Skip to main content
Factlen ExplainerSmart Lock SecurityTrade-Off AnalysisAug 14, 2026, 8:53 AM· 5 min read· in shopping

The Security Redesign: Bluetooth vs. Matter Smart Locks After the WiseConnect Flaw

The discovery of a critical vulnerability in widely used Bluetooth chips has exposed the risks of legacy pairing, forcing a reevaluation of how smart locks secure our homes. Here is how Bluetooth LE compares to newer Matter-over-Thread alternatives.

By Paige Carter

Vulnerability Researchers 50%Smart Home Architects 50%
Vulnerability Researchers
Focus on identifying and mitigating cryptographic flaws in legacy wireless protocols to prevent unauthorized access.
Smart Home Architects
Advocate for transitioning physical security devices to robust, certificate-based mesh networks like Matter-over-Thread.
7.6 / 10
CVSS severity score for CVE-2026-65935
2.0.0 to 4.x.x
Affected WiseConnect firmware versions
12–18 months
Typical battery life of BLE smart locks

If you are buying a smart lock today, the connectivity protocol you choose determines whether your front door has a digital backdoor. On August 13, 2026, the cybersecurity community and hardware manufacturer Silicon Labs disclosed a critical vulnerability affecting millions of connected devices. Tracked as CVE-2026-65935, the flaw resides in the Bluetooth Low Energy implementation of the RS9116W and SiWx917 wireless chips—components heavily utilized in smart locks and IoT sensors. The vulnerability exposes a severe weakness in the passkey entry mechanism of legacy Bluetooth pairing. By manipulating the temporary key value during the initial handshake, an attacker within radio range can bypass the intended authentication process entirely, pairing their own smartphone to the lock without knowing the correct PIN.[1][2][3]

The technical root of the WiseConnect flaw lies in insufficient cryptographic validation during the device handshake. When two devices attempt to establish a trusted connection using legacy Bluetooth Low Energy pairing, they exchange temporary keys to verify each other's identity. Because the vulnerable Silicon Labs chips fail to properly check these parameters for consistency, an attacker can inject modified keys that trick the system into accepting invalid credentials. This man-in-the-middle attack exploits the predictable nature of legacy key generation. The resulting CVSS severity score of 7.6 reflects the high impact of the vulnerability: once paired, the attacker gains persistent, unauthorized access to the device, effectively compromising the hardware without triggering any tamper alarms.[1][3]

For a smart lock securing a residential front door, this vulnerability translates to a silent, digital lockpick that leaves no physical trace of forced entry. The operational impact extends beyond a single compromised door; attackers can leverage this weakness to gain a foothold into broader IoT ecosystems where these specific chips are deployed. Because the RS9116W and SiWx917 modules are designed to provide comprehensive multi-protocol wireless connectivity, they are frequently embedded in high-end consumer electronics that require both Wi-Fi and Bluetooth capabilities. The revelation that their legacy Bluetooth pairing can be so easily bypassed has forced manufacturers to scramble for firmware patches and prompted security experts to advise consumers to disable legacy pairing modes wherever possible.[2][3]

The WiseConnect vulnerability exposes the severity of legacy Bluetooth pairing bypass attacks.

This disclosure serves as a stark reminder of the structural vulnerabilities inherent in older, proximity-based wireless protocols. For years, the consumer electronics industry favored Bluetooth Low Energy for smart locks because it offered an unbeatable combination of low component cost and extreme battery efficiency. A standard motorized deadbolt could operate for twelve to eighteen months on four standard AA batteries while communicating directly with a user's smartphone. This direct-to-phone architecture eliminated the need for complex networking hardware, making Bluetooth locks highly appealing to renters and homeowners looking for a simple, plug-and-play security upgrade.[4]

This disclosure serves as a stark reminder of the structural vulnerabilities inherent in older, proximity-based wireless protocols.

However, the reliance on legacy pairing methods has transformed that convenience into a liability. While the Bluetooth Special Interest Group introduced "Secure Connections" (LESC) in later iterations of the protocol to utilize stronger Elliptic Curve Diffie-Hellman cryptography, many manufacturers continued to support legacy pairing to ensure backward compatibility with older smartphones. The WiseConnect flaw specifically targets this legacy fallback. As security researchers continue to uncover bypass techniques that exploit these older standards, the smart home market is being forced into a rapid architectural redesign, pushing consumers to reevaluate how their physical security devices communicate.[1][4]

In response to the escalating frequency of Bluetooth vulnerabilities, the industry has begun a massive shift toward mesh networking and hub-based architectures, championed by the Thread protocol. Unlike Bluetooth, which relies on a direct, point-to-point connection between the lock and a phone, Thread is an IPv6-based mesh network designed specifically for the smart home. Devices on a Thread network communicate with each other and route traffic through a "Border Router"—such as an Apple TV, Google Nest Hub, or Amazon Echo—which securely bridges the local mesh to the broader internet. This architecture not only improves range and reliability but fundamentally changes how devices authenticate.[4]

Newer Matter-over-Thread architectures rely on dedicated home hubs to provide certificate-based authentication, bypassing Bluetooth's vulnerabilities.

