Crosswalk speakers across Silicon Valley played fake voices last April.

How a small prank went public

At roughly 20 pedestrian crossings in and around Silicon Valley, people pushing the walk button heard something odd: prerecorded messages that didn't say "wait" or "safe to cross." Instead, the tiny speakers broadcast altered voices claiming to be well-known tech billionaires. The incident began in the early hours one night last April and, in time, the same vulnerability turned up in intersections as far away as Seattle and Denver.

The prank wasn't subtle.

At one Menlo Park crossing a spoofed voice attributed to Mark Zuckerberg warned that people wouldn't be able to stop artificial intelligence from being "forcefully" inserted "into every facet of your conscious experience." At another location, the same fake voice celebrated "undermining democracy." And an altered Elon Musk voice at one intersection described President Donald Trump as "actually really sweet and tender and loving," while elsewhere the impostor Musk voice complained about loneliness. The recordings were uploaded wirelessly to the devices and triggered each time someone pressed the button.

The behaviour of the attackers — and the choice of messages — made the episode more than a prank. Officials in Menlo Park, Redwood City and Palo Alto called it embarrassing. Then the problem spread.

Why the speakers were so easy to hijack

The root cause was simple: installers left factory passwords in place and the devices sat on open wireless links, which let outsiders upload audio files.

Many of the crosswalk button systems were managed by vendors and installed under municipal contracts that didn't spell out digital security requirements. Redwood City's files show the city's contract required contractors to "use reasonable diligence and best judgment" but didn't say anything explicit about passwords, account locks or remote access controls.

That lack of specificity left gaps for anyone who knew how the devices communicated. Former employees of the button-maker told investigators and security experts that the units were designed to accept firmware or audio uploads over wireless links. If those links weren't locked down — if the password remained the factory default or was publicly documented — then an outsider could wirelessly push new audio files without ever touching the equipment.

This wasn't some exotic hack. It happens when networked gear is exposed and basic hardening — like changing passwords and locking remote access — hasn't been done.

City officials scrambled — and asked who’s to blame

Emails and internal messages obtained under public-records rules show the scramble inside city halls. In Redwood City, then-city manager Melissa Diaz asked staff to figure out responsibility: "We need to understand who should be accountable for the security of these systems and what we can do to hold either staff or the external responsible party accountable," she wrote in the days after the incident.

Nick Mathiowdis, Redwood City's communications manager, said staff have been working on fixes but declined to detail them publicly to avoid giving would-be hackers a how-to guide. "We're addressing the issue based on lessons learned and evolving best practices," Mathiowdis told investigators, while resisting requests to share technical specifics.

Federal Highway Administration officials briefly investigated the tampering. Edward Fok, a veteran cybersecurity official at the agency who examined the case before leaving the post, said cities need clearer contract language about cybersecurity when buying and installing tech for roads and crossings. "Cities need to do a better job ensuring that cybersecurity clauses are baked into contracts with suppliers and installers of technology," Fok said.

That's both a governance and technical failure. Procurement rules often trail how these devices behave once they're hooked to municipal networks.

What vendors and regulators said

The agency overseeing highway safety issued a technical advisory before this incident, urging steps to protect roadside devices, and reiterated those points after the crosswalk tampering surfaced. The advisory recommended measures aimed at keeping pranksters from endangering pedestrians, according to the agency's statement.

Vendors that supply audio-enabled buttons and intersection controllers have long faced questions about the security of low-cost, widely deployed kit. Former employees of one manufacturer told investigators that installers and municipal clients sometimes prioritised rapid deployment and low cost over hardening networked interfaces.

That approach can work for a while. But when devices are put on public networks, public safety rules change. Hacky, attention-grabbing stunts can become serious if they coincide with heavy traffic, emergency responses or other stressors on street infrastructure.

Broader implications for municipal tech

Cities are buying more connected gear all the time. Cameras, vehicle sensors, smart lighting and pedestrian aids are all part of modern transport planning. But procurement teams often treat these items like hardware purchases: pay for a box and a warranty, then expect it to run. Digital access control, logging, firmware updates and password management are afterthoughts.

When contracts say only to use "reasonable diligence," they leave interpretation wide open. Who decides what's reasonable? If a vendor ships devices with factory passwords that are documented online, the buyer has to insist on change-management procedures. If the installer connects units to municipal networks without segmentation, the whole system can be reached from the wrong place.

Security experts give unglamorous advice: change default passwords, add access controls, segment municipal networks, keep firmware updated, and put explicit security requirements into contracts so they survive staff turnover. Municipalities also need testing regimes that simulate attacks before equipment is made public. None of those measures is invented in a lab — they're basic hygiene that too many projects still skip.

And Not just about avoiding embarrassment. The crosswalk incident showed how a small oversight can ripple into multiple jurisdictions, forcing police, IT teams and communications staff to divert time and resources to put things right.

Who pays when infrastructure is hacked?

Redwood City's internal debate about accountability highlights a thorny question: when procurement, installation and maintenance are spread across suppliers, contractors and city staff, who bears ultimate responsibility for cyber hygiene? Diaz's message asking for clarity echoed across municipal governments when the tampering reached other cities.

Insurance may cover some losses, but reputational damage and the time spent by officials in meetings and patching systems are real costs. Vendors that argue they provided "reasonable" service don't always bear the same legal exposure as a city if a contract's language is vague. That gap makes clear, hard contract terms more important.

City officials have started to amend procurement templates to include digital-security checklists and explicit password-management requirements. Some departments are insisting on signed attestations from installers that devices were hardened before going online. Others are running scans of deployed gear to find factory-default accounts.

Those are the band-aids. The deeper work is embedding cybersecurity into procurement decisions from the start.

Lessons for other towns and transit agencies

Cities and agencies outside Silicon Valley have every reason to take notice. The crosswalk hijack wasn't a targeted physical attack; it was an exploitation of commonplace settings that can exist in any networked device. A transit authority, a small town or a regional transport body could face the same risk.

Public officials should insist on clauses that specify password policies, update practices and remote-access controls. They should demand audit logs and the ability to push emergency fixes. And they should treat any wireless or internet-connected element of infrastructure as a component that needs ongoing maintenance, not a one-off purchase.

Point is, the hack that produced silly, creepy and at times politically charged messages also exposed a gap in how municipalities buy and manage technology. The prank was dumb, but the lesson is real.

Related Articles

"Cities need to do a better job ensuring that cybersecurity clauses are baked into contracts with suppliers and installers of technology," said Edward Fok, veteran Federal Highway Administration cybersecurity official.

This article was created with AI assistance.