Kryptonite Evolution 2000 U- Lock hacked by a Bic pen
Much to our surprise, we were able to hack our
Kryptonite Evolution 2000 U- Lock with a ballpoint pen. This $50 lock is supposed to be one of the best for
"toughest bicycle security in moderate to high crime areas"—unless the thief happens to have a Bic pen. We
used to use these to lock up our bicycles, but we're switching to something else ASAP. (Oh, and just to be
trite, the pen is mightier than the lock.)
Click here to watch the video (WindowsMedia)
[Via Metafilter]















Some combinations may pick easily like this. It makes interesting video. The pen may have been run through a duplicator.
I heard about this and thought it was a joke, but I tried it out on my Kryptolock (U-Lock) and it worked! And now my lock is screwed up. This worries me, because I have been locking my laptop up with a Kryptonite cable lock with the same type of lock. Trust me, the pen thing works. Scary.
As posted, the "tube" locks are used in many other things. Example, many of those "el cheapo" gun safe use this type of lock. I'm more worried of a thief breaking in to a home and getting something out of a gun safe then a bike....
Before this story, maybe a limited few people knew of this "trick". Now, everyone knows. And people posting quick tricks to make the pen fit doesn't help.
Are you better off knowing that this type of lock can be defeated that easily? This information is a double edged it can help you, but also put to at risk..... Oh well, the damage is done.
WELL AT LEAST KRIPTONITE'S STOCK PRICES WILL BE COMING DOWN
now I know how my bike vanished. I had a "cheap" beach cruiser w/surf racks locked in the alley with a Kryptonite U-bolt and a cable Key lock. I decided to lock it with only the U-bolt one holiday weekend because i would be using it often.
well guess what, it got ripped off!
Ok, earlier in the comments, someone mentioned that Google's Ad on this page was advertising Kryptonite locks... This time, it's advertising Bic Pens... I love AdSense.
I live in the backwoods about 50 miles north of Redding, CA. We don't use bike locks of any kind around here. We have something that works much better against thieves: guns.
Does this trick work on a rusted-shut U-Lock? Mine won't open with the key.
There are now reports on gun web sites that
the same type locks that are used on low priced gun safes can also be opened the same way.
I'm a student at Syracuse University and I am writing an article about this topic. Is there anyone who has had their bike stolen when it had a kryptonite bike lock on it? Or is there anyone who has followed through with Kryptonite's exchange policy? If so, can you e-mail me at airyelly1@aol.com? It would really help me out.
I'm cracked up by some of this information regarding how easily these locks are compromised. its pretty awesome how something as common as a bic pen can mess up someones life. Like a professional biker, but u get the picture.
yehhh adsense is pretty awesome!!
one more thing "UNIVERSAL BITTORRENT SOURCE"
wow.. my bike was stolen recently so now i am doing research and this was a great find. I'll make sure to check out every lock more closely for this flaw.
29 septembre 2004
Une requ? qui pourrait atteindre 56 M$
Un Qu?cois d?se une demande de
recours collectif contre les cadenas Kryptonite
Un cycliste qu?cois a d?s?ne demande de recours collectif pouvant atteindre 56 M$ contre le fabricant de cadenas am?cain Kryptonite, dont certains produits se d?rrouilleraient avec un simple stylo ?ille.
Alain Bisson
Christophe Courtoy a pr?nt?a requ? par l'entremise du cabinet d'avocats B?rd & Pollanen lundi, au palais de justice de Montr?. La demande vise ?lement le distributeur Accessoires pour v?s O.G.D., de l'arrondissement Saint-Laurent.
Au cours d'un entretien avec le Journal, Me Michel B?rd a dit ?luer qu'au moins 100 000 et jusqu'?00 000 Qu?cois ont achet?es cadenas Kryptonite ?l?ylindrique au fil des ann?.
Il a expliqu?ue le recours, s'il est autoris?ar la Cour sup?eure, r?amera pour tous le remboursement des cadenas - environ 40 $ - et des dommages de 100$.
Selon Me B?rd, le programme de remplacement gratuit r?mment lanc?ar Kryptonite ne limite en rien la validit?u recours.
« L'entreprise essaie de s'en tirer ?on compte », a-t-il dit.
