Researchers find 12 of 16 Bluetooth smart locks they tested could be hacked and opened by unauthorized users
LAS VEGAS — Many Bluetooth Low Energy smart locks can be hacked and opened by unauthorized users, but their manufacturers seem to want to do nothing about it …
Context & Ripple Effects
This Las Vegas disclosure lands a few months after researchers showed that a radio amplification attack could extend key-fob range to unlock and start 24 cars from 19 manufacturers — the same class of short-range-wireless trust failure, now applied to door hardware instead of ignition systems.
The arc that follows confirms the pattern was structural rather than one-off: Samsung later shipped patches for SmartThings Hub flaws that exposed smart locks and cameras, and the Bluetooth SIG itself issued advisories for the KNOB encryption-key brute-force flaw before researchers detailed SweynTooth bugs capable of crashing BLE devices. The headline detail here is that most lock makers declined to act at all.
First-order effects
- Owners of the 12 vulnerable lock models face a direct physical-entry risk from anyone in radio range, since the flaw opens the door rather than merely exposing data.
- The named manufacturers come under immediate pressure to patch or pull products, made sharper by the finding that they 'seem to want to do nothing about it.'
Second-order effects
- Buyers and insurers of connected homes shift due diligence toward platforms with demonstrated patch pipelines — the route Samsung took with its SmartThings Hub fixes — penalizing standalone locks with no update path.
- Lock competitors can now differentiate on third-party security testing and coordinated disclosure, turning a research paper into a sales objection against the laggard vendors.
Third-order effects
- If the pattern holds, physical-security products get absorbed into the software-update lifecycle: standards bodies like the Bluetooth SIG issuing protocol-level advisories and hub vendors carrying device security become the norm, not the exception.
- Regulators and liability frameworks eventually treat a hackable door as a product-safety defect rather than a consumer-electronics bug, forcing certification requirements onto BLE access-control hardware.
The trend: Wireless physical-access devices are being re-judged as software products whose safety depends on coordinated patching across chip, protocol-standards, and smart-home hub layers.