Unitree Robotics Scrambles to Patch 'Wormable' Flaw Affecting Humanoid and Quadruped Robots

Unitree Robotics Scrambles to Patch 'Wormable' Flaw Affecting Humanoid and Quadruped Robots

A significant security vulnerability has been discovered across a range of robots from Unitree Robotics, a prominent Chinese robotics firm. The flaw, first reported by IEEE Spectrum, allows for remote hijacking and can spread automatically between devices, creating the potential for a "robot botnet."

The vulnerability affects both humanoid models like the G1 and H1 and quadrupedal robots such as the Go2 and B2. According to security researchers Andreas Makris and Kevin Finisterre, the flaw resides in the robots' Bluetooth Low Energy (BLE) interface, which is used for initial Wi-Fi configuration.

The researchers found that the BLE communication, while encrypted, uses a hardcoded key that had been previously exposed. An attacker could exploit this by sending a specific encrypted string to bypass authentication, thereby gaining root-level administrative access to the robot's operating system. Once compromised, attackers could execute malicious commands by disguising them as Wi-Fi network names or passwords. Potential actions include data theft, installing backdoors, blocking firmware updates, and taking full remote control of the robot.

A critical aspect of the vulnerability is its "wormable" nature. An infected robot can autonomously scan for other vulnerable Unitree devices within Bluetooth range and propagate the exploit, enabling a chain reaction of infections. According to the IEEE Spectrum report, this represents what is believed to be the first publicly demonstrated major exploit for a commercial humanoid platform.

The researchers stated they first informed Unitree of the flaw in May 2025 but received a limited response, with communication ceasing in July. Citing a lack of action from the company, they publicly released a proof-of-concept exploit tool called "UniPwn" on GitHub in September 2025.

In response to the public disclosure, Unitree issued a statement on platforms including LinkedIn and X, acknowledging it was aware of the security issues. The company said it "immediately started to address these problems and has now completed most of the repair work," with updates to be pushed to customers soon. Unitree also announced the formation of a dedicated product security team and stated it would improve permission management to minimize "any potential misunderstandings," alluding to what it called "exaggerated rumors" online.

Despite the company's assurances, some observers noted that key vulnerabilities, such as the hardcoded BLE key, appeared to persist after the statement was released. The issue has drawn attention from the broader robotics security community, with firms like Alias Robotics publicly offering to collaborate with Unitree to enhance system security.

Subscribe to ChinaBiz Insider

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
[email protected]
Subscribe