Chaos Computer Club hackers say they have defeated Samsung Galaxy S8's iris recognition system using a photo of victim's iris
Biometrics on smartphones … Ian Morris / Forbes : Samsung Galaxy S8 Iris Scanner Hacked In Three Simple Steps Corbin Davenport / Android Police : Members of the Chaos Computer Club have cracked the Galaxy S8's Iris scanner Timi Cantisano / Neowin : Samsung's Galaxy S8 iris scanner defeated with a print out and contact lens Raymond Wong / Mashable : Hackers reportedly bypass Samsung Galaxy S8's ‘airtight’ iris scanner Jeff Gamet / The Mac Observer : Samsung Galaxy S8 Iris Scanner Already Hacked Rachel Kaser / The Next Web : Samsung S8's iris scanner fooled by photograph of an eye Kate Bevan / Naked Security : News in brief: Dubai launches its first robocops; Samsung woes over iris recognition; IoT security criticised Lanh Nguyen / Android Authority : 5 reasons why the Samsung Galaxy S8 Plus is my daily driver Andrew Martonik / Android Central : Galaxy S8 iris scanner unsurprisingly bypassed with picture of an eye and a little time Justin Duino / 9to5Google : The Galaxy S8's iris scanner can be ‘hacked’ using a contact and an IR image BBC : Samsung S8 ‘eye security’ fooled by photo Sarah Clark / NFC World : Hackers defeat Samsung Galaxy S8 iris scanner Chris Burns / SlashGear : Galaxy S8: How to bypass the Iris Scanner with a photo and a contact lens Paul Wagenseil / Tom's Guide : Hackers Fool Samsung Galaxy S8 Iris Scanner with Photo Alex Hern / The Guardian : Samsung Galaxy S8 iris scanner fooled by German hackers Quentyn Kennemer / Phandroid : Samsung Galaxy S8's iris scanner falls prey to security group's fake eyes Chaos Computer Club Updates : Chaos Computer Clubs breaks iris recognition system of the Samsung Galaxy S8 Tweets: David Meyer / @superglaze : The promise of biometric security is so seductive, and so regularly shown to be empty http://www.zdnet.com/... #samsung #galaxyS8 #security
Context & Ripple Effects
The Chaos Computer Club's iris bypass lands weeks after Samsung's own fallback advice followed reports that the Galaxy S8's facial recognition could be fooled with a photo — meaning both of the S8's novel biometrics have now been shown spoofable within weeks of launch. The club's method is deliberately cheap: a printed photo of the victim's eye plus a contact lens to defeat liveness detection.
The stakes are higher than screen unlocking because Bloomberg-reported plans had the S8 extending biometrics to Samsung Pay authorization via facial recognition, building on existing fingerprint and iris authorization. The CCC result also extends a pattern researchers established earlier: inkjet-printed fingerprints unlocked a Galaxy S6 and Huawei Honor 7, after a reported flaw allowing fingerprint cloning on the Galaxy S5.
First-order effects
- Samsung's security messaging around the S8 is directly undercut: iris scanning, pitched as the more secure alternative when face recognition was spoofed, is now demonstrated defeatable with household materials by the Chaos Computer Club.
- S8 owners who enrolled irises for device unlock — and anyone counting on biometrics for payment authorization — face a live, documented attack path requiring only a photo of their eye.
Second-order effects
- Samsung's plan to route Samsung Pay authorization through facial recognition now carries reputational risk it did not have before this demonstration, forcing the company to defend or re-stage how biometrics gate payments.
- Rival vendors gain a marketing wedge on biometric liveness detection, while sensor suppliers face pressure to add anti-spoofing measures that survive print-and-lens attacks rather than just camera-quality demos.
Third-order effects
- Across the S5 fingerprint flaw, the S6/Honor 7 inkjet-print unlocks, and the S8's face and iris defeats, consumer phone biometrics are settling into the role of convenience factor rather than standalone security boundary — pushing the industry toward layered authentication and hardware-isolated credential storage.
- If payment networks keep accepting spoofable biometrics as authorization, regulators and banks may eventually impose explicit liveness standards for biometric payment flows, turning what is now a hacker demo into a compliance requirement.
The trend: Smartphone biometric authentication is being repeatedly defeated by low-cost presentation attacks, pushing vendors from single-biometric trust toward multi-layered, hardware-backed verification.