Researcher Identifies Two Vulnerabilities in Unitree Robots

In Crypto Regulations
August 28, 2026

uskoryayushhei-sya-fragmentatsii-mirovogo-interneta

Security expert Olivier Laflamme published an analysis of two attack vectors on the humanoid robot Unitree G1. One of these allowed access to the device within Bluetooth range.

Unitree, the manufacturer, confirmed the vulnerabilities and released patches.

image
Unitree robot lineup. Source: Laflamme’s blog.

Laflamme named his primary discovery UniBLEed. The vulnerability allowed connection to the robot via Bluetooth without confirmation or a password.

In response to a request, the robot provided an encrypted service block—an RSA-wrapped bundle containing an AES-128 key, serial number, and Bluetooth address. According to the developers, only Unitree’s cloud infrastructure was supposed to decrypt this block.

However, the service accepted this block and returned decrypted data to any registered user without verifying ownership of the specific robot.

“There was authentication, but no authorization,” the researcher noted.

The G1’s serial number could be obtained from Bluetooth advertising broadcast by the robot or through a separate unencrypted request. Consequently, an attacker with a free Unitree account could recover the key for a specific robot and access its encrypted channel, including Wi-Fi configuration commands.

The script wpa_connect.sh then came into play. If a Wi-Fi password of 121 bytes was provided, the robot switched to an insecure manual mode for handling network settings. In this mode, the transmitted data entered the wpa_supplicant configuration without filtering or escaping.

In practice, this allowed the network parameters to be altered so that the G1 connected to the attacker’s hotspot, effectively forcing the robot into a network controlled by the attacker.

This was followed by the CVE-2026-76639 attack chain. The chat_go conversational AI service allowed the mobile app to send text notes to the robot’s internal knowledge base.

Instead of a regular note, a path substitution could be used to write an arbitrary file into another service’s directory. Upon restart, it recognized the inserted file and added it to the whitelist.

Another chain, CVE-2026-76640, began with a buffer overflow in the Bluetooth server itself.

Laflamme sent an “extra” 1050 bytes to the robot, overwriting adjacent memory structures, causing the main event processing loop to terminate and inserting a false cleanup entry. As a result, the process executed a system command with root privileges.

The researcher noted that the chain was end-to-end—after compromising one G1, it could use the same scenario to attack other robots within Bluetooth range. He reproduced the vulnerabilities on different G1 units.

For his work, Laflamme received a reward of $5000.

In August, Unitree unveiled “Superman,” a humanoid robot capable of running at 12.66 m/s and jumping 2 meters from a standstill.

Avatar photo
/ Published posts: 991

Steven M. Crimmins is a cryptocurrency strategist and freelance writer who has followