r/safecracking

Image 1 — Very old yale safe with what i assume is the code on the furnace
Image 2 — Very old yale safe with what i assume is the code on the furnace

Very old yale safe with what i assume is the code on the furnace

Very very old safe, here's what's written in the furnace. i transcribed it to the best of my ability.

right 2 stop

left and stop 3

right 1 stop 62

75

u/LazerBrainzz — 1 day ago

Any clues about the specific model for this safe?

Hey folks, the one person at work who knew the combination died. High probability there is money in here. Visible info on the nameplate is not returning any results. Sargent and Greenleaf, but the serial number doesn’t seem to be for the safe itself, rather a specific part.

u/Fuzzybaseball58 — 3 days ago

$50 Auction

Hey guys first time poster long time lurker.

We got this safe for $50 at an estate sale with no combination. Any tips on where to start for cracking it? There’s no model number on the back or sides but there is a small metal plate on the back that says 3153.

Any other information about the safe (good or bad) I’d appreciate as I plan on using it after.

u/PresentRing00 — 3 days ago
▲ 38 r/safecracking+8 crossposts

The 2003 Antwerp diamond vault heist is the cleanest case study in how defense-in-depth fails. Ten independent layers, each beaten by something trivial — hairspray on the IR sensor, aluminum tape on the magnetic contact — because the attacker had 2.5 years of legitimate tenant access to study them.

The vault two floors under the Antwerp Diamond Center was the diamond trade's gold standard, in a city that handles roughly 80 percent of the world's rough diamonds. The control stack:

  • Combination lock, 100M+ possible sequences
  • Separate keyed lock
  • Multi-tonne steel door
  • Magnetic field sensor on the door
  • Seismic sensor for drilling or force
  • Light detector
  • Infrared heat-and-motion sensor
  • Doppler radar sweeping the chamber
  • Camera coverage on the approaches
  • Private guard force monitoring the whole apparatus

Ten controls, each independently credible, and the industry's assessment was that the stack was effectively absolute. Dealers stored inventory there specifically because nobody believed it could be opened.

Over the weekend of 15-16 February 2003 a crew opened it without tripping anything, forced roughly 100 of about 160 safe deposit boxes, and left with north of $100 million. No weapons, no violence, no forced entry into the building. It wasn't discovered until staff came in Monday morning and found emptied boxes and missing tapes.

What each control actually fell to

The IR heat-and-motion sensor — the layer specifically designed to catch a warm body moving in a dark room — was temporarily blinded with a film of ordinary hairspray, long enough for someone to reach it and physically disable it.

The magnetic contact on the door, which should have fired the instant the door broke its field, was defeated by holding the two halves together with aluminum and tape so the field never opened.

The light detector was covered. The combination had been captured weeks earlier by a concealed camera recording the dial being turned.

The University of Washington security group made the point that lands hardest here: taken individually, the exploit against each of the ten high-tech controls looks trivial to the point of absurdity.

Why that's the interesting part rather than the funny part

The stack was never ten independent defenses. It was ten expressions of one shared assumption — that no attacker would get close enough, for long enough, to study the set.

An IR sensor is formidable if you meet it by surprise in the dark. It's a can of hairspray if you've known its make and position for two years. A magnetic contact is unbeatable if you don't know it exists and a strip of tape if you do.

The stack's real security was a sum of surprises. Remove surprise and the layers stop multiplying difficulty and start merely adding to a to-do list. Ten controls became a sequence of known problems with known answers, and the arithmetic changed from multiplicative to additive.

That's the failure mode, and it's the one the industry eventually internalised the hard way — which is why the impenetrable perimeter got abandoned in favour of assume-breach, continuous monitoring, and blast-radius limitation.

The access model

Leonardo Notarbartolo didn't break in to study the vault. He rented in it.

For roughly two and a half years he posed as a diamond merchant with an office and a safe deposit box in the building, which gave him an unremarkable reason to come and go and to descend to the vault whenever he liked. From inside, he filmed the door and its controls with a concealed camera, took notes on guard schedules and the brand names of the locks and safes, and at some point obtained building blueprints. He carried all of it back to Turin and built a complete model of the target.

He defeated the vault by being welcomed through it, repeatedly, until he understood its controls better than the firm that installed them. The taxonomy for that is a decade old now — legitimate access, long dwell, extensive reconnaissance, single objective, exfiltration in one event — but Antwerp is the physical-world version, and it predates the vocabulary by years.

The control that was actually missing

Everything in the stack was a prevention control. The vault could be opened, and there was no meaningful capability to notice that it had been.

It was opened, occupied for around two hours, comprehensively looted, and closed again — over a weekend, with nobody watching, and the only record of any of it walked out the door in a bag. Detection lag was roughly 40 hours, and detection when it came was a human noticing empty boxes.

Ten prevention controls, zero response capability, and log integrity that depended on the logs being physically present in the building the attacker was inside.

The cleanup

They engineered every step of the intrusion and none of the exit.

