Biometric Lock Failures: How a 12-Year-Old Opened a Gun Safe

Here's a sentence that should stop you cold: a biometric lock on your front door, or your gun safe, or your phone, reads a fingerprint that a photograph can copy. Not steal. Copy. With acetate paper, a laser printer, some wood glue, and about five dollars in supplies, researchers have built fake fingerprints that unlock consumer devices with a 100% success rate. But that's not even the scariest part of this story. The scariest part is a setting most people never knew existed, one that let a 12-year-old boy in Nevada open a locked gun safe with his own finger, because the safe was never really locked at all.
A biometric lock is supposed to open only for the fingerprint you enroll, but a documented "default to open" flaw in tens of thousands of biometric gun safes let any fingerprint, including a child's, open the safe as if it had never been locked.
What a biometric lock actually promises, and where it quietly breaks
A biometric lock is built on one idea: your body is the key. Instead of a code or a physical key, the lock reads something uniquely yours, a fingerprint, in most consumer products, and compares it to a fingerprint you saved earlier. If they match, it opens. If they don't, it stays shut. That's the whole pitch, and it's a good one. You can't lose your finger the way you lose a key. You can't forget it the way you forget a code. For home use or office use, that convenience is genuinely appealing, which is exactly why biometric locks have shown up on everything from phones to gun safes to front doors. That added convenience is a big part of why a fingerprint lock shows up in so many products today.
Not all biometric locks look the same. Some replace a traditional rim lock, the kind mounted on the surface of a door, with a fingerprint scanner built into the same housing. A fingerprint rim lock combines that old mounting hardware with a modern sensor, but the underlying risk is identical: the scanner has to actually verify every print, every time.
But here's where it gets interesting, and a little unsettling. In October 2023, more than 60,000 biometric gun safes were recalled after a programming flaw let the devices work in a mode nobody asked for. According to the U.S. Consumer Product Safety Commission, the safes could remain in a "default to open" mode, meaning the fingerprint scanner would accept an unpaired print, a print that was never enrolled or authorized, and open anyway. The owner believed the lock worked. The screen on the safe may have even said so. It didn't.
How does a biometric lock fail without anyone noticing?
It fails silently, and that's the part that catches people off guard. The safe's firmware, the built-in software that runs the device, is supposed to check every fingerprint against a stored list of approved prints. When that check is broken, or shipped in a demo mode meant only for stores, the lock still looks and acts like a working lock. It clicks. It shows a light. It just doesn't actually verify anything. The Consumer Product Safety Commission received 39 separate reports of these safes opening for fingerprints that were never paired to the device, and in January 2022, that flaw ended in tragedy when a 12-year-old boy in Nevada gained access to a firearm inside a safe his father had bought less than a year earlier, according to CBS News.
Why a biometric lock is not the same thing as a secure screen
This is the misconception, and honestly, it's an easy one to fall into. Most of us assume biometric means secure, because a fingerprint feels private. It's yours. Nobody else has it. But that logic mixes up two different ideas: uniqueness and secrecy. Your fingerprint is unique. It is absolutely not secret. You leave it on your coffee mug, your phone screen, your car door, and any photo that catches your hand in decent lighting. A password lives in your head. A fingerprint lives on everything you touch. This article is part of a series, start with Facial Recognition Software 14 Wrongful Arrests So Far.
Researchers writing in a peer-reviewed study published by Springer Nature demonstrated mock fingerprints successfully unlocking consumer devices essentially every time they tried. Separate reporting from All About Circuits broke down exactly how cheap this is to pull off: a printed photo of a fingerprint, some acetate sheet, a bit of wood glue to create texture, and a laser printer. Total cost, about five dollars. That is the actual security level of "uses unique biological identifiers" as a locking method. Unique, yes. Locked away from prying eyes, not even close.
Think of it like a bouncer at a club door who's handed a photo lineup of approved guests. If that bouncer is doing the job right, he checks every face against the list before waving anyone through. But imagine the bouncer's instructions got scrambled, and now he waves everyone through while still stamping "verified" on their hand. From the outside, the door looks guarded. The stamp is right there. Nobody checks twice, because the system looks like it's working. That's the "default to open" flaw in one image: the appearance of a check, with no actual check happening.
