Unsaflok: Hacking millions of hotel locks
Lennert Wouters, Ian Carroll
DEF CON 32 Main Stage · Day 1 · Main Stage
Overview
In a groundbreaking presentation at DEF CON 32, security researchers Lennert Wouters and Ian Carroll unveiled "Unsaflok," a critical vulnerability impacting millions of hotel locks manufactured by Dormakaba. Their research exposed a fundamental design flaw in the widely deployed Safelok system, allowing an attacker to create a universal master key capable of opening any vulnerable hotel room door, even when secured by an internal deadbolt, by simply reading a single, discarded key card from the property. This vulnerability has persisted in the Safelok system since its inception in 1988, affecting both its original magnetic stripe and subsequent RFID iterations.

Key moments
- 0:00 Introduction and the motivation behind the research
- 1:10 History of hotel lock vulnerabilities and disclosure methods
- 2:30 Introduction to Dormakaba Safelok: scale and architecture
- 4:10 Setting up a 'hotel' for research: acquiring tools
- 5:30 Uncovering the Firebird database vulnerability and card data
- 6:05 The core finding: single card read creates master key
- 7:00 Responsible disclosure process and system upgrade efforts
- 7:45 Beginning of the live demonstration of the attack
Unsaflok: Hacking millions of hotel locks
Speakers: Lennert Wouters, Hardware Security Researcher, K Leuven University; Ian Carroll, Application Security Researcher, Seats Aero
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=4cx0RUV7i0s
Overview
In a groundbreaking presentation at DEF CON 32, security researchers Lennert Wouters and Ian Carroll unveiled "Unsaflok," a critical vulnerability impacting millions of hotel locks manufactured by Dormakaba. Their research exposed a fundamental design flaw in the widely deployed Safelok system, allowing an attacker to create a universal master key capable of opening any vulnerable hotel room door, even when secured by an internal deadbolt, by simply reading a single, discarded key card from the property. This vulnerability has persisted in the Safelok system since its inception in 1988, affecting both its original magnetic stripe and subsequent RFID iterations.
The implications of the Unsaflok vulnerability are far-reaching, impacting an estimated 3 million doors across 13,000 hotels in 131 countries. Wouters and Carroll meticulously detailed how they reverse-engineered the system, from acquiring proprietary hotel management software and hardware to understanding the cryptographic weaknesses inherent in the Mifare Classic 1K RFID cards used by the locks. Their findings highlight the enduring security challenges posed by legacy systems, especially those designed without modern cryptographic principles or robust update mechanisms.
This talk not only provided a technical deep dive into the attack methodology but also emphasized the critical importance of responsible disclosure. The researchers collaborated extensively with Dormakaba, ensuring a fix could be developed and deployed before public disclosure. The severity of Unsaflok underscores the need for continuous security auditing of critical infrastructure, particularly in sectors like hospitality where physical security directly impacts guest safety and privacy.
Background
▶ Watch: Introduction and the motivation behind the research (0:00)
The landscape of hotel lock security has seen its share of high-profile vulnerabilities over the years, often exposing fundamental design flaws rather than simple implementation errors. Wouters and Carroll contextualized their research by referencing two significant prior attacks. In 2012, security researcher Sarah demonstrated a vulnerability in Onity locks, where plugging a device into an external programming port allowed the extraction of a "site code," sufficient to generate an unlock command. Sarah's immediate public disclosure led to a widespread "hacking spree," with individuals using homemade devices to open hotel doors, resulting in thefts and significant disruption.
Six years later, in 2018, researchers from F-Secure uncovered a flaw in SA Abloy's Vingcard system. This attack allowed the creation of a master key for an entire property after reading just one legitimate key card. Crucially, F-Secure engaged in a responsible disclosure process with SA Abloy, leading to a fix before technical details were widely publicized. This approach, which Wouters and Carroll explicitly aimed to emulate, allowed for remediation without immediately exposing hotels to widespread attack.
The subject of the Unsaflok research is the Dormakaba Safelok system, a product with a complex corporate lineage. Introduced in 1988 by Computerized Security Systems (CSS) as a magnetic stripe lock, CSS was acquired by Kaba in 2006. In 2015, Kaba merged with Dorma, forming Dormakaba. This system transitioned from magnetic stripe to RFID technology but, as the research revealed, carried over foundational security weaknesses. The sheer scale of its deployment—3 million doors in 13,000 hotels across 131 countries—makes its security paramount.
