Speaker Details

Kolja Grassmann

Kolja Grassmann

Security Researcher @ Neodyme

Kolja is a Security Researcher and Trainer at Neodyme with years of exploit development, red teaming, and pentesting experience. He focuses on white-box pentests as well as Windows and Active Directory security. He has reported vulnerabilities in security products from multiple well-known vendors, in other widely used software, and in IoT devices.

Keyless Entry: Hacking SwitchBot Smartlocks

Friday, 13 November 2026, 14:00 - 14:30

Smart locks are rapidly replacing physical keys, but trusting your front door to an IoT device still comes with significant risks. In this talk, we will dissect the highly rated SwitchBot Lock Pro and demonstrate how a classic cryptographic implementation flaw allowed anyone to silently unlock the door without any physical tampering.

By reverse-engineering the firmware and analyzing the custom Bluetooth Low Energy (BLE) protocol between the outdoor keypad and the indoor actuator, we discovered the system relies on AES in Counter (CTR) mode with zero integrity checks. We will demonstrate how we exploited this to create a universal, software-only UNLOCK payload. Join us as we showcase the live exploit, break down the vendor’s flawed patch, explain how backward compatibility significantly delayed the patch, and celebrate our massive 100€ bug bounty.