Biometric metal keyless thumbprint device: what "locked" actually means
A biometric metal keyless thumbprint lock is marketed on the promise that only your thumbprint opens it. In practice, that promise depends entirely on the software behind the scanner correctly comparing a live print to a stored one every single time. When that comparison logic ships broken, as it did in the recalled safes, "locked" becomes a word on a screen, not a fact about the object in front of you.
| What you assume | What actually happens when the flaw hits |
|---|---|
| Only your enrolled fingerprint opens the safe | Any fingerprint, including a child's, opens it in default mode |
| The lock screen confirms it's secure | The screen can display "verified" while performing no real check |
| A biometric lock works like a stronger version of a key lock | The lock mode is a software setting that can silently revert or ship wrong |
| Fingerprints can't be copied like a password | A photo, printer, and wood glue reproduce a workable print for about $5 |
What You Just Learned
- 🧠Fingerprints are unique, not secretthey're left on nearly everything you touch, unlike a password
- 🔬 A "default to open" mode can make a locked safe function as an unlocked one, silently
- 💡 This is not one company's mistakethe CPSC has flagged the same pattern across multiple gun safe brands
- 💡 The screen can liea device can display "locked" or "verified" without performing an actual check
The safes could be operated in a "demonstration mode" that allowed any fingerprint, including that of a child, to open the safe. reporting on CPSC findings, NBC News
Biometric lock apps and gun safe apps: does "fixed" mean it's actually fixed?
A lot of these safes pair with a companion app, the same way a phone's lock screen pairs with a settings app that manages fingerprints. So when a brand says the issue is fixed, what does that actually mean for the safe already sitting in your closet? According to Medical Xpress, which reported on the HealthDay coverage of the recall, the fix required consumers to actually take action, either returning the unit or applying a firmware update, rather than the flaw correcting itself automatically. A recall notice sitting unread in your inbox does not lock your safe. Only the update, applied, does that. Many of these lock apps also log every attempt, successful or not, which is one more way to confirm your safe hasn't quietly reverted to demo mode.
Most of these safes also include a low battery alarm that beeps when a 9 volt battery backup is running low, but that warning has nothing to do with whether the fingerprint check itself is working. A dead battery and a broken verification check are two completely separate problems, and only one of them announces itself with a beep.
This pattern isn't a one-time story either. A separate CPSC stop-use warning in January 2025 flagged the same failure mode, unpaired fingerprints opening a biometric gun safe, on a different brand, according to reporting from Migliaccio & Rathod LLP. And an earlier recall covered by NBC News involved roughly 120,000 units across multiple manufacturers, tied to that same demonstration-mode setting shipping active by mistake. This is an industry pattern in how these locks work, not a single bad batch from one factory.
Does a lock screen setting explain why the safe opened for a child?
Yes. Many of these safes ship with a demo mode meant only for store displays, so shoppers could test the scanner without enrolling a real fingerprint. If that mode never gets switched off during setup at home, the safe keeps behaving like a store demo unit: any finger works, because no fingerprint is actually being checked against a saved one. Previously in this series: Voice Cloning Technology 500 Buys Scammers A Kids Voice.
How CaraComp thinks about biometric lock risk beyond gun safes
This is the same blind spot we study when we look at facial recognition. People assume that because a system checks something unique about your body, it must be secure. But a face can be captured from a photo. A voice can be cloned from a few seconds of audio. A fingerprint can be lifted from a glass. The body part isn't the vulnerability. The software deciding what to do with that body part is. Whether it's a face scan on a phone or a thumbprint on a gun safe, the actual question is never "is this biometric," it's "does the system genuinely verify a match every single time, with no default mode, no demo setting, and no silent fallback."
The same technology shows up far beyond gun safes. Many of the locks smart homes install on doors, and many of the doors smart apartment buildings use for keyless entry, run on this identical fingerprint or code logic, and depend on the same kind of firmware check working correctly every time. A biometric lock can be a suitable choice for low-stakes storage, but a firearm is not low-stakes.
