https://labs.f-secure.com/advisories/keywe-smart-lock-unauthorized-access-traffic-interception
"The KeyWe smart lock suffers from multiple design flaws resulting in an unauthenticated - potentially malicious - actor being able to intercept and decrypt traffic coming from a legitimate user. This traffic - as described below - can then be used to execute actions (such as opening/closing the lock, denial of service, silencing the lock etc.) on behalf of the owner."
An interesting read from a well respected security research site.
Teardown and messy details here: https://labs.f-secure.com/blog/digital-lockpicking-stealing-keys-to-the-kingdom