerous flaw in the security of some electric rickshaws, which form the backbone of last-mile transport across many Indian cities.
Many of these budget e-rickshaws, often built with imported parts, lack robust software authentication for their Battery Management Systems (BMS). This oversight allowed anyone within Bluetooth range (typically 10-15 meters) with a compatible app to connect and disable the vehicle.
Key facts
| Aspect | Detail |
|---|---|
| Date of Order | July 3, 2026 |
| Issuing Authority | Ministry of Electronics and Information Technology (MeitY) |
| Platforms Affected | Google Play (Android), Apple App Store (iOS) |
| Vulnerability | Remote disabling of e-rickshaws via Bluetooth-connected BMS apps |
| Apps Flagged | BAT-BMS, Lossigy, Epoch-i-ion |
How the Apps Exploit a Flaw
Reports indicate that apps like BAT-BMS, Lossigy, and Epoch-i-ion were flagged for removal. BAT-BMS, for instance, was developed by China’s Shenzhen Grenergy Technology as a companion app for Bluetooth-enabled lithium-ion batteries. These Battery Management System (BMS) tools are designed for owners and technicians to monitor battery health and toggle discharge on or off for servicing purposes. However, it is this very control feature, when lacking proper authentication, that enabled misuse.
The vulnerability is specific to e-rickshaws equipped with Bluetooth-enabled lithium-ion batteries whose BMS either has no password or still operates on factory-default credentials. Vehicles using older lead-acid batteries or branded EVs with encrypted systems are not susceptible to this particular exploit. Once disabled, the e-rickshaw cannot be restarted with the ignition key until the battery setting is restored via the app.
Government Response and Future Implications
S. Krishnan, Secretary of MeitY, stated that the apps came to the government’s attention just a day prior to the removal orders. He emphasized that app stores must exercise due diligence in vetting applications, and the Centre plans to engage with platforms to prevent such damaging apps from appearing. The Delhi Transport Department has also initiated its own investigation into the matter.
This incident underscores a growing concern as India rapidly expands its EV fleet. The software components within these vehicles, particularly the BMS, will require the same level of scrutiny and security as the physical hardware. MeitY has indicated that more app takedowns could follow if additional problematic applications are identified, signaling a push for tighter vetting processes from app platforms. For India’s digital economy and its burgeoning EV sector, ensuring robust cybersecurity at every layer, from hardware to companion apps, is paramount.