What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

No evidence in the cited warning shows that millions of LoRaWAN devices were hacked. IOActive’s January 2020 paper said millions of devices were connected to LoRaWAN and described ways insecure implementations and deployments could be attacked. That is a statement about the technology’s scale, not a count of compromised devices.

LoRaWAN has built-in authentication and encryption, but those protections depend on how devices, keys, servers, and network operations are configured and maintained.

What the “millions of devices” warning means

IOActive’s January 2020 white paper, LoRaWAN Networks Susceptible to Hacking: Common Cyber Security Problems, How to Detect and Prevent Them, discussed security weaknesses and possible attacks. Its abstract used “millions of devices” to describe how many were connected to LoRaWAN; it did not report that millions had been hacked, identify a compromise count, or provide a census method.

The paper is a security analysis, not current incident telemetry. Its findings are useful for understanding possible weaknesses, but should not be read as proof that every LoRaWAN device—or any particular commercial network—was vulnerable or compromised.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
IoTeikXgo Indoor LoRaWAN Gateway with MT7628 MCU, SX1302+SX1250 LoRa Chip
  • High-Performance LoRaWAN Gateway: Powered by MediaTek MT7628 processor and Semtech SX1302 with dual SX1250 chips, this gateway offers 10 programmable parallel demodulation paths and advanced packet forwarding, ensuring stable, efficient, and reliable LoRaWAN data transmission
  • Wide Coverage & Strong Signal: The ThinkNode G1 LoRaWAN gateway provides 5 to 10 km of LoRaWAN coverage with high sensitivity up to -139 dBm @ SF12 and max 26 dBm transmit power, ensuring long-range, stable, and reliable communication for various IoT applications
  • Dual Network Connectivity & Flexible Deployment: Supports stable WiFi and RJ45 Ethernet connections for flexible deployment. Built-in IEEE 802.11 b/g/n wireless and 10/100M Ethernet port ensure reliable network access and stable LoRaWAN gateway performance
  • Flexible Network Server Support: Compatible with Various Network Servers. Equipped with advanced packet forwarding technology, it seamlessly supports multiple LoRaWAN network servers including The Things Network (TTN), ChirpStack, etc., offering flexible network service options
  • User-Friendly Web UI & Effortless Configuration: Equipped with professional management tools and cloud services, easily configurable through a user-friendly Web interface, enabling rapid deployment and efficient management. Easy deployment simplifies setup and accelerates IoT project implementation

Is LoRaWAN secure by design?

LoRaWAN specifies security mechanisms, including unique 128-bit network and application session keys, AES-based authentication and integrity, and application-level end-to-end payload encryption. In the architecture, gateways relay traffic between end devices and a network server, which routes it to an application server. The specification describes session keys derived from device root keys and assigns root-key storage and derivation operations to a Join Server. See the LoRaWAN Specification v1.1 and the Alliance’s security explanation.

Encryption does not make a deployment unhackable. The LoRa Alliance Technical Committee warns that devices and networks can be compromised if keys are not kept safe, are not randomized across devices, or if cryptographic nonces are reused. IOActive also discusses risks including hardcoded or guessable keys, weak server credentials, server vulnerabilities, reverse engineering, and threats involving manufacturers or deployment technicians. These are possible attack paths described by the sources, not proof that each is widespread today.

Rank #2
Private LoRaWAN Gateway (US 915MHz) | Built-in Local Server & Node-RED | 8-Channel Indoor IoT Hub for Smart Agriculture | No Monthly Fees, All-in-One Edge Server
  • NO SUBSCRIPTION FEES & PRIVATE LORAWAN NETWORK: Build a local LoRaWAN IoT network with the built-in SIoT server and pre-installed Node-RED. Collect data, create dashboards, and run automation flows locally without required cloud service fees. Suitable for DIY makers, home gardeners, educators, and small IoT prototype projects.
  • LOCAL DATA PROCESSING & PRIVACY CONTROL: Sensor data can be processed on the local network through the built‑in MQTT/SIoT server, reducing reliance on third‑party cloud platforms. Local automation rules continue running when internet access is unavailable — suitable for home, garden, greenhouse, and classroom IoT setups.
  • 4KM COVERAGE & 8-CHANNEL RELIABILITY: Equipped with the SX1302 8-channel LoRaWAN chip, -140dBm sensitivity, 27dBm max transmit power, and included 5dBi antenna. Supports up to 4km coverage in open environments, helping connect garden sensors, greenhouse nodes, garages, mailboxes, and remote monitoring points.
  • NODE-RED DRAG-AND-DROP VISUAL AUTOMATION:Automation rules, data dashboards, and control logic can be built with little to no coding using the pre‑installed Node‑RED. Flows such as reading soil moisture, checking temperature, and sending relay commands are created through a visual interface — reducing setup time for maker, education, and prototype projects.
  • EASY SETUP WITH WIFI AP & MQTT INTEGRATION: Configure the gateway via Wi-Fi AP mode using a laptop or mobile device. Built-in MQTT broker supports integration with Node-RED dashboards, and other MQTT-compatible platforms. Designed for indoor residential, educational, and prototyping use; not intended for outdoor installation.

What attacks have researchers demonstrated?

IOActive’s 2020 paper describes vulnerabilities, possible attacks, detection approaches, and open-source tools. A separate paper, ChirpOTLE: A Framework for Practical LoRaWAN Security Evaluation, reports a testbed demonstration of an adaptive-data-rate denial-of-service attack using common off-the-shelf hardware and shows the feasibility of a Class B beacon-spoofing attack.

Those demonstrations establish that the attack ideas could be evaluated in the reported settings. They do not measure how often such attacks occur in deployed networks, prove that a named service was compromised, or establish the number of exposed devices.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
SenseCAP Multi-Platform LoRaWAN Indoor Gateway(SX1302-4G) - US915 (M2- US915)
  • 🟩【Support Multiple LoRaWAN Network Servers】Compatible with multiple LNS like AWS, TTN, ChirpStack, etc. via using the Packet Forwarder / Basics Station mode.
  • 🟩【Built-in LoRaWAN Network Server】Based on Chirpstack, provides a fast and reliable solution for launching a LoRaWAN network.
  • 🟩【Built-in SenseCAP Local Console for Configuration】Provides a simple setup experience to configure the device on Web UI through Wi-Fi AP and Ethernet.
  • 🟩【Support Power-over-Ethernet (PoE)】For users who need to power the gateway on Ethernet instead of an extra power supply cable, the PoE feature is also added to this device, making your deployment more reliable and faster.
  • 🟩【Wide-range Coverage and Strong Signal】Provides up to 10km of LoRaWAN coverage and strong signal, allowing users to send data with extremely long ranges at low data rates.

OTAA and ABP: security-relevant differences

OTAA (Over-the-Air Activation) and ABP (Activation by Personalization) differ in how device sessions and keys are established and maintained. Neither activation method makes a deployment secure by itself.

Approach Session keys and rekeying Operational consideration
OTAA The Things Network documentation says session keys are regenerated at each activation; the LoRa Alliance says OTAA permits rekeying. Protect root credentials and configure activation and rekeying correctly.
ABP The Things Network documentation says session keys remain until changed. Provision keys securely and manage frame-counter state. The Things Network notes that development devices may reset counters on restart, causing messages to be rejected until counters advance or the device is re-registered.

These behaviors are described in the The Things Network security documentation. Frame counters help detect replayed messages, so resetting or mishandling counter state can interfere with replay protection and normal message acceptance.

Rank #4
Sale
ELECROW LoRaWAN Gateway with ESP32-S3 Processor & SX1262 Chip ThinkNode G3
  • ESP32-S3 & SX1262 Hardware: Built with a 240MHz dual-core ESP32-S3 and Semtech SX1262 LoRa transceiver, ThinkNode G3 provides low-power LoRaWAN connectivity. The internal TCXO improves frequency stability for reliable IoT data communication
  • WiFi & Ethernet Backhaul: Connect the gateway to your network through 2.4GHz Wi-Fi or Ethernet. Use the web console to select the network mode, enter your Wi-Fi credentials or wired settings, and configure the gateway for cloud connectivity
  • Web Configuration & OTA Updates: Configure network and LoRaWAN settings from a phone or PC through the built-in web interface. Set the gateway ID, server address, region, channel, spreading factor, and time zone, then apply changes and use OTA firmware upgrades for remote maintenance
  • Single‑Channel LoRaWAN Gateway: Designed for single-channel LoRaWAN projects, G3 supports US915 frequency bands and connects LoRa nodes with cloud services through IP networks. Use it with compatible nodes and a LoRaWAN server to build smart home, agriculture, or monitoring systems
  • Flexible Development & Installation: Develop and customize applications with MicroPython or C/C++ using ESP-IDF or Arduino IDE. The compact 75 × 75 × 30 mm enclosure supports desktop, wall, or back-hanging installation, making it practical for indoor IoT deployments and prototypes
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to secure a LoRaWAN deployment

  • Protect root and session keys. Restrict access and storage, use distinct non-guessable keys rather than reusing one across devices, and include provisioning and technician workflows in the review.
  • Prevent nonce reuse. The Alliance identifies reuse of cryptographic numbers intended for one-time use as a security risk.
  • Choose activation deliberately. Use OTAA where it fits the deployment and manage its root credentials; if using ABP, account for persistent session keys and counter state.
  • Preserve frame-counter state. Ensure device and network behavior supports replay detection without unexpected counter resets.
  • Review the whole system. Assess device hardware and firmware, network server, Join Server, application server, service providers, and the people and processes involved in deployment—not just the radio protocol label.
  • Prefer certified devices and trusted providers. Certification can be useful, but it does not replace secure key handling or ongoing operational controls.
  • Check current specifications and guidance. The Alliance lists LoRaWAN Specification v1.1 as published September 15, 2023, with linked errata. Its developer guidance page lists TR007 v1.0.0 on October 27, 2025 and also links a newer v1.1.0 entry; check the latest documents before relying on version-specific recommendations. See TR007-Developing LoRaWAN Devices.

What to conclude from the headline

LoRaWAN security is neither absent nor automatic. The protocol supplies cryptographic protections, while implementation and operational choices determine whether a deployment uses them safely. The “millions” in the 2020 warning refers to connected-device scale—not a verified number of hacked devices. For an overview of the technology and standards, see the Alliance’s LoRaWAN for Developers page.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.