During the first Pwn2Own Automotive, organised by ZDI in Tokyo in January 2024, Computest Sector 7 successfully demonstrated exploits for vulnerabilities in three different EV-chargers. All three could be exploited to execute arbitrary code on the charger, with the only prerequisite being close enough to connect to Bluetooth. Most of these vulnerabilities were very easy to find once the firmware was extracted. The lack of mitigations against binary exploitation meant writing the exploits was also straightforward. In this talk, we will explain the vulnerabilities we found, the exploits we developed and what lessons about IoT security in general can be learned from this.