Unitree G1 Vulnerabilities Explained: CVE-2026-76639 and CVE-2026-76640
Two Unitree G1 humanoid robot flaws give attackers root over Bluetooth and the AI chatbot, and one robot can reach the next. What happened and what to do.
TL;DR: Two vulnerabilities in the Unitree G1 EDU humanoid robot, CVE-2026-76639 and CVE-2026-76640, let an attacker gain root-level control of the robot. One works over the network through the robot's AI chatbot service. The other works over Bluetooth Low Energy (BLE) from nearby, with no pairing required. The researcher showed that a compromised G1 could be used to reach a second G1 in the same room. Unitree fixed a related cloud-side flaw in July 2026, but as of late August, public reporting had not confirmed which firmware release fixes the on-robot bugs.
Last updated: October 4, 2026
What happened
On August 27, 2026, security researcher Olivier Laflamme published research on the Unitree G1, one of the most widely sold humanoid robots (roughly a $20,000 platform popular with universities and labs). He described two vulnerabilities that each give root-level code execution on the robot (The Hacker News; Security Affairs).
- CVE-2026-76639: a path-traversal weakness in the G1's AI chatbot service (
chat_go). It allows arbitrary file writes that can be escalated to command execution as root, from the robot's network. - CVE-2026-76640: unauthenticated Bluetooth Low Energy writes combined with a buffer overflow in the robot's BLE server. Anyone within Bluetooth range can trigger it, and no pairing is required.
According to Security Affairs, the work took about three months, starting in May 2026. Unitree paid a $5,000 bug bounty in August, and Laflamme described the vendor's cooperation as "close to ideal."
Why this one matters: "hack one robot, reach the next"
The most important finding isn't root access by itself. It's that a compromised G1 can be used to attack another G1 over Bluetooth, without the attacker needing to find or reconfigure the second robot. Laflamme demonstrated this on two robots in one room, and he did not claim a self-spreading worm (The Hacker News).
That nuance matters. Still, the pattern is new for humanoids: robots that sit next to each other in a lab, warehouse or factory can become each other's attack path, much like laptops on a flat office network.
This is not the G1's first Bluetooth problem
The August disclosure follows "UniPwn", a Bluetooth exploit disclosed in September 2025 that also allowed root access to G1 robots from roughly 30 meters away without pairing. According to Humanoid Guide, the authentication design behind that exploit remained in production firmware, and no public patch had been documented.
Separately, research by Alias Robotics alleged that the G1 regularly sent audio, video, location and sensor data to servers in China without notifying the operator. Unitree has said it does not collect private or sensitive data without authorization. Neither side's claim has been independently verified by a full platform audit (Humanoid Guide; see also Alias Robotics' paper on humanoids as attack vectors).
Patch status (as reported)
| Item | Status |
|---|---|
| Cloud account-to-robot ownership check | Patched by Unitree in July 2026 |
| BLE pairing / buffer overflow (CVE-2026-76640) | Fixed firmware version not publicly confirmed |
| Chatbot path traversal (CVE-2026-76639) | Fixed firmware version not publicly confirmed |
Sources: Security Affairs, The Hacker News. If Unitree publishes a firmware advisory, we will update this table.
Who is affected
The research targeted the G1 EDU model. Whether other Unitree robots that share components (for example the BLE provisioning service) are affected has not been confirmed. G1 units are common in university labs, R&D teams and demo fleets, and those are often environments with little network segmentation and many robots in one room.
What G1 owners should do now
- Check firmware: confirm you are on the latest Unitree release, and ask Unitree support directly which version fixes CVE-2026-76639 and CVE-2026-76640.
- Limit Bluetooth exposure: where your workflow allows, disable BLE after provisioning, and keep robots away from public or shared spaces when not in use.
- Segment the network: put robots on an isolated VLAN with no inbound access from general corporate or guest networks.
- Treat the chatbot as an attack surface: restrict who can upload content or files to on-robot AI services.
- Watch for anomalies: unexpected motion, disabled collision detection, or new outbound connections are red flags worth investigating.
- Plan for physical safety: make sure emergency stops are hardwired and independent of the robot's software stack.
The bigger picture for humanoid security
The G1 findings fit a pattern now familiar from IoT, but with higher stakes. Convenience features (Bluetooth provisioning, cloud pairing, voice and chat assistants) ship first, and authentication arrives later. With humanoids, a compromised device can see, hear and move. That is what makes physical AI security different from traditional IT security. As standards like ISO 25785-1 and the EU AI Act mature, expect buyers and regulators to start asking for the same security evidence they already demand from industrial control systems.
FAQ
Can the Unitree G1 be hacked? Yes. Researchers have demonstrated root-level compromise of the G1 over Bluetooth (CVE-2026-76640, and the earlier 2025 "UniPwn" exploit) and through its AI chatbot service (CVE-2026-76639).
Is the Unitree G1 vulnerability wormable? The researcher showed that one compromised G1 could attack a second nearby G1 over Bluetooth, but he did not claim or demonstrate a self-spreading worm.
Has Unitree patched CVE-2026-76639 and CVE-2026-76640? Unitree fixed a related cloud ownership-check flaw in July 2026. As of late August 2026, public reporting had not confirmed the firmware version that fixes the on-robot bugs.
Does the Unitree G1 send data to China? Alias Robotics alleged that it does. Unitree says it does not collect private or sensitive data without authorization. No independent full audit has settled the question.
See the bigger picture in our State of Humanoid Robot Security 2026 report.
Get the weekly Humanoid Threats Brief → Subscribe