Vulnerability Disclosure

Built for congressional staff, aviation trade press, and security researchers — then for readers.

Every instruction a pilot obeys is authenticated by nothing but recognition.

The voice sounds right, so the voice is right. That was a reasonable assumption for eighty years. It stopped being reasonable when AI could clone a controller’s voice and language models could generate accurate ATC jargon on demand — correct phraseology, in the identity of the specific controller who worked that position.

Aviation VHF Voice · 118.0–136.975 MHz · No Encryption · No Signature · No Challenge-Response

Last updated July 30, 2026 · Corrections welcome


What is actually missing

Air traffic control voice communication runs on unencrypted analog VHF. There is no cryptographic handshake, no digital signature, and no challenge-response.

A pilot complies with an instruction because it sounds like the controller, arrives on the expected frequency, uses correct phraseology, and makes operational sense. Authentication, in practice, is recognition.

The openness is deliberate, and it is genuinely useful — pilots need to hear other traffic, not only the controller. That is why encryption has consistently been rejected.

Controller
speaks
VHF
transmit
Authentication
VHF
receive
Pilot
complies

The trust chain. Authentication is absent.


This has already been demonstrated

At DEF CON 33 on August 10, 2025, audio engineer and aviation-transparency researcher Andrew “Helicopters of DC” Logan demonstrated the use of a cloned controller voice to instruct an aircraft to cross an active runway in front of landing traffic.
DEF CON 33 Main Track, August 10, 2025 · Talk ↗ · AIN Coverage ↗
Synthetic ATC transmissions preserved safety-critical instructions — altitude, heading, runway, frequency — with a critical-token F1 of 0.958. Word error rate was 3.9%, with a median of 0%. Speaker-embedding cosine similarity was 0.726; the paper notes that same-speaker verification typically reaches ≥0.8 for the same utterance, so 0.726 across different utterances is the striking figure.
Vu & Wei, George Washington University · IEEE ICNS 2026 · Peer-Reviewed Conference Paper · Paper ↗
The training data is free. Hobbyist websites archive thousands of hours of live controller audio, indexed by facility. The synthesis software is open source. The required hardware is commodity.
Vu & Wei Threat Model: “An adversary capable of generating synthetic ATC-style audio conditioned on publicly available recordings of controller speech… exploiting the absence of cryptographic authentication and encryption in legacy VHF voice communication architectures.”
The detail worth pausing on

The George Washington researchers found that the one dimension synthetic ATC speech does not reliably reproduce is prosody — cadence, pause structure, pitch contour. That is the detection cue. They then listed, as a limitation of their own work, that their evaluation was conducted “without explicit VHF channel modeling, radio compression artifacts, or environmental noise injection.”

The antagonist of this novel spends months of the story solving precisely that problem. The researchers named the gap as future work. The novel had already walked through it.


It has happened before, with a person improvising

DateIncident
Apr 1999A USAir flight diverted on approach to Reagan National by an unknown voice transmitting on the ATC frequency.
Dec 1999A transmitter stolen from Edinburgh Airport was used to issue false commands to aircraft.
1999A ham radio operator issued false instructions to aircraft at Manchester.
Jul 2000A controller at East Midlands Airport was compelled to transmit “Respond to my voice only” due to unauthorized transmissions.
These incidents are twenty-six years old and three of the four are British. They establish that the attack class is old. They establish nothing about the present.

What is worth noting is the reason regulators assessed them as low-severity at the time: pilots read instructions back, and impostors give themselves away with incorrect phraseology. An amateur with a transmitter cannot sustain the performance.

That is exactly the defense that has stopped working. A model trained on thousands of hours of archived controller audio does not get the phraseology wrong. It produces correct phraseology, in the identity of the specific controller who worked that position, and it can answer a read-back.

As far back as 2000, the FAA acknowledged that unauthorized people periodically use controller frequencies to issue false instructions, including “ghost transmissions” at JFK. Reporting at the time indicated that no capability existed to block or filter such broadcasts. We are not aware of any deployed since.
ABC News, August 29, 2000 · Reporter’s paraphrase, not an agency statement · 26 years old

The FAA is spending more than $32 billion. It is not buying this.

$32B+
Appropriated & Requested
2028
Target Completion
612
Radar Systems Replaced
40%
Telecom Migration Complete
$12.5 billion was appropriated for ATC modernization in the reconciliation bill signed July 4, 2025. Approximately $20 billion additional has been requested. The program targets replacement of up to 612 legacy radar systems by June 2028 and migration of legacy copper telecommunications to fiber, satellite, and wireless — approximately 40% complete.
Reconciliation bill (H.R.1), signed July 4, 2025

The program modernizes the transport layer while leaving the trust layer unchanged. It replaces the pipes. It does not verify that the voice inside the pipe is real.

The FAA entered 2026 approximately 3,544 certified controllers below its own staffing target. According to NATCA, more than 41% of certified controllers work 10-hour days, six days per week. On May 15, 2026, the FAA revised its staffing target downward from 14,633 to 12,563.
FAA Staffing Data · NATCA (National Air Traffic Controllers Association) for the 41% Figure

Fatigue degrades exactly the pattern-recognition capability that currently constitutes the only line of defense.


One question

The goal of this campaign is not a bill. It is a single question, asked on the record, at any hearing touching FAA modernization or AI in critical infrastructure:

Does the air traffic control modernization program include any capability to verify that a voice transmitted on an ATC frequency belongs to an actual controller? If not, why not — and what would it cost to add?
Download the policy brief (PDF) →

The people behind this

Ernie Ortiz
Ernie Ortiz
Retired Air Traffic Controller · Technical Adviser

Ernie Ortiz spent 35 years as an FAA air traffic controller, working some of the nation's busiest and most demanding airspace — Miami Center, Tampa TRACON and Tower, and Houston TRACON — before retiring in December 2017, capping more than 37 years of federal service that began with two years at the FBI. He served as technical adviser on HAIJACKED, checking its phraseology, procedures, and failure modes against how the job is actually done. He also spent that entire career on a frequency anyone with a radio could key up, trusting the voice on the other end because there was no other way to work; that is the vulnerability at the center of this book, and the reason he was willing to put his name on it. He and his wife, Jonna, have been married more than 36 years, have four children and twelve grandchildren, and live in Texas.

Sunny Paul Smith
Sunny Paul Smith
Author

Sunny Paul Smith is a technologist, serial entrepreneur, author, and Christian leader who has spent the past five years focused on AI. HAIJACKED started as a what-if between him and his sons, two of whom are pilots: synthetic speech has gotten cheap, fast, and convincing, while the VHF frequencies air traffic runs on stayed exactly as open as they were in 1950 — anyone can transmit, and nothing on the other end can prove who's talking. His faith runs through the book as plainly as the engineering does; the questions it asks about guilt, warning, and what a man owes his neighbor are the ones he lives with. Written with retired air traffic controller Ernie Ortiz as technical adviser, the novel argues that the FAA's $32 billion modernization is buying radar and fiber but not a way to authenticate a voice. He and his wife have five children, and they live in Virginia.


On publishing this at all

Responsible Disclosure Statement

The obvious objection to a novel about this is that it hands someone a blueprint. It’s a fair question and it deserves a direct answer.

Every element of this vulnerability was already public. It was demonstrated on stage at DEF CON in August 2025 and the video is online. The threat model was published in a peer-reviewed conference paper in April 2026. The training audio sits on hobbyist websites indexed by airport. Nothing here is a revelation.

The authors have not built, tested, or transmitted any synthetic ATC audio, and will not. Transmitting on an aviation frequency is a federal crime, chargeable under 49 U.S.C. § 46308 and 18 U.S.C. § 32. There is no demonstration on this website and there never will be — no audio, no simulation, no tooling.

The novel exists because the argument it makes is that seeing a problem does not make you the person entitled to prove it. Building the thing would have been the easy part.


HAIJACKED

HAIJACKED book cover

A security contractor in western Kansas proves that air traffic control cannot tell a real controller from a synthetic one. Four hundred and twelve people die. The President goes to war with the wrong enemy. And the only man who can find him is an NSA analyst who has to become his friend first.

Fall 2026

Only used to tell you when the book is out.