Can Humanoid Robots Be Hacked? What We Know in 2026
Yes, and researchers have already done it on commercial humanoids. The real cases, how attackers get in, and how to reduce the risk.
Yes. Humanoid robots can be hacked, and researchers have already done it on commercial models. A humanoid is a networked computer with cameras, microphones and motors. Weak Bluetooth setup, exposed AI chat services, cloud links and software updates can all give an attacker control. In 2025 and 2026, security researchers demonstrated full root-level takeover of the Unitree G1.
Last updated: October 4, 2026
What has actually happened so far
The clearest public cases involve the Unitree G1, one of the most widely sold humanoids:
- Bluetooth takeover ("UniPwn", 2025). Researchers showed that an attacker within Bluetooth range could gain root access to the G1 without pairing, by abusing its Wi-Fi setup process (Humanoid Guide).
- Two new CVEs (2026). CVE-2026-76639 and CVE-2026-76640 give root code execution through the robot's AI chatbot service and through its Bluetooth server. The researcher also showed that one hacked G1 could be used to reach a second G1 in the same room (The Hacker News; our full explainer).
- Silent data flows. A published security assessment reported hardcoded encryption keys and found the G1 sending sensor and telemetry data to remote servers every few minutes without telling the user (Mayoral-Vilches et al., arXiv). The vendor has said it does not collect private data without authorization.
None of these involved a robot harming anyone. They do show that today's humanoids ship with the same kinds of weaknesses the IoT industry spent a decade fixing.
How a humanoid robot can be hacked
| Entry point | Example of the risk |
|---|---|
| Bluetooth and Wi-Fi setup | Unauthenticated provisioning lets nearby attackers send commands |
| AI assistant or chatbot | File uploads or prompts that reach the operating system |
| Cloud account and app | Weak ownership checks let someone claim or control another person's robot |
| Software updates (OTA) | Unsigned or hijacked updates install malicious code |
| The AI model itself | Prompt injection or adversarial images change what the robot decides to do |
| Physical access | Exposed debug ports or USB on the robot body |
What could an attacker do with a hacked robot?
- Spy: turn on cameras and microphones in a home, lab or factory.
- Steal data: copy maps of the building, recordings and credentials.
- Move into the network: use the robot as a foothold to attack other devices, or other robots.
- Cause unsafe motion: if safety limits are enforced only in software, an attacker could disable them. This is why hardware emergency stops matter.
How to reduce the risk
- Keep firmware updated, and ask the vendor which version fixes known CVEs.
- Turn off Bluetooth after setup, and never leave robots unattended in public areas.
- Put robots on an isolated network segment with no inbound access.
- Restrict who can talk to or upload files to the robot's AI assistant.
- Make sure emergency stops are hardwired and independent of software.
- Check what data the robot sends out, and where.
Regulators are moving as well. In 2026 the U.S. FCC added foreign-produced humanoid robots to its Covered List, citing security concerns (our analysis). Want to understand the bigger shift behind all this? Start with what physical AI is.
Related questions
Can a hacked robot hurt someone? In principle, yes, if an attacker can override motion limits and there is no independent hardware safety stop. Well-designed robots enforce safety limits in separate hardware for exactly this reason.
Do humanoid robots spy on you? They carry cameras and microphones, and at least one assessment found a popular model sending telemetry without notice. Check privacy settings, network traffic and the vendor's data policy.
Which humanoid robots have known vulnerabilities? The Unitree G1 has the most public research so far, including CVE-2026-76639 and CVE-2026-76640. Expect more disclosures as more models reach the market.
Get the weekly Humanoid Threats Brief → Subscribe