If you own a biometric gun safe, or any biometric metal keyless thumbprint lock, check the manufacturer's website for your model number against active recall notices. Confirm the firmware is current. Then physically test it: have a family member who was never enrolled try their own finger. If the safe opens for them, it is not locked, no matter what the screen says.
A biometric lock is only as secure as it actually is, not as secure as it looks, and a screen that says "locked" is not proof, it's just a claim; test the actual lock with an unenrolled finger before you trust it with a firearm in the house.
So here's the aha moment worth carrying out of this: a biometric lock was never supposed to be beaten by force, the way you'd pry open a padlock or apply a powerful magnet to a cheap mechanical latch. It was supposed to be smarter than that. Instead, the safest looking lock in the house was undone by the simplest possible failure, a setting nobody checked, and a fingerprint that didn't even need to belong to an authorized person. If this were happening in your home tonight, would you know to actually try the wrong finger first, before you ever trusted it with your child's safety?
biometric lock: Frequently Asked Questions
Is a biometric lock suitable for home use with a firearm inside?
It can be, but only if you confirm the demo or default mode is switched off and the firmware is current. Multiple CPSC recalls show biometric gun safes shipped in a mode where any fingerprint opened the lock, which defeats the entire purpose for home use. Test the lock yourself with an unenrolled family member's finger before storing a firearm inside. Up next: Biometric Lock How A 12 Year Olds Finger Opened A Gun Safe.
Are biometric locks good for office use too?
Biometric locks are common for office use on doors, cabinets, and lockers, and the same rule applies: check whether the device has ever had a recall or firmware flaw, and confirm setup fully removed any demo mode. For low stakes storage, a biometric lock for office use is usually fine. For anything dangerous, treat it the way you would a home gun safe and verify it directly.
Can a biometric lock be opened with a powerful magnet?
Some older mechanical safes and low-cost locks have had reported weaknesses to a powerful magnet interfering with internal solenoids, separate from the fingerprint scanner itself. This is a different failure than the "default to open" software flaw described in the CPSC recalls, but it's a reminder that a lock's overall security depends on more than just its biometric scanner, it depends on the whole mechanism.
Why do biometric locks use fingerprints if they can be copied?
Fingerprints are used because they use unique biological identifiers such as ridge patterns that are hard to duplicate by accident, and they're convenient, you can't forget your finger at home. The problem researchers have shown is that fingerprints are not secret, since they're left on surfaces constantly, so a copied print can still trick a scanner if the underlying software doesn't add extra checks.
How do I know if my biometric lock app actually fixed a known flaw?
Check the manufacturer's site or the CPSC recall page for your model number and confirm a firmware update was released and applied, not just announced. An app showing a new version number isn't proof the flaw is patched on your specific unit. The safest confirmation is a physical test: have someone whose print was never enrolled try to open it.
What does "locks" mean when a gun safe says it locks automatically?
It typically means the safe engages its bolts after a set time or when closed, without you pressing a button. But automatic locking only matters if the fingerprint check behind it is actually verifying prints. A safe that locks automatically but accepts any fingerprint provides a false sense of security, the mechanism works, the verification does not.
Ready for forensic-grade facial comparison?
Full forensic reports with detailed similarity scoring. Results in seconds.
Run My First SearchMore Education
Deepfake AI: One Public Photo Is All Blackmailers Need
A deepfake sextortion scam killed a 16-year-old over a fake photo. Here's how the AI technology behind it works, how detection catches what your eyes can't, and where to look first if it happens to your family.
facial-recognitionHow Does Facial Recognition Work: 512 Numbers, Wrong Arrests
Your face gets turned into a string of 512 numbers the moment a camera catches it. Here's what those numbers actually do, why they can vary from one image to another, and how a stranger's numbers can end up matching yours.
facial-recognitionFacial Recognition Glasses: 1 Glance Pulls a Home Address
Two Harvard students turned ordinary-looking smart glasses into a stranger-identifying machine. Here's exactly how the tech chains together, why the "recording light" won't save you, and what to actually check tonight.
