Tapplock is rolling out much-needed updates after it was learned that the padlock that uses fingerprint authentication can be hacked.
Security researchers at Pen Test Partners revealed on Wednesday that the Tapplock software can be hacked, thus allowing unauthorized people to open it to steal whatever valuable things it is supposed to be keeping safe.
Andrew Tierney of Pen Test Partners said in a blog post that the accompanying Tapplock app transmits data through an HTTP server, which simply means no encryption is applied. During the researchers’ test, they observed that each time the lock establishes a connection to the app through Bluetooth Low Energy (BLE), it sends “a string of ‘random’-looking data” necessary for the lock to respond to the app’s commands.
However, the researchers found that these strings of data do not change even at different times that the lock is accessed through the app. “A couple of lines of commands in gatttool and it was apparent that the lock was vulnerable to trivial replay attacks,” the researcher said.
It was also found that the lock and its app do not use factory reset options, meaning all data used can be recovered even when a user unlinks the lock from the app. Additionally, Pen Test Partners revealed that app lets the lock be used by someone else.
“I shared the lock with another user, and sniffed the BLE data. It was identical to the normal unlocking data. Even if you revoke permissions, you have already given the other user all the information they need to authenticate with the lock, in perpetuity,” Tierney wrote.
Shortly after Pen Test Partners’ discovery, Tapplock said it will be rolling out the necessary firmware update to address the serious flaw, according to CNET. The said patch will be automatically installed on the padlock once it is available.
The digital security issue was found just weeks after the widely followed YouTube channel JerryRigEverything demonstrated how easy it was to physically open a Tapplock by only using a suction cup and a GoPro mount. Tapplock responded to this by saying the YouTuber’s Tapplock units were just defective.


Instagram Outage Disrupts Thousands of U.S. Users
Anthropic Eyes $350 Billion Valuation as AI Funding and Share Sale Accelerate
SoftBank Shares Slide After Arm Earnings Miss Fuels Tech Stock Sell-Off
Elon Musk’s SpaceX Acquires xAI in Historic Deal Uniting Space and Artificial Intelligence
Nvidia Nears $20 Billion OpenAI Investment as AI Funding Race Intensifies
Amazon Stock Rebounds After Earnings as $200B Capex Plan Sparks AI Spending Debate
SpaceX Updates Starlink Privacy Policy to Allow AI Training as xAI Merger Talks and IPO Loom
Jensen Huang Urges Taiwan Suppliers to Boost AI Chip Production Amid Surging Demand
AMD Shares Slide Despite Earnings Beat as Cautious Revenue Outlook Weighs on Stock
OpenAI Expands Enterprise AI Strategy With Major Hiring Push Ahead of New Business Offering
Nintendo Shares Slide After Earnings Miss Raises Switch 2 Margin Concerns
Elon Musk’s Empire: SpaceX, Tesla, and xAI Merger Talks Spark Investor Debate
SoftBank and Intel Partner to Develop Next-Generation Memory Chips for AI Data Centers
Global PC Makers Eye Chinese Memory Chip Suppliers Amid Ongoing Supply Crunch
Nvidia CEO Jensen Huang Says AI Investment Boom Is Just Beginning as NVDA Shares Surge
Baidu Approves $5 Billion Share Buyback and Plans First-Ever Dividend in 2026
Palantir Stock Jumps After Strong Q4 Earnings Beat and Upbeat 2026 Revenue Forecast 