The architecture of these locks is predominantly offline. The front desk server and associated computers generate key cards, but the locks themselves operate autonomously, making access decisions locally based on the data encoded on the card. This offline nature means locks do not typically communicate with a central server for real-time authentication or revocation. The only common point of interaction is via a handheld unit called the HH6, which can be plugged into a USB port on the lock to perform upgrades or retrieve audit logs. A "semi-online" variant exists, particularly in large venues like Las Vegas hotels, where Zigbee coordinators in hallways allow locks to push audit logs to the front desk. However, even in this setup, the core decision-making for door access remains entirely local to the lock and the key card. This reliance on local decision-making and the historical persistence of insecure card technologies like Mifare Classic 1K laid the groundwork for the Unsaflok vulnerability.
Key Findings
▶ Watch: Introduction to Dormakaba Safelok: scale and architecture (2:30)
The central and most critical finding of the Unsaflok research is the ability to generate a universal master key for an entire hotel property by simply acquiring and reading the data from any single key card associated with that property. This means an attacker could pick up a discarded guest key card in a hallway, use it to extract vital information, and then create a new, powerful card capable of opening any door at that hotel.
The scope of this vulnerability is staggering, affecting an estimated 3 million Dormakaba Safelok doors across 13,000 hotels in 131 countries. This makes it one of the most significant hotel lock vulnerabilities disclosed to date. A particularly concerning aspect is the age of the vulnerability: the researchers discovered that the fundamental flaw in the system's key generation and authentication process has existed since the Safelok system's initial introduction in 1988, affecting both its original magnetic stripe and subsequent RFID implementations. This means the system has been vulnerable for over three decades, pre-dating the birth of both researchers.
The vulnerability hinges on the insecure design surrounding a crucial piece of information: the Property ID. This identifier, present on every valid key card, allows an attacker to derive the necessary cryptographic keys to create specialized cards. The researchers demonstrated that by leveraging this Property ID, they could craft an "emergency level resequence card." Unlike standard guest cards, these emergency cards are designed to bypass deadbolts and force locks open, providing access even when a room is secured from the inside.
A significant positive outcome of this research was the successful responsible disclosure process undertaken with Dormakaba. Despite initial requests for an NDA (which the researchers declined), Dormakaba took the findings seriously and engaged constructively. This collaboration allowed Dormakaba to develop and distribute a fix—primarily involving updates to the locks and the adoption of more secure RFID card technologies—before the public disclosure at DEF CON 32. This approach prevented the kind of immediate "hacking spree" seen with previous hotel lock vulnerabilities, demonstrating the value of ethical hacking and responsible coordination. The market impact of this remediation was evident, as the price of previously expensive RFID encoders (required for hotels to write new key cards) plummeted from around $600 to $45 on eBay, indicating a widespread replacement effort by hotels.
Technical Deep Dive
▶ Watch: Uncovering the Firebird database vulnerability and card data (5:30)
The technical foundation of the Unsaflok attack lies in a series of weaknesses spanning software, hardware, and cryptographic design, culminating in the ability to create unauthorized master keys. The initial step for the researchers involved setting up a simulated hotel environment, which required acquiring the proprietary System 6000 software and an RFID encoder. The System 6000 software, responsible for managing hotel operations and key card encoding, presented its own set of vulnerabilities. The installation manual itself instructed users to disable all Windows security features, a glaring red flag. Once installed, the software relies on a Firebird database file containing critical configuration data and records of all generated key cards. This database, accessible with a default username and password, allowed the researchers to inspect the internal structure and data fields encoded on key cards.
The key cards themselves are typically Mifare Classic 1K cards, a technology known to be cryptographically weak and easily compromised for over a decade. The attack leverages this weakness to read and manipulate card data. The process begins with an attacker obtaining any valid or even expired guest key card from a target hotel. Using an RFID reader like a Proxmark 3, the attacker can read the Unique Identifier (UID) of the Mifare Classic card. Due to the known vulnerabilities of Mifare Classic, the researchers could then derive the keys for the various sectors on the card.
Once the sector keys are obtained, the data stored on the card can be decrypted and deserialized. This decrypted data reveals several fields, including the card's level (e.g., "level one card" for a regular guest key), the room it was assigned to, and its creation date, which helps determine if it's expired. Crucially, among these fields is the Property ID. This identifier is the linchpin of the attack. It is a unique code that identifies the specific hotel property, and it is used by the Safelok system to derive the cryptographic keys necessary to generate valid key cards for that property.