« Ce programme s'adresse ?n nombre limit?'acheteurs et seulement ?eux qui feront les d?rches. Le d?t d'un recours collectif est la seule fa? de s'assurer que toutes les personnes l?es seront indemnis?. »
Deux autres recours
Des cyclistes canadiens et am?cains ont d?s?es demandes semblables en Ontario et en Californie, au cours des derni?s semaines. La requ? ontarienne cible d'autres fabricants, dont Norco et Bike Guard.
Les d?acteurs des cadenas ?l?ylindrique all?ent que les fabricants savent depuis au moins 12 ans que leurs produits peuvent ?e ouverts avec le corps des stylos de style Bic. Une revue de v? britannique a fait un reportage ?e sujet en 1992, tout comme la BBC.
« Kryptonite savait ou aurait d?voir, mais a continu?e vendre ses cadenas. C'est au mieux un cas de n?igence ?dente », a d?ar?e B?rd.
Donna Tocci, porte-parole de Kryptonite, a d?ar?u cours d'un entretien avec le Journal que la soci? du Massachusetts ignorait tout et qu'elle n'admet rien.
L'affaire a repris l'avant-sc? il y a une dizaine de jours avec la diffusion dans Internet d'extraits vid?montrant comment d?rrouiller un Kryptonite Evolution avec un stylo Bic.
I watched the video with intrest, as I have an old Kryptonite lock on my bike -the model says Kryptolok by Kryptonite. I found an actual BIC pen, not a cheap substitute, and tried several times. I could not get it to work. I admit that it may be just me, but it really ain't that complex, so I'm thinking that as the newer lock models come out, Kryptonite, like other manufacturers has resorted to a smaller/cheaper lock mechanism for their product.
Four weeks ago I bought a new bike, and a Krypto lock. Yesterday my bike was stolen from outside the shop where I work in Central London.
The lock was on the ground, open but intact. I just couldn't figure out how the lock had been opened.
I just saw this on the internet tonight, and now I know. It must be more than coincidence that this story broke about a week ago.
I would warn any bike owners in Central London NOT to lock their bikes with Krypto locks, 'cos once this gets round all the London crack head gangs nothing with a Krypto lock will be safe.
I have now bought a new bike with a padlock and chain and a long barrelled lock.
I did notice that all the Krypto locks had been taken off sale in the store and were stacked up behind the counter. The store staff didn't say anything to me about it though, probably 'cos it was them who sold me the Krypto lock Four weeks ago.
What a load of rubish he has shaped the end of the pen so it is the same as using a key, he does not even realy show that the lock is locked to start with I will not belive it until I see it I have traed mine and it will not open, its brand new, bye the way what does this person do for a living, I would be asking this question first.
What a load of rubish he has shaped the end of the pen so it is the same as using a key, he does not even realy show that the lock is locked to start with I will not belive it until I see it I have traed mine and it will not open, its brand new, bye the way what does this person do for a living, I would be asking this question first.
After seeing this story with the Kryptonite locks and the bic pen, I tried it with a Master Lock steering wheel lock I had to protect my car. It works on these too! I unlocked the steering wheel lock in about 9 seconds.
As a lock person, here's my view on this issue. Hope it clears things up a bit.
We have received many emails regarding Kryptonite's recent vulnerability to be opened with a simple Bic pen
It is 'not possible' to open a well pinned tubular cylinder. . . . .http://www.lockitt.com/Notice_tub_lock.htm
If you would like to exchange your Kryptonite tubular cylinder lock for a comparable lock, please fill out the information below. Once you submit your information, you will be added to our database. You will then be contacted by us with a UPS Call tag that we will send out to you. Due to the volume of e-mails it may take several days for us to contact you. The locks will be available beginning mid October.
Please complete all the required fields marked with a *.
https://www.kryptonitelock.com/inetisscripts/abtinetis.exe/templateform@public?tn=product_exchange.tem
etc. etc.
I wonder if my quick-swap hard drive bay's key will work. It has a slightly smaller diameter than the Bic pen, and it's metal. For that matter, I wonder if that hack will work on my drive bay! I know the locking mechanism is not meant for security so much as data integrity. You can't boot off of the drive unless the "lock" is engaged, which turns on the logic board and allows power and data communication. It also physically secures the drive so you can't remove it while it's running. For those poor souls who use the drive bay as a "security" device...well I hope their potential data thieves don't read engadget.