The security advantages of this new architecture are heavily amplified by the Matter smart home standard, which operates seamlessly over Thread. Matter mandates strict, enterprise-grade cryptographic security for every device joining the network. Instead of relying on easily manipulated temporary passkeys or proximity-based handshakes, Matter requires devices to authenticate using distributed digital certificates. When a Matter-over-Thread smart lock is installed, it undergoes a rigorous cryptographic verification process before it is allowed to communicate with the home hub. This certificate-based approach effectively neutralizes the type of man-in-the-middle attacks that plague legacy Bluetooth pairing.[4]

For consumers currently shopping for a smart lock, the landscape has shifted from a simple aesthetic choice to a strict cryptographic decision. The market is now cleanly divided into two distinct connectivity paradigms: traditional Bluetooth Low Energy models and the newer generation of Matter-over-Thread devices. While Bluetooth locks remain ubiquitous on hardware store shelves and offer undeniable setup simplicity, the introduction of the Matter standard provides a level of cryptographic resilience previously reserved for commercial security systems. Understanding the specific trade-offs between these two approaches—detailed in the comparison below—is essential for securing your home without inadvertently installing a vulnerable digital backdoor.[4]

Viewpoints in depth

Option 1: Bluetooth LE Smart Locks

The traditional, low-power choice that connects directly to a smartphone without external networking hardware.

For: Bluetooth locks are highly energy-efficient and cost-effective. They operate for 12 to 18 months on standard AA batteries and do not require a separate smart home hub, making them ideal for single-device setups. Because they communicate directly with the user's phone, they remain fully operational during internet or Wi-Fi outages. Against: As demonstrated by the 7.6 CVSS score of CVE-2026-65935, legacy Bluetooth pairing is highly susceptible to proximity-based bypass attacks. If a manufacturer prioritizes backward compatibility over enforcing Bluetooth LE Secure Connections (LESC), the lock's authentication can be manipulated via temporary key injection. Evidence: The Silicon Labs WiseConnect vulnerability confirms that legacy passkey entry can be bypassed at the protocol level, granting attackers persistent access without physical tampering. Fits well when: You need a standalone lock for an interior door or a temporary rental property, and you can verify that the manufacturer strictly enforces LESC protocols. Does not fit when: You are securing a primary exterior door against sophisticated threats or want remote access without purchasing a proprietary Wi-Fi bridge.

Option 2: Matter-over-Thread Smart Locks

The modern, mesh-networked standard requiring a dedicated home hub for certificate-based authentication.

For: Matter mandates strict cryptographic security, requiring devices to authenticate via distributed digital certificates rather than easily manipulated temporary passkeys. Thread provides a self-healing IPv6 mesh network that extends range and reliability. This architecture neutralizes local man-in-the-middle attacks and ensures that the lock cannot be bypassed by simple radio spoofing. Against: These locks require a compatible Thread Border Router (such as an Apple TV 4K or Google Nest Hub) to function, which increases the initial setup cost and complexity. They also tie the physical security of the home to the operational status of the broader smart home ecosystem, and active routing can reduce battery life to 6-8 months. Evidence: The Matter 1.2 specification requires all joining devices to pass a rigorous cryptographic Device Attestation Certificate (DAC) check, structurally preventing the legacy pairing bypasses seen in Bluetooth. Fits well when: You are building a comprehensive, future-proof smart home and demand enterprise-grade encryption on your exterior doors. It is the optimal choice for users who already own a compatible smart display or speaker. Does not fit when: You want a simple, plug-and-play lock without investing in a broader smart home ecosystem, or if you strictly avoid keeping internet-connected hubs in your home.

Sources

Source coverage

4 outlets

2 viewpoints surfaced

Vulnerability Researchers 50%Smart Home Architects 50%
  1. [1]CVE ProgramVulnerability Researchers

    CVE-2026-65935: Bypassing passkey entry in legacy pairing

    Read on CVE Program
  2. [2]Silicon Labs CommunityVulnerability Researchers

    Security Advisory: Bluetooth LE Legacy Pairing Bypass

    Read on Silicon Labs Community
  3. [3]arXivVulnerability Researchers

    Bluetooth LE Vulnerabilities: B-E3 Passkey Bypass

    Read on arXiv
  4. [4]Factlen Editorial TeamSmart Home Architects

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team

Comments

Stay informed

Every angle. Every day.

Get shopping stories with full source coverage and perspective breakdowns delivered to your inbox.