The fundamental flaw is that the Property ID, while unique to a property, is not adequately secured or authenticated during the card creation process. With the Property ID extracted, an attacker can use it to craft a new key card. The researchers specifically focused on creating an emergency level resequence card. These cards are designed for hotel staff to regain access to rooms in emergencies, even if a guest has engaged the internal deadbolt. The "resequence" aspect refers to a mechanism that updates the lock's internal sequence number, invalidating older emergency cards but ensuring the new one works. By creating such a card with the correct Property ID, the attacker effectively generates a master key.
The attack does not require direct access to the hotel's System 6000 software or the RFID encoder. Once the Property ID is extracted from a single card, an attacker can use a readily available tool like the Proxmark 3 to encode a new Mifare Classic 1K card with the crafted emergency resequence data. The lock, designed to accept keys generated with its Property ID, will validate this card as legitimate, granting access. This bypasses all standard security measures, including the deadbolt, because the emergency resequence card is designed to override such protections. The system's long-standing vulnerability stems from its reliance on a easily compromisable card technology and a key derivation scheme that does not properly protect the foundational Property ID, allowing an attacker to replicate the hotel's key-making authority.
Demo / Proof of Concept
▶ Watch: The core finding: single card read creates master key (6:05)
The demonstration provided by Lennert Wouters and Ian Carroll vividly illustrated the simplicity and effectiveness of the Unsaflok attack. The setup included a Dormakaba Safelok door lock, several RFID cards, and a Proxmark 3 device, a versatile tool for RFID analysis and manipulation.
The demo began by showing a standard "valid" guest card successfully opening the lock. However, Wouters then demonstrated that if a guest had engaged the internal deadbolt, this same valid guest card would no longer work, highlighting the normal security behavior. Next, an "expired or invalid" card was presented, which, as expected, failed to open the lock. This invalid card was crucial, as it represented the type of card an attacker might find discarded in a hotel hallway. Two additional cards, labeled "attacker cards one and two," were initially shown to be non-functional, establishing a baseline before the attack.
The core of the demonstration involved using the Proxmark 3 to compromise the invalid guest card. Wouters first tapped the invalid card to the Proxmark 3. The device then performed a series of automated steps:
- Read UID: The unique identifier of the Mifare Classic 1K card was read.
- Derive Key for Sectors: Leveraging known weaknesses in Mifare Classic, the Proxmark 3 derived the necessary cryptographic keys to access the card's data sectors.
- Read Data from Card: The encrypted data stored on the card was extracted.
- Decrypt Data: The extracted data was decrypted using the derived keys.
- Deserialize Data: The raw decrypted data was then parsed into human-readable fields.
The Proxmark 3's output was displayed, showing several critical pieces of information from the invalid card. This included confirmation that it was a "level one card" (a regular guest key), that it was "made for the lead room," and its creation date, which indicated the card was indeed expired. The most vital piece of information extracted at this stage, though not explicitly highlighted on screen but central to the attack, was the Property ID.
With the Property ID now in hand, Wouters then proceeded to reprogram one of the "attacker cards." The Proxmark 3 was used to write new data to this blank card, transforming it into an emergency level resequence card. This new card, crafted using the extracted Property ID, effectively became a master key for the property.
Finally, the re-programmed attacker card was tapped to the Dormakaba Safelok. Despite the implicit assumption that the deadbolt was engaged (as demonstrated earlier with the valid guest card), the lock immediately opened. This dramatic conclusion showcased the complete bypass of physical security measures and the successful creation of an unauthorized master key from a seemingly innocuous, discarded guest card. The demo conclusively proved that an attacker with minimal equipment and a single card could gain unrestricted access to any room in a vulnerable hotel.
Defensive Implications
▶ Watch: Beginning of the live demonstration of the attack (7:45)
The Unsaflok vulnerability presents significant defensive challenges for hotels and mandates immediate action to protect guest safety and privacy. The primary and most urgent defensive implication is the absolute necessity for hotels using Dormakaba Safelok systems with Mifare Classic 1K cards to replace all existing key cards with more secure alternatives. The researchers explicitly recommended upgrading to Ultralight C or Desfire cards, which offer superior cryptographic protection and are not susceptible to the same fundamental weaknesses as Mifare Classic. This card replacement must be accompanied by corresponding firmware updates to the Safelok locks themselves, as Dormakaba has released patches to address the underlying vulnerability. Hotels must work with Dormakaba to ensure their lock firmware is up-to-date to properly support the new, secure card technologies and to mitigate the resequencing attack.
