How I Cracked the Flume Water Monitor Encryption in a Few Weeks

Flume Water Monitor 915 MHz Security Is Pretty Good

How I Cracked the Flume Water Monitor Encryption in a Few Weeks

I successfully broke the encryption on the Flume Water Monitor's 915 MHz RF signal after weeks of part-time work. By combining reverse-engineering insights with a brute-force attack on a reduced 44-bit key space, I decrypted the AES-128 payload. While the security is reasonable for a consumer device, the vulnerability allows for message spoofing. Flume responded positively and shared their plans to enhance future privacy and security measures.

For a consumer water sensor, a frequency-hopping waveform combined with 44-bit effective encryption on the payload is not an unreasonable level of security.

More from this day

2026-07-30