Independent security testing firm Merculite Security tested 16 Bluetooth-enabled smart locks and found that 75% of them had vulnerabilities serious enough to make them exploitable. A separate academic evaluation of 18 commercial Bluetooth Low Energy (BLE) smart locks found that 14 remained vulnerable to real attacks — a research finding the authors noted potentially affects millions of installed devices. If you're relying on a smart lock to keep your front door secure, these numbers deserve a closer look — but so does the important context most headlines leave out.
The important nuance: the overwhelming majority of these documented attacks require an attacker to be physically within Bluetooth range (typically under 30 meters) carrying specialized radio equipment, and targeting a specific model they already know is vulnerable. This is a real risk — especially for a determined, informed attacker casing a specific property — but it is meaningfully different from a random remote hacker breaking in from anywhere in the world, which is the scarier scenario most people picture.
Not all smart locks use the same technology
The connection method matters enormously for security. Bluetooth locks talk directly to your phone at close range. Z-Wave/Zigbee locks talk to a local hub over an encrypted mesh network, and the hub handles internet connectivity separately. Wi-Fi locks connect directly to your home network and the internet. Each has different tradeoffs, covered below.
Why Smart Lock Security Deserves Extra Scrutiny Compared to Other Smart Devices
It's worth being explicit about why a door lock warrants a more careful buying and setup process than, say, a smart speaker or a plug. A compromised smart speaker is a privacy problem. A compromised smart lock is a physical access problem — the failure mode is a stranger inside your home, not just data exposure. This doesn't mean smart locks are inherently a bad choice; as covered below, a well-chosen, properly maintained smart lock compares favorably to a traditional deadbolt on several dimensions. But it does mean the research-and-setup effort described in this guide is worth taking seriously rather than treating a lock the same way you might treat a smart light bulb, where a security lapse has much lower real-world consequences.
What Independent Research Actually Found
Beyond the Merculite Security and academic BLE evaluations cited above, earlier research presented at a major security conference tested 16 Bluetooth smart locks and found that 12 had either no meaningful security or poorly implemented security on their Bluetooth communication. Academic research published more recently in the Wireless Networks journal confirmed that vulnerabilities persist in smart lock ecosystems, particularly around Bluetooth Low Energy communication and companion mobile apps that don't properly validate or secure their connection to the lock.
The types of attacks documented include man-in-the-middle interception (where an attacker intercepts and modifies data passing between your phone and the lock), replay attacks (capturing and reusing a legitimate unlock signal), and exploitation of poorly secured companion apps. These attacks enable unauthorized unlocking, denial of service, and in some cases bypassing the lock's own access logging — meaning the owner might not even know someone entered.
| Connection Type | How It Works | Relative Risk Profile |
|---|---|---|
| Bluetooth (direct) | Phone connects directly to lock at close range | Independent testing found meaningful vulnerability rates in some models; attack requires physical proximity |
| Z-Wave / Zigbee (via hub) | Lock talks to a local hub over encrypted mesh network; hub connects to internet | Generally lower remote risk — no direct internet exposure on the lock itself |
| Wi-Fi (direct) | Lock connects directly to home Wi-Fi and the internet | Convenient (remote access anywhere) but depends heavily on standard IoT security hygiene |
Not sure if your smart lock or hub setup is secure?
Our certified bilingual tech remotes in, checks your smart lock and full home network setup, and locks it down — same day, from $119.99. No fix, no fee.
What to Check Before Buying a Smart Lock
Choose a brand with a real firmware update history
Before buying, check the manufacturer's support page or release notes for evidence of regular security updates over the past 1-2 years. A brand that has shipped multiple firmware updates is actively maintaining the product; an unbranded or extremely low-cost lock with no visible update history is disproportionately represented among the vulnerable models found in independent research.
Confirm the app supports two-factor authentication
Check the product listing or manufacturer's app store page for mention of 2FA/MFA support. This is one of the highest-impact features, since it means a stolen account password alone can't be used to unlock your door remotely (for Wi-Fi/app-connected locks).
Verify there's a physical key override
Nearly every reputable smart lock includes a mechanical keyway as backup for dead batteries, app outages, or firmware issues. Avoid electronics-only models with no physical override — a dead battery shouldn't mean you're locked out of your own home.
Consider Z-Wave/Zigbee if you already have a smart home hub
If you own a hub (SmartThings, Hubitat, Home Assistant, or similar), a Z-Wave or Zigbee lock avoids exposing the lock itself directly to Bluetooth-range attacks or the open internet — the hub becomes the single point to secure instead of the lock's own connection.
Securing the Smart Lock You Already Own
Change the default PIN and app password
Open the companion app and go to lock settings or account settings. Replace any default keypad PIN with a unique code, and make sure your account password is unique — never reused from another site.
Enable two-factor authentication
In Account > Security settings, turn on 2FA if your lock's app supports it. This adds a second verification step beyond just the password before anyone can access remote-unlock features.
Update the lock's firmware
Check the app's Device or Firmware section for available updates and install them. This is the direct fix for the Bluetooth and app vulnerabilities documented in independent research — manufacturers that discover and patch these issues can only protect you if the update is actually installed.
Review and remove old access codes
Open the Users/Guests/Access Codes section of the app and delete any code or shared access for a former contractor, cleaner, dog-walker, or guest who no longer needs entry. This is one of the most common real-world smart lock security gaps — not a sophisticated hack, just forgotten standing access.
If it's a Wi-Fi lock, put it on a guest/IoT network
Log in to your router (typically 192.168.1.1 or 192.168.0.1) and connect the lock to a separate guest or IoT network with client isolation. If the lock is ever compromised, the attacker stays contained and cannot reach your other devices.
Keep the physical key backup stored securely off-property
Store the mechanical backup key with a trusted neighbor, family member, or in a proper lockbox — never hidden near the door itself (under a mat, in a fake rock), which defeats the purpose of having a smart lock at all.
Renting, or bought a home with an existing smart lock?
Before relying on a smart lock left by a previous tenant, landlord, or homeowner, do a full factory reset and re-pair it under a brand-new account. Never assume the previous occupant's access was fully removed — this applies just as much to smart locks as it does to garage door openers and Wi-Fi routers left behind during a move.
Installation Security Considerations Often Overlooked
A smart lock's digital security only matters if the physical installation itself is sound. A few installation-related points worth checking regardless of which model you own: confirm the strike plate and door frame are solid — a weak frame can be defeated with simple physical force regardless of how strong the lock's electronics and encryption are, making this a more common real-world entry method than any Bluetooth exploit. Check that the lock is rated for exterior use if installed outdoors (temperature and moisture resistance affects both physical durability and, for models with exposed circuitry, potential tampering vulnerability). If a professional installed the lock, confirm the installer's own access — a temporary installer code or account — was removed once installation was complete, the same way you'd remove a contractor's access code after any other home service.
What App Permissions Does a Smart Lock App Actually Need?
Like camera apps, smart lock companion apps sometimes request more phone permissions than their core function requires. Legitimate reasons for common permission requests: Bluetooth (required to communicate with the lock directly), location (often used for auto-unlock-on-arrival features — legitimate but optional, and worth disabling if you don't use that specific feature), and notifications (for access alerts and low-battery warnings). Be more cautious of requests for contacts, SMS, or broad file storage access, which aren't typically necessary for a lock's core function — if an app requests these without a clear in-app explanation of why, it's worth researching before granting them, the same caution that applies to any smart home app.