Beyond card and firmware upgrades, hotels should re-evaluate their entire key management infrastructure. The System 6000 software and its underlying Firebird database represent a critical attack surface. Hotels should ensure that this software is installed on secure, isolated systems, not on general-purpose workstations, and that all default credentials for the Firebird database are changed to strong, unique passwords. Access to these systems should be strictly controlled and logged, as unauthorized access could provide attackers with the Property ID and other sensitive configuration data, even without needing to read a physical card.
The physical security of RFID encoders also warrants attention. While the price drop of these devices indicates widespread replacement, any older, vulnerable encoders still in use should be secured or replaced. These devices are effectively "key-making machines" and their compromise could facilitate unauthorized card generation.
Hotels should also consider the benefits of moving towards more online or semi-online lock architectures where feasible and appropriate. While the current Safelok system is largely offline, the semi-online Zigbee setup, which allows for audit log transmission, offers a glimpse into improved security. Online systems can provide real-time key revocation, centralized authentication, and more granular audit trails, making it significantly harder for attackers to exploit offline vulnerabilities or for their actions to go undetected. Even with offline systems, regular retrieval and review of audit logs from the HH6 programmer can help detect suspicious access patterns, although this is a reactive measure.
Finally, the Unsaflok case serves as a broader reminder for the hospitality industry and other sectors relying on legacy access control systems. Regular, independent security audits of these systems are crucial. Assumptions about "security through obscurity" or the longevity of older cryptographic standards are dangerous. Investing in modern, cryptographically sound access control solutions and maintaining a robust vulnerability management program are essential to protect assets and build trust with guests.
Key Takeaways
- Legacy Systems are High-Risk: The Unsaflok vulnerability highlights that systems designed decades ago, especially those with offline architectures and outdated cryptographic principles, pose significant security risks even when widely deployed.
- Mifare Classic is Compromised: The continued reliance on Mifare Classic 1K cards for critical access control, despite well-known cryptographic weaknesses, is a fundamental security flaw that must be rectified immediately.
- Responsible Disclosure Works: The successful collaboration between the researchers and Dormakaba demonstrates the effectiveness of responsible disclosure in allowing vendors to patch vulnerabilities before public release, preventing widespread exploitation.
- Single Point of Failure: The Property ID served as a critical single point of failure; its extraction from any card allowed an attacker to derive the necessary authority to generate master keys.
- Upgrade to Secure Card Technologies: Hotels must urgently upgrade from Mifare Classic 1K cards to more secure alternatives like Ultralight C or Desfire, along with corresponding lock firmware updates.
- Beyond the Lock: Securing the entire key management ecosystem, including front desk software (e.g., System 6000, Firebird database) and RFID encoders, is crucial to prevent multiple attack vectors.
About the Speaker(s)
Lennert Wouters is a hardware security researcher affiliated with the K Leuven University in Belgium. His research primarily focuses on hardware-level attacks, including techniques like voltage glitching. His expertise in understanding and exploiting the physical and electrical characteristics of embedded systems was instrumental in dissecting the Dormakaba Safelok hardware and its underlying vulnerabilities.
Ian Carroll is an application security researcher with a background in offensive security. He previously worked on the Red Team at Robinhood, where he honed his skills in identifying and exploiting software and system-level vulnerabilities. He currently runs a point search engine called Seats Aero. His experience in application security provided valuable insights into the software components of the Safelok system, such as the System 6000 software and its database, complementing Lennert's hardware focus.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
Wouters and Carroll delivered a groundbreaking piece of technical research, exposing a decades-old universal master key vulnerability in millions of Dormakaba Safelok hotel locks. Their meticulous reverse engineering, from proprietary software to cryptographic weaknesses in Mifare Classic cards, allowed them to derive a Property ID from a single discarded key card and craft an 'emergency resequence' card capable of opening any door, even with a deadbolt engaged. This talk is a critical wake-up call for the hospitality industry, demonstrating profound technical depth, immense practical impact, and a clear, compelling live demonstration.
Heather Calloway (CISO) — MUST SEE
This "Unsaflok" presentation from DEF CON 32 is a critical review of a pervasive vulnerability in Dormakaba's Safelok system, affecting millions of hotel doors globally. The researchers clearly demonstrate how a fundamental design flaw, present since 1988, allows an attacker to create a universal master key from any discarded hotel key card. This work is a stark reminder of the risks posed by legacy systems and highlights significant governance and operational accountability gaps within the hospitality sector regarding physical access control. It provides a clear, actionable path for remediation, making it essential viewing for security leaders and executives responsible for institutional…