I think that this post is starting to get to much comment and that nothing more can be said so I'll just agree with everything here that make sence and tell you : "This is some pretty clean work you did there !" ;-)
Due to the "Bic Pen" incident, Kryptonite has now manufactured a NEW Cylindrical Lock that can not be picked using a Bic Pen. We actually thank the person/persons that shared this information because this has enabled us to have a much more improved product. The new products should be in stores by the middle of November.
A guy at work tells me about this, so I go Googling and comeup with this site.
After reading, I'm thinking I'll give it a shot. I have two older locks gathering dust (don't lock up the bikes anymore...they go where I go).
The trick did work on the Krypto-Lok, but not on the older generic one. I'm guessing the Krypto-Lok is at least 4 years old and the "older" krypto is probably about '91.
I did have to stretch the pen barrel with a scissors, and kinda hammer the pen in with the other lock.
If anyone thinks this is BS, I will gladly post pics of the two vertical "notches" not lined up....try taking your key out of the lock "mid-turn"
maybe you can find better here :http://www.cnmoto.com
Very cool hack!
cool
so does anyone know of a lock system that is worth the money?
Hey, this works for EV Disc Locks too, I just did it to mine, but it's actually harder to get the lock to go back to the normal position, but not impossible.
You are teaching people how to break into locks. This is a shame. People cherish their bicycles and you are putting them in danger of getting them stolen. I am sure Kryptonite is doing every thing possible to rectify this situation.
Please remove the video from your website.
Please!
im a bike rider, a matter of fact i dont drive
at all , so that being so, i take it upon my self to have expensive bicycles , i would
to know all the possible ways to pick, break, smash , drill, etc a bicycle , so that i can be prepared , evan if i live in fresno ca. where the thieves are to stupid and drug ridden to know how to steal a bicycle .
is there any one can tell me or email me a list of all or some ways to comprimise a bike lock, example i have a master lock with anti drill shackle with a small elbow that prevents a good hold for bolt cuters , is there any way to pick it or break it ?
Check this out Kryptonite will replace your lock! here's the link
http://www.kryptonitelock.com/inetisscripts/abtinetis.exe/templateform@public?tn=urgent_update
Man, Someone stole my Holiday inn bic pen..Hotel pens are the best...I guess I will just go to my bike shop and ask if my lock needs to be replaced...I guess I will be going to Velo in Seattle..
OK so I went to their site to check if the krypto lock I bought today needs to be replaced. But there they ask for the lock's key number in order to put me on their list but I can't locate that number anywhere on the pen! :)
Wow! what is this? A school for thief? :)
Thief is usually smarter than the police!
THEY SAY THEY WILL START SHIPPING IN....OCTOBER 2005!!! so what ever happens in bewtween is your responsibility. What a shame! Shameless people, poor products, shameless company!
Great, thanks for the tip, I will never use this lock.
http://www.bikeguardlocks.com/ulocks/magnum_2000hd.php
I just purchased this U-Lock which was recommended as one of the best anti-theft deterrants.
- 12 Tonne Pull Strength
- Case hardened anti-pick mechanism
- 20mm Square Shackle
- Includes 5 FLAT keys
- $2000 Anti-Theft Protection
Very intersting; I'll have to try this...
Well,that is very easy,but still.. Remember this saying-- It applies in many parts of the life:
"You make it foolproof,we'll make better fools!"
Cheers!
Anyone read the latest issue of Wired? It has an interesting article on a lock-picking contest in Europe (amsterdam, I think it was). My guess is they don't use a Kryptonite in the contest!
Anyone else see the new info on Kryptonite's website about the class action suit?
They're replacing any locks affected or bikes stolen using the bic trick!
www.kryptonitesettlement.com
For those interested in the best security, testing and certification by Sold Secure (a UK testing lab) appears to be the world gold standard. From its website "Sold Secure is an independent test laboratory, we test using methods used by thieves with the added advantage that all our testers are also skilled locksmiths."
