Profile of Aaron Cashatt, who used a known bug discovered by researchers in 2012 and $50 in hardware to compromise hotel room locks and commit 75+ robberies
ON A WARM Phoenix night five years ago, Aaron Cashatt walked down the red-carpeted hall of the second floor of a Marriott hotel … Tweets: @mstreshinsky , @a_greenberg , @a_greenberg , @hatr , @nxthompson , @issielapowsky , @harrymccracken , @josephmenn , and @nxthompson Tweets: Maria Streshinsky / @mstreshinsky : “Even in his meth addled state, he was so taken aback by his success in hacking...” Amazing. @a_greenberg @WIRED. http://www.wired.com/... Andy Greenberg / @a_greenberg : This crime spree took advantage of research presented at Black Hat five years ago last month. (There's a lesson here about bug disclosure.) Andy Greenberg / @a_greenberg : In 2012, a known bug in millions of hotel locks went unfixed. Now, meet the man who exploited it for >100 burglaries https://www.wired.com/... Hakan Tanrverdi / @hatr : 2012: “This flaw will open millions of hotel doors. All you need is 50$.” Then this guy went on a crime spree. https://www.wired.com/... Nicholas Thompson / @nxthompson : TFW you learn about @a_greenberg's expense account. https://www.wired.com/... pic.twitter.com/CIHoSgeHNG Issie Lapowsky / @issielapowsky : Here's the reason I've been terrified of staying alone in hotels with key card locks for the last year @a_greenberg https://www.wired.com/... Harry McCracken / @harrymccracken : Great story, and man did I end up hating its hotel-robbing protagonist. https://www.wired.com/... Joseph Menn / @josephmenn : Epic tale of hotel door hacking, enabled by a slow-moving vendor of the sort that dominates IoT. https://www.wired.com/... Nicholas Thompson / @nxthompson : 2012: Huge security flaw in hotel keys revealed to public 2012-2016: Crime spree! 2017?: Time to fix it? https://www.wired.com/...
Context & Ripple Effects
The arc here starts at Black Hat in 2012, where researchers disclosed a vulnerability in hotel room locks — and ends with a vendor that, per the relationships on record, never patched it, leaving deployed units exposed for years. Andy Greenberg's profile of Aaron Cashatt closes the loop: a meth-addicted burglar turned Black Hat slide deck and roughly $50 of hardware into a working room-key attack and 75+ robberies, including a floor of a Phoenix Marriott.
The story matters because it is not an outlier. Six years after Cashatt's spree began, researchers found a separate flaw in Vingcard's Vision locks — used across 140,000 hotels in 160 countries — that again let an attacker mint a master key from an old card and a few hundred dollars of gear. Same vendor category, same cheap-hardware attack shape, same industry slow to rotate credentials.
First-order effects
- Hotels running the affected unpatched locks — Marriott among the brands Cashatt hit — face direct liability exposure from guests robbed via a publicly documented technique any burglar can replicate for pocket change.
- Cashatt himself converted a conference disclosure into a repeatable criminal method, showing the immediate cost of an unpatched embedded device falls on whoever sleeps behind it.
Second-order effects
- Hotel operators are pushed toward demanding patch-and-rekey programs from lock vendors, since the 2018 Vingcard Vision master-key flaw proved the 2012 pattern was systemic rather than a one-off product failure.
- Security researchers gain leverage in negotiations with hospitality vendors: each new cheap-attack demonstration makes 'we'll patch eventually' untenable when the alternative is headline coverage of robberies.
Third-order effects
- If the pattern holds, physical access control gets absorbed into software-disclosure norms — coordinated disclosure, firmware update obligations, and breach-style liability for door locks treated as networked endpoints rather than dumb hardware.
- Conference-stage research becomes a de facto criminal playbook whenever vendors lag: the structural risk shifts from the vulnerability itself to the gap between publication and fleet-wide remediation.
The trend: Disclosed vulnerabilities in connected physical-security hardware keep resurfacing as real-world crime because vendors treat locks as appliances, not software that must be patched for the life of the building.