Researchers discover flaw in Vingcard's Vision locks, used in 140K hotels in 160 counties, that lets them create master key using $300 reader and old key card
IN 2003, FINNISH security researcher Tomi Tuominen was attending a security conference in Berlin when a friend's laptop …
Context & Ripple Effects
This finding extends a pattern Wired has tracked across physical-access security: researchers repeatedly show that shared cryptographic keys and cheap hardware defeat locks and vehicles at fleet scale. The closest precedent in hotel locks is the profile of Aaron Cashatt, who turned a bug disclosed by researchers in 2012 and $50 of hardware into 75+ room burglaries — evidence that published lock research reaches criminals, not just vendors.
The same template appeared in cars: the Volkswagen key-fob cloning research showed millions of vehicles sharing cryptographic keys that inexpensive radio hardware could exploit. Six years after the Vingcard disclosure, the Saflok hacking technique hit RFID locks across 13K properties — suggesting the hotel-lock industry's fix cycle did not close the class of vulnerability.
First-order effects
- Hotels running Vingcard Vision locks — roughly 140,000 properties in 160 countries — must rely on Vingcard for patches or lock replacement, since the master-key forgery needs only an old guest card and a $300 reader an attacker can carry casually.
Second-order effects
- Hotel chains and their insurers face pressure to audit lock firmware and re-key or upgrade estates, shifting procurement toward vendors who can push cryptographic updates rather than ship fixed-key hardware.
Third-order effects
- If the Cashatt precedent repeats, disclosure-to-remediation lag becomes the real attack window: embedded locks deployed for decades cannot be patched like software, pushing the industry toward replaceable, updatable credential architectures — the same reckoning the automotive immobilizer findings forced on carmakers.
The trend: Shared-key designs in deployed-at-scale physical security — hotel locks, car fobs, immobilizers — keep falling to low-cost hardware, and the gap between researcher disclosure and fleet-wide remediation is where the risk lives.