Security Flaw in Unitree Robots Puts Users at Risk

Security Flaw in Unitree Robots Puts Users at Risk

Ondřej Barták
Ondřej Barták
Entrepreneur and Programmer
10. 10. 2025
3 minutes reading · 22 views
Security Flaw in Unitree Robots Puts Users at Risk

Chinese robot manufacturer Unitree Robotics is facing intense scrutiny over serious security flaws in its humanoid robots, particularly the G1 and H1 models. These flaws involve Bluetooth Low Energy (BLE) and the Wi-Fi setup interface, allowing nearby attackers to gain full access and remotely control the robots. Moreover, these flaws spread like a worm, enabling a compromised robot to independently search for and infect other robots within Bluetooth range, potentially leading to the creation of a network of controlled devices.

Researchers found that command injection via BLE enables privilege escalation and complete control of the robot. Shared encryption keys and weaknesses in proprietary security schemes undermine the system's confidentiality and integrity. The robots regularly send telemetry data, including sensor readings and service status, to servers in China every 300 seconds, often without clearly notifying the user, raising concerns about privacy and compliance with the GDPR (General Data Protection Regulation).

The G1 model functions as a covert sensor and platform for offensive cyber operations, posing risks to both privacy and national security. Despite some fixes and recent firmware updates, key vulnerabilities remain unpatched, and data continues to be sent to China.

G1 Model

Researchers Uncover the UniPwn Exploit

On September 20, 2025, security experts Andreas Markis and Kevin Finnisterre disclosed an exploit called UniPwn, which affects the Go2 and B2 quadruped robots as well as the G1 and H1 humanoid models. These robots are already used in laboratories, universities, and some police departments. The flaw stems from the use of BLE to simplify Wi-Fi setup, where users first pair the device via Bluetooth and then switch to Wi-Fi.

The researchers discovered that Unitree's implementation relies on hard-coded encryption keys that were leaked online. This means that all devices are identical from an attacker's perspective, making it possible to exploit thousands of robots at once. A compromised robot can then spread autonomously to others within range, potentially creating a botnet.

Andreas Markis explained that a simple attack could involve rebooting the robot, but an attacker could carry out much more sophisticated actions. The researchers expressed disappointment with Unitree Robotics' communication, as the earlier discovery of a backdoor in the Go1 model did not lead to sufficient changes.

Go2 model

Mysterious Data Transmission to China

The G1 model secretly sends data to servers in China every five minutes without informing the user. This data includes sensor readings and service status, enabling hackers to take over the robot's computer and use it for cyberattacks. This practice raises privacy concerns because the data is transmitted without consent.

Earlier incidents involved the Go1 model, which used a third-party cloud service that exposed thousands of robots—including those at major US universities—to the risk of remote takeover and unauthorized access to live camera feeds. This service was later shut down, and newer models have reportedly abandoned it.

H1 Model

Unitree's Response and Expert Recommendations

On September 29, Unitree published a statement on LinkedIn, stating that it was aware of the security vulnerabilities and network issues. The company has completed most of the fixes and will release them in updates soon. Unitree emphasized that its robots are designed for offline use and send only basic data when operating online, with plans to improve permission management.

However, independent reviews question whether these fixes are sufficient, as data continues to flow to China and some flaws remain. Victor Mayoral-Vilches, founder of Alias Robotics, recommended that users connect the robots only via Wi-Fi and disable Bluetooth to minimize risks.

Source: interestingengineering.com

Advertisement

Content created with help from UpTier.

SEO and GEO on autopilot. UpTier’s multi-agent systems write and optimize content for search engines and AI answers.

Discover UpTier ↗

Category:AI
Did you enjoy this article?
Discover more interesting posts on our blog
Back to blog

Related posts

OpenAI gives Codex reusable cloud workspaces accessible from any deviceOpenAI gives Codex reusable cloud workspaces accessible from any device
Codex gains reusable cloud development environments, alongside voice controls in its CLI, code reviews in the ChatGPT desktop app and cloud-based security tools.
2 min read
2. 10. 2026
Amazon releases Strands Decider 2B for AI workflow decisionsAmazon releases Strands Decider 2B for AI workflow decisions
Strands Decider 2B selects from predefined options and returns a confidence score. The fully open-source model is available now and small enough to run locally.
2 min read
1. 10. 2026
OpenAI says it disrupted a campaign to extract hidden model reasoningOpenAI says it disrupted a campaign to extract hidden model reasoning
OpenAI reported a coordinated effort to extract protected model reasoning and said it closed an extraction pathway. It attributed the main cluster of activity to individuals associated with Moonshot AI, the developer of Kimi.
3 min read
1. 10. 2026
Přihlaste se k odběru našeho newsletteru
Zůstaňte informováni o nejnovějších příspěvcích, exkluzivních nabídkách, a aktualizacích.
CodedTrip

Operated by CodedTrip LLC, USA.

YouTube
TikTok