The evidence bag was supposed to be burned. One crew member, left alone with it, convinced himself he heard someone coming, scattered the contents across a patch of ground off the E19 and fled. The land belonged to a retiree with a documented hatred of litterers and a habit of reporting illegal dumping.

Within about 48 hours he found the pile and called the police. Recovered from it: a Diamond Center videotape, envelopes from the building, payment stubs, a business card belonging to the crew's electronics specialist, a discarded SIM card, a supermarket receipt whose timestamp let investigators pull store camera footage of one of the crew, an invoice for a low-light surveillance system naming Notarbartolo as the purchaser, and a half-eaten salami sandwich carrying his DNA.

Notarbartolo drew ten years. Others got five apiece. Several participants were never identified. Almost none of the diamonds were recovered, because loose stones are fungible, anonymous, and effectively untraceable once they re-enter the flow through Antwerp and Mumbai and Tel Aviv.

The attack was the engineered part. The cleanup was the part that generated attributable artifacts, which is more or less exactly how sophisticated intrusions get attributed now — not by failing to get in, but by reusing infrastructure, leaving metadata, or otherwise producing the digital equivalent of a sandwich with your DNA on it.

Full write-up on the vault, the reconnaissance, the crew, and the Wired interview where the ringleader claimed the whole thing was an insurance fraud:

https://unteachablecourses.com/antwerp-diamond-center-heist/

The question I'd put to this sub: the Antwerp stack failed because ten controls shared one assumption and nobody stress-tested the assumption rather than the controls. In practice, how often does a layered architecture get audited for correlated dependency — where the layers look independent on the diagram but all rest on the same premise about attacker dwell time, or the same identity provider, or the same assumption that a tenant with valid credentials isn't the threat? I've seen plenty of control-by-control audit. I've seen much less "what single assumption, if false, degrades all of these at once."

reddit.com
u/unteachablecourses — 3 days ago

How to unlock this ground safe from 80s?

We just have model # and serial #, no code or any other information. Some information online said with this info and proof of ownership, the company could provide a reset code. That doesn't seem to be possible as far as I can tell. Any help would be greatly appreciated 🙏🏻

u/StorageNo5403 — 3 days ago

I have a stack on elite dial safe

Curious how hard it works be for a novice or otherwise inexperienced person to crack. Got it from my mother's estate. No combination found.

reddit.com
u/KennyFromTheGym — 3 days ago
▲ 14 r/safecracking+1 crossposts

Safe won't open

Red light flashes for every digit I enter, when the code is done instead of the green light the panel stays stuck and the light flashes red, I can't turn the handle.

Any ideas?

I've added a photo of the panel, safe has worked for at least 10 years

u/ShallWeStartThen — 5 days ago

This safe was here and locked when we bought the house, no one can tell us the code. Netherlands, house built in 1908.

Heard about this community, so I’ll take any tips!

u/adastraperaspera0 — 8 days ago

Found safe while clearing garage

I had the keys from previous owner but it didn’t open due to corrosion.

Found the the brute force way

u/oceanswim — 10 days ago

Our neighbor asked my welder husband to open this safe/dropbox

I bet there is nothing of value in it and want to document my opinion right here. Husband is hopeful ☺️

It's not a priority for him so I dont know when he will get to it or if he'll be able to open it. I'll update when it happens.

u/Zucchini_Breath — 13 days ago
▲ 41 r/safecracking+1 crossposts

Old Safe, can’t access

Bought a house. Previous owner didn’t have code and doesn’t know what’s inside. Any ideas how can I open without damage?

u/Trashpandakun — 11 days ago

Digital Keypad Replacement

I bought a second hand safe and the digital keypad doesn’t work because of corrosion. Is it replaceable? It would be very handy to have a digital entry.

u/TubelessCrank — 11 days ago

TL-15 and TL-30 safes with dials... a waste of $$$? Safe strategies?

I've seen videos of people opening dial safes without much of a problem. If someone spends $10,000 or more for a dial safe that's tool resistant 15 or 30 minutes are they wasting their money?

As I understand it, the locking dials, all use the same key. Is this correct?

There are some dial safes that use 4 numbers. Does the extra number make it exponentially more difficult for a safe cracker?

Example of a used TL-30 https://www.craigslist.org/view/d/oklahoma-city-amsec-amvault-tl-30/qeF4KtNKKnYhRSv95iePBb

Buying/transporting such a safe makes one vulnerable via OPSEC. 4-6+ men of unknown ethics know the address and location of someone with valuables.

Gun to my head, like most people of reason, I'm opening the safe for the bad guys.

The best safe is the one no one knows about. Right?

Thanks in advance.

u/LivingVerticalTime — 11 days ago

I have the key and code but I can’t open it

It’s my father’s safe, he has both the key and the code but he has forgotten how to open it because it has been a couple of years since he last opened it. Any help would be appreciated!

u/Emme248 — 14 days ago