For Sold Secure approved bicycle locks, see http://www.soldsecure.com/Leisure.htm
what the heck I thought my bike was safe
Well, I am not surprised. After wathing the movie I checked the security of the looks on my bike. The main look is certified by the Swedish Safety Organisation (SSF) is told to stand hackning attempt for at least three minutes. I opened the lock within ten seconds using a papper clip. All three locks was opened in 45 seconds without a trace of any mark of hacking. You invest about 140 USD for bike locks in your belief to stop a thief for five minutes or make your bike less attractive. Well, there your bike disappears.
The certiefied lock I tested is Basta Click3 no 5360-08-43/B frame lock.
By a local lock smith I was told to use a certiefied chain with padlock for motor bikes with a shacle thickness of at least 12 mm. This look system costs between 240 and 450 USD. It weighs about 20 kgs. Se an example at http://www.abus.de/us/main.asp?ScreenLang=us&sid=81589907409360009062005213113243118&select=0105b02&artikel=4003318201820m
Better bike locks, thank you
Thorwald Persson, Malmo Sweden
I wonder if this works with those pesky hhd bay drawers?They have the round type keyhole
Has anyone posted a page or explanation on why some circular locks have this vulnerability? Obviously the pins in the circular lock are designed to prevent attacks like this, so why aren't they effective? Is it just loose tolerances?
DUDE WTF something is wrong with the fuckin vid I can't play it!
FYI the video is borked....
so what IS a good lock then? any recommendations?
i used to just laugh and say " its a huffy and no one is going to steal a huffy!"
well the huffy has now been retired after i put it thru the hell of me riding it EVERYWHERE and isnt worth the money it would cost to fix it, so i went and bought a nice mtn bike. i was going to get a kryptonite lock, but i had heard about the pen thing and after reading all of this im concerned. my cable and lock and key is too easy to chop with boltcutters....so im stumped.
The video is not clear. I know how to hack. But I don't see the key-hole. Is it really for circular key? Well... stupid me... No other types of exposed keyholes exist.
Back in 2001 I have predicted the risk of the circular keyhole being hacked too easily. This is a flaw by design. Because all security pins are exposed simultaneously for arbitrary manipulation. Any random motion on them can open the lock. That's why I didn't buy these locks, and didn't recommend anyone else. Now my theory is proven by experiment. Not exactly "now"... I am sure thieves have done this long before this one experiment.
Anyway, I am proud of my prediction.
The answer to the question what lock is good is simple: any key of a crown type is far better than a circular key.
However wise I was, the knowledge of the risk of the circular key didn't prevent the loss of my bicycle back in 2002. And perhaps it even facilitated the loss. There were no U-locks in Lithuania with crown keys at that time. So I was stuck with a cable lock. Having a U-lock even with a circular key might save my bike from a stupid thief. Just might.
The "Bic-Pen" method works allright on u-locks, but an even easier way to bust almost any normal sized or long sized u-lock is to use a Volvo Car Jack for flats. You place the car jack in the on the middle of the lock where the staight U bar is and wind the volvo jack so it presses and bends the u lock and it falls right out of the holster. Tried and true, seen it done many times. Enjoy!
While it might appear that explaining how to pick this lock is education for thieves, I prefer to think that it is education for consumers about something that many thieves already know. Now that I know this I am equal to the thieves, whereas I was previously at a disadvantage.
well i lost my one and only krypto lock key over thanksgiving. I've had it over 10 years and sort of knew this day would come. so I tried the bic pen-- it didn't fit my old model lock, though let's face it: there are plenty of various size pens out there! Anyway, last night I readied my volvo car jack for the purpose of busting my lock, and the last entry by wouldie has sealed it. I just hope no one questions me for 'stealing' my unregistered bike from my sweetheart's back stoop since she's gone for the day. I can't wait to bust this lock.
What about the combination U style lock?
Are they secure?
Welcome comments
I guess they run out of pens at there design meeting then :)
... !
Now that's a neat little trick! Does anyone know if it only works on this model or if the Bic Hack actually works on all models? I always knew there was something fishy about the Key Hole.
Now that's a neat little trick! Does anyone know if it only works on this model or if the Bic Hack actually works on all models? I always knew there was something fishy about the Key Hole.
With their Anti-Theft Protection program, I can get me a new bike with that. Isn't it great?
The lock did not fail, or was not broken so it is not covered by the Protection Program. There is no evidence that the lock was broken into. You are screwed if it happens.
What's that foul brew those plants rest in the background of the video?
Now where did I put that pen....
ha now does this mean you are going to get sued for the dmca for breaking protections?
hahahahahahahahahaahahahaha
ha now does this mean you are going to get sued for the dmca for breaking protections?
hahahahahahahahahaahahahaha
Now that's an eye-opener. I might have to get a new lock!
Please change the water for those poor flowers.
I tried it with a BIC pen on my regular Kryptonite Krpyto-Lok model. First, the barrel of the pen doesn't fit into the keyhole unless you really push hard and stretch it out. Second, no matter how I twisted, I couldn't get the lock open. I hope this is an issue exclusive to the Evolution 2000 series.
I did it on my evolution 2000. It swear it worked in 10 seconds at most. it took me longer to get the black plastic piece out of the end of the pen.
The only prob is how do I get the lock back into the ready to lock position?, so that I can try it again.
i've got one of the first evolution 2000 locks (circa 1992-93); i'm sitting right here with a bic pen and the lock in hand, and there is NO WAY the pen barrel will go in the lock. the barrel of the pen is just too narrow/wall of the barrel is just too thick.
maybe they've changed the lock barrel in later models, but those of us with old skool evolution 2000's can rest assured that bic pen-packing thieves won't get our bikes.
mine is circa 1996, it worked
does it have to be a marriott hotel pen? hahhah, jk. really cool, that company is going to have problems now.
*lol* The google ad for this page is a link for Kryptonite locks. How ironic is that?! :)
What really needs to be answered here is whether or not this works for other Kryptonite locks, and if so, which ones? Those of us with or about to buy them would really like to know.
I just came home with a spanking new Evo2000 Mini today and saw this story on 3 sites. Dang.
If you read the bikeforums.net thread, there are folks claiming success with various models. I think that includes the KryptoLok (less pricey than Evolution 2000)
The bike forum mentioned that you can just twist the Bic pen the opposite way to relock the lock. This may explain how some bikes just "disappear", with the lock still locked to the rack.
One guy said it was about as easy as using his keys to lock/unlock...
Another way is to file the nub on one of your keys down enough so you can insert it into the lock and return the tumblers back to their original, locked position.
Is that beer in your flower vase? Seattle is taking this brewpub thing a little too seriously I guess.
http://www.bikeforums.net/showthread.php?t=66128
Hell, there's more than one way to skin a cat. Those long-shackle U-locks are easy to break if there's enough open shackle -- put a car jack into the space of the U so that the plates of the jack are touching the flat parts of it. Then crank the jack open, and eventually the shackle will break loose.
wow, thats pretty funny. I wonder if that works with other U locks?
This technique has apparently been around for a decade or so (see Google groups), but now the cat's definitely out of the bag. If not with a Bic, then someone can make cheap skeleton key with a custom plastic cyllinder, effectively making circular keyed locks obsolete.
That said, it's now a race between the newly-tooled thieves and bike owners. I'm of the mind that as many people should know about this as possible, since the pool of thieves is smaller than the pool of owners. If it just remains in the blogosphere, then the thieves have a great window of opportunity.
On the way to work today, I saw a few dozen bikes locked up with compromized equipment. How long until they're penjacked?
To pick a master lock (maybe not all) with an aluminum can. You need a knife or sissors to cut the can. Make a "key" similar to an E but without the top and bottom bar. "|-" is kind of what it would look like. Then you hug the metal loop and sneak the "-" part into the body, turn around and if you are lucky you can pull the "U" portion of the lock and open it up. Without gloves you might cut your fingers on the thin metal.
Thank You Kryptonite Locks and Small Little Hick Towns, With all Types of People Without Internet Obsession... hahahah ---omg when I see a Police I have to Hide My Bic-Pen Now........
I just popped my kryptonite evolution 2000 *AND* the kryptonite ev disc lock that came with the nyc lock/chain. There goes $150 down the drain.
Tried this on my old Schwinn U lock. Worked like a charm. This is really bad. Guess its back to the Padlock and Cable for me!!
Tried this on my old Schwinn U lock. Worked like a charm. This is really bad. Guess its back to the Padlock and Cable for me!!
I've heard of the cardboard tube from toilet paper rolls used to do the same thing as the bic pen for any diameter lock...