StoryOther
Researchers disclose UniPwn, a Bluetooth flaw that gives attackers root access to Unitree G1, H1 and Go2 robots
Researchers Andreas Makris and Kevin Finisterre published UniPwn, an exploit for the Bluetooth setup interface of Unitree G1/H1 humanoids and Go2/B2 quadrupeds. Hardcoded encryption keys and trivial checks let anyone within ~30 meters gain root access; infected robots can spread to others nearby. Unitree said it completed most fixes.
- Bluetooth BLE setup uses hardcoded encryption keys leaked online; trivial verification enables unauthenticated root access.
- Attack range ~30 meters; no pairing required; root access enables arbitrary command execution.
- Contagion: infected robot compromises other Unitree robots in radio range, creating self-propagating botnet.
- G1 also sends data to Chinese servers every 5 minutes without user notification; Unitree acknowledged September 29.