Types of Smart Locks: Retrofit vs Full Replacement vs Padlocks
Not every smart lock is the same category of product, and the security considerations shift slightly across types:
| Type | What It Is | Security Note |
|---|---|---|
| Retrofit deadbolt (keeps existing exterior hardware) | Smart module installed on the inside over your existing deadbolt; exterior keyway unchanged | Preserves traditional key-based physical security while adding app/code access; a reasonable middle-ground option |
| Full replacement smart deadbolt | Entire lock mechanism replaced, including exterior keypad or reader | More features (dedicated keypad, biometric options on some models) but the entire lock's security now depends on the smart manufacturer's engineering, not a separate traditional mechanism |
| Smart padlocks | Bluetooth or app-controlled padlocks for sheds, gates, storage units, gyms | Same Bluetooth-related considerations as door locks apply; check for the same firmware update history and 2FA support before buying |
Battery Life and the Security Tradeoff
Nearly all smart locks run on batteries, and low battery behavior varies by model in ways that matter for security. Some locks fail "locked" (staying secured but unresponsive to app/keypad commands until batteries are replaced), while others provide an emergency external power option (a 9V battery contact point on the outside of the lock, used to temporarily power it for a low-battery unlock). Know which behavior your specific lock has before you're facing a dead battery at your front door — check the manual or manufacturer's FAQ. Set up low-battery notifications in the app (nearly universal across brands) and treat them with urgency rather than letting the lock run to a full dead stop, since some models' auto-lock and access-logging features can behave unpredictably in a low-power state. Keeping a spare set of the correct battery type on hand somewhere nearby in the entryway closet (not directly on the lock itself) removes the last-minute scramble of a dead lock at an inconvenient moment, whether that's a late arrival home or an early morning departure.
How BLE Attacks on Smart Locks Actually Work
To make the vulnerability research above concrete, here's what the documented attack types actually involve:
Man-in-the-middle (MITM) interception: an attacker with specialized radio equipment positions themselves between your phone and the lock during the Bluetooth pairing or unlock exchange, intercepting and potentially altering the data passing between them. This requires being physically close — typically within Bluetooth's effective range — at the exact moment an unlock command is sent.
Replay attacks: the attacker captures a legitimate unlock signal (again, requiring close-range presence during a real unlock event) and retransmits it later to trigger the same unlock command without ever needing your password or PIN. Locks with poorly implemented rolling codes or session tokens are more susceptible to this than ones that properly randomize each exchange.
Companion app exploitation: rather than attacking the Bluetooth link directly, some vulnerabilities researchers found were in the mobile app itself — insecure storage of credentials on the phone, or the app failing to properly validate that it's talking to the genuine lock rather than an impersonating device.
In all three cases, an attacker needs either close physical proximity with the right equipment, or a way to compromise your phone/account directly (the same credential-stuffing and phishing risks that apply to any connected device). This is why firmware updates matter so much for smart locks specifically — many of the disclosed vulnerabilities in the independent research were patched by manufacturers once found, but only for owners who actually installed the update.
Worth noting for context: relay attacks against Bluetooth-based systems are a well-known concept from the automotive world, where thieves use signal-relay equipment to extend a key fob's range and trick a car into unlocking as if the key were nearby. The underlying radio-relay principle is conceptually similar for some smart lock attack scenarios, though the specific implementation and required equipment differ between automotive keyless-entry systems and residential BLE locks — it's a useful mental model for understanding why proximity-based attacks are taken seriously by researchers even though they require more effort than a purely remote hack, and why a determined, well-equipped attacker targeting a specific known-vulnerable model is a meaningfully different threat than an opportunistic random intrusion attempt.
Keypad Code Security: Practical Best Practices
For locks with a physical keypad (common on many residential smart locks), a few practical habits matter as much as the digital security above:
- Avoid predictable codes — birthdates, repeated digits, or sequences (1234, 0000) are the first things anyone would try if attempting physical entry without electronics at all.
- Use unique codes per person where the lock supports it rather than one shared code for the whole household — this lets you revoke a single person's access (a departing roommate, an ex) without having to reprogram everyone else's code too.
- Watch for worn keys on the keypad — physical wear patterns on the most-used digits can reveal your code to anyone who examines the keypad closely, similar to the "smudge attack" concept known from touchscreen PINs.
- Set temporary codes for guests and service providers with an expiration — many smart locks support time-limited or single-use codes specifically for this; use them instead of your permanent household code whenever possible.
Do Smart Locks Affect Home Insurance?
Some home insurance providers offer modest discounts for homes with monitored smart security systems, including certain smart locks, though policies vary significantly by insurer and region — check directly with your provider rather than assuming a discount applies. On the liability side, if a smart lock is later shown to have been left on default credentials or unpatched firmware at the time of an incident, that could be a relevant factor in a claim, the same way an unlocked traditional door might be — another practical reason to keep the basic hygiene steps above current rather than a one-time setup task.
How IT Cares Approaches a Smart Lock and Entry Security Check
When reviewing a smart lock as part of a broader home security or smart home audit, we follow a consistent process: confirm the account password and any keypad PIN are unique and strong, check firmware version against the manufacturer's latest release, review the full list of active users and access codes against who the household actually recognizes, verify 2FA is enabled if the platform supports it, and — for Wi-Fi models — confirm the lock sits on an isolated network segment rather than the main household network. We also physically check the installation itself: strike plate condition, door frame integrity, and whether a mechanical key backup exists and is stored appropriately. A digitally secure lock installed in a weak door frame, or one with no working key backup, still leaves a real gap that the electronics alone can't close.
Smart Locks and Home Automation Integrations: A Security Tradeoff
Many smart locks integrate with broader home automation platforms — unlocking automatically when a linked smart doorbell confirms a recognized face, or triggering lights and thermostat changes on unlock. These integrations add convenience but also add complexity: every additional connected service the lock talks to is another account, another API connection, and potentially another point of failure if any linked service is compromised. If you use these integrations, apply the same security hygiene (unique passwords, 2FA where available, current firmware) to every service in the chain, not just the lock's own app — a weak link anywhere in an automation chain can undermine the strongest individual component. If the integration isn't providing meaningful daily value, disabling it reduces your overall attack surface without much practical loss.
A Note on Sharing Access With Family and Service Providers
Beyond simply removing old codes, it's worth being deliberate about how you grant access in the first place. Where the app supports scheduled or time-limited codes, use them for anyone whose need for entry is temporary or recurring on a known schedule — a cleaner who comes every other Tuesday, a dog-walker on weekday afternoons — rather than issuing a permanent code "just in case." For family members with ongoing need for access, individual codes per person (rather than one shared household code) make it far simpler to revoke a single person's access later without having to redistribute a new code to everyone else. This same principle — individual, scoped, revocable access rather than one shared credential — is a core security concept that applies well beyond smart locks, but a front door is one of the clearest places to see its practical value.
For short-term rental hosts specifically, time-limited codes tied to a guest's actual booking window are worth setting up as standard practice rather than an occasional precaution — automatically expiring access at checkout removes the manual step of remembering to delete a code after every single stay, which is exactly the kind of routine task most likely to be forgotten during a busy turnover between guests.
It's also worth checking your baby monitor, cameras, and doorbells for their own warning signs once the lock itself is secured, since none of these devices exist in isolation on a home network — see our baby monitor security guide and smart doorbell/camera hacked warning signs guide for device-specific checklists that complement the smart lock hardening covered here. The same fundamental principles — unique passwords, 2FA where available, current firmware, and network isolation — apply consistently across every connected device in a well-secured smart home, not just the front door, and getting into the habit of checking one device tends to make checking the rest far quicker the next time around, since the menu paths and general approach carry over from one app to the next.
Quick Reference: The Full Smart Lock Security Checklist
- Choose a brand with a real, visible firmware update history before buying
- Confirm 2FA support and a physical key override before buying
- Change the default PIN and account password immediately after setup
- Enable two-factor authentication, preferring an authenticator app over SMS where available
- Install the latest firmware and keep automatic updates on if supported
- Review and remove old access codes for anyone who no longer needs entry
- Put Wi-Fi models on a guest/IoT network with client isolation
- Store the mechanical backup key securely off-property, never hidden near the door
- Check the physical strike plate and door frame, not just the lock's electronics
As with the camera and router guidance elsewhere on this site, none of these steps require specialized technical knowledge — they're menu paths in an app and a few minutes of router configuration, addressing essentially every attack category documented in the independent research covered above.
Renters and Smart Locks: What to Know Before Installing One
If you rent, check your lease before installing any smart lock that replaces existing hardware — many landlords require either written permission or that you retain the original hardware to reinstall at move-out. If a smart lock is already installed by a landlord or previous tenant, treat it the same as any other secondhand smart device: request confirmation that the account was reset for you, or perform that reset yourself if the landlord allows it, before relying on it for security. When you move out, remove your account, delete your access codes, and reinstall the original hardware if your lease requires it — leaving a lock linked to your personal account for the next tenant is both a privacy risk for them and a liability question for you.
Smart Lock vs Traditional Deadbolt: Which Is Actually More Secure?
This is a common misconception worth addressing directly: a well-chosen, properly secured smart lock is not inherently less secure than a traditional deadbolt — traditional locks have their own long-documented weaknesses, including bump-key attacks and simple physical picking that require no electronics knowledge at all. The real comparison isn't "smart vs traditional" in the abstract, it's "a cheap, unmaintained smart lock with no updates" vs "a quality traditional deadbolt" vs "a reputable smart lock kept updated with 2FA enabled." The middle and right options are both reasonable; the first is the one to avoid.
What smart locks add that traditional deadbolts can't: individual, revocable access codes per person (so you're never handing out a physical key you can't get back), a full access log showing who entered and when, and remote lock/unlock for deliveries or guests without being home. These are real security and convenience benefits when the underlying device is properly maintained.
It's also worth checking your home Wi-Fi router for signs of broader compromise alongside your smart lock, since neither device exists in isolation on a home network — see our router and smart home hacked warning signs guide for the network-wide checklist, and our home Wi-Fi router security guide for the full hardening steps that protect every connected device in the house, including a Wi-Fi-connected lock.
Want a professional to check your whole smart home setup?
IT Cares audits smart locks, routers, and every connected device in your home — closes exposed access, sets up network segmentation, and confirms firmware is current. Most audits completed same-day, remote or on-site across Canada.
Frequently Asked Questions
Can smart locks really be hacked?
Independent testing has found real vulnerabilities in a meaningful share of consumer smart locks — Merculite Security found 75% of tested Bluetooth models had exploitable flaws, and an academic evaluation found 14 of 18 tested BLE locks remained vulnerable. Most attacks require close-range physical proximity with specialized equipment, unlike a random remote attack from anywhere.
Is Bluetooth, Wi-Fi, or Z-Wave/Zigbee safer for a smart lock?
Z-Wave/Zigbee locks generally carry lower remote risk since they connect through a local hub rather than directly to the internet. Bluetooth locks have shown real vulnerabilities in independent research. Wi-Fi locks offer remote access convenience at the cost of a larger attack surface if not properly secured.
What should I check before buying a smart lock?
Look for a manufacturer with a real firmware update history, 2FA support in the app, a physical key override, and avoid unbranded low-cost models with no update history.
Should I keep a physical key backup for a smart lock?
Yes — nearly every reputable smart lock includes a mechanical override for dead batteries or app outages. Store that backup key securely off the property, not hidden near the door.
How do I remove old access codes from a smart lock?
Open the companion app's Users, Guests, or Access Codes section and delete entries for anyone who no longer needs access. Review this list every few months — forgotten standing access is one of the most common real-world gaps.
What is a replay attack on a smart lock?
An attacker captures a legitimate Bluetooth unlock signal during close-range presence and retransmits it later to unlock the door without needing your password. Locks with properly randomized session tokens resist this better than ones with static signals.
Do smart locks affect home insurance?
Some insurers offer modest discounts for monitored smart security systems, though this varies by provider — check directly. A lock left on default credentials at the time of an incident could also be a relevant factor in a claim.

Comments (3)
Went through our access codes after reading this and found our old dog-walker from over a year ago still had a working code. Removed it immediately. Good reminder that the boring stuff (forgotten access) matters more day-to-day than exotic hacking scenarios.
Appreciated the honest context about the Bluetooth range requirement for most of these attacks — makes the risk feel proportionate instead of terrifying. Still updated our lock's firmware and turned on 2FA since it took five minutes.
Switched to a Z-Wave lock through our existing hub after reading the comparison table. Already had the hub for other devices so it made sense to keep the lock off direct Wi-Fi/Bluetooth. Clear, practical guide.
Leave a Comment