At the end of the last post, I left everyone hanging, having tapped into and sniffed some data being transferred on the wires between the bike and the

Reverse Engineering a VanMoof e-shifter – Part 2 – Decoding the Signals

submited by
Style Pass
2025-01-15 14:30:07

At the end of the last post, I left everyone hanging, having tapped into and sniffed some data being transferred on the wires between the bike and the e-shifter. The questions to answer were:Is the bike the requester, or is it the responder?What speed and format was that data?What messages are being transmitted?

The reliability of this e-shifter in the X3 and S3 has been argued as the cause of the failure and eventual bankruptcy of VanMoof. If I can decode these messages, I have the opportunity to build a replacement module that could spoof the original e-shifter.

This component fails and has failed for many owners, and historically this failure occurred during the bike's warranty period. It's been suggested that VanMoof provided so many replacements that they used up their entire stock and were unable to make or sell any more bikes. We've had the e-shifter fail and be replaced twice on our bike since owning it. I really need to come up with a solution before it fails again.

By removing jumpers from the data lines on the Spy! Break! Inject! we can determine which side asks the question and which side responds.

Leave a Comment