Hacking a Smart Kettle: No Direct API, Only Tuya Cloud

Operation Smart Kettle – Börzels Blog

Hacking a Smart Kettle: No Direct API, Only Tuya Cloud

A curious shopper buys a Wi-Fi smart kettle, expecting a local API or at least the HTTP 418 teapot joke. Instead, a man-in-the-middle setup reveals the kettle only talks to Tuya's Azure cloud over TLS, with no direct app-to-kettle traffic. The device runs Tuya firmware, and while OTA flashing to open firmware exists, this unit is too new. The adventure ends without the hoped-for hack.

Since I had not yet done any projects or hacking on smart wifi IoT devices, I had no idea how it works and what I had to expect.
  1. speedping

    Probably a beken chip, should be easy enough to flash OpenBeken using the pins if they're exposed

    You can usually take over tuya devices if you sign up for a developer account and go some sort of verification process, it's pretty easy, sometimes it's possible to get a token for local control (tuya-local)

  2. niemandhier

    If you ever ask yourself what German hackers do with their life, while our peer in the US build startups:

    That’s what we do.

  3. Asraelite

    I don't get it. A kettle is not a teapot.

More from this day

2026-09-13