/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Researchers reveal a hotel keycard hacking technique that can let a hacker almost instantly open RFID-based Saflok locks used in 3M doors across 13K properties

The company behind the Saflok-brand door locks is offering a fix, but it may take months or years to reach some hotels.

Wired Andy Greenberg

Context & Ripple Effects

This disclosure extends a recurring pattern in hospitality access control: earlier research found that Vingcard Vision locks could yield a master key from an old card and inexpensive reader. The new case matters because Saflok’s deployment spans a far larger installed base and its remedy must move through individual properties.

The coverage also documents how known lock weaknesses have been exploited in hotel theft, making the gap between vulnerability disclosure and on-property remediation operationally significant. Past misuse of a known hotel-lock bug illustrates why patch rollout—not only the technical fix—determines exposure.

First-order effects

  • Hotels using affected Saflok RFID locks must assess and deploy the vendor’s fix, while some properties remain exposed during a rollout that may take months or years.
  • Guests and hotel operators face an immediate physical-access security concern because the disclosed technique can open affected doors almost instantly.

Second-order effects

  • The slow remediation cycle makes inventory, access-control procedures, and coordination between the lock vendor and each property central to risk reduction—an example of an earlier hotel-lock master-key flaw whose impact also extended beyond a single site.
  • Competing lock providers and hotel buyers are likely to face closer scrutiny of how quickly they can identify affected installations and deliver security updates across deployed hardware.

Third-order effects

  • If repeated disclosures continue to expose long-lived access systems, physical-security purchasing will increasingly weigh lifecycle patchability and deployment support alongside lock features.
  • The broader issue is ecosystem cyber defense: a vendor fix does not resolve a fleet-wide vulnerability until thousands of independently operated properties can implement it.

The trend: Connected and RFID-based physical access systems are making security-update capacity a defining part of infrastructure resilience.

Discussion

  • @LukaszOlejnik@mastodon.social Lukasz Olejnik on mastodon
    Forgot your hotel room keys/card?  No problem.  It's easy to hack them and get into any.  It's cheap and easy!  You only need a single card to any room to enter any other.  Vulnerability is being fixed. https://unsaflok.com/
  • @ErikJonker@mastodon.social Erik Jonker on mastodon
    “Two quick taps and we open the door,” says Wouters, a researcher in the Computer Security and Industrial Cryptography group at the KU Leuven University in Belgium.  “And that works on every door in the hotel.”  —  https://www.wired.com/...  #hacking
  • @savagepardon @savagepardon on x
    “Now, more than a year and a half later, they're finally bringing to light the results of that work: a technique they discovered that would allow an intruder to open any of millions of hotel rooms worldwide in seconds, with just two taps.” https://www.wired.com/...
  • @binitamshah Binni Shah on x
    Hackers Found a Way to Open Any of 3 Million Hotel Keycard Locks in Seconds : https://unsaflok.com/ More : https://www.wired.com/... [video]
  • @weldpond Chris Wysopal on x
    Hackers found a way to open any of 3 million hotel SafLok keycard locks in seconds using a valid keycard, 2 blank keycards and RFID read-write device like Flipper Zero https://www.wired.com/... [image]
  • @iethics @iethics on x
    #Cybersec researchers “taking a more cautious approach, while still warning the public about their technique, given that hundreds of properties will likely remain vulnerable to it even now that [the company] has offered its fix”: https://www.wired.com/... #ethics #business #tech
  • @lennertwo Lennert on x
    In 2022 we found vulnerabilities in dormakaba Saflok hotel locks. Reading one RFID card enables us to forge a pair of cards that open any door in that hotel! Dormakaba is currently working with its customers to fix the 3 million affected locks. https://www.wired.com/...
  • @_videoman_ David M. N. Bryan on x
    Well this will be fun: https://www.wired.com/... Pro-tip: Test your stuff before deploying to customers.
  • @breizh2008 @breizh2008 on x
    Hackers Found a Way to Open Any of 3 Million Hotel Keycard Locks in Seconds https://www.wired.com/... The company behind the Saflok-brand door locks is offering a fix, but it may take months or years to reach some hotels
  • @a_greenberg Andy Greenberg on x
    Security researchers found flaws in Saflok hotel keycard locks, used on 3 million doors in 13,000 properties worldwide, that can be used to open them in seconds. The lockmaker Dormakaba has been working on a fix but told them only 36% of locks are updated. https://www.wired.com/.…
  • r/netsec r on reddit
    Unsaflok: Master Keys for dormakaba Saflok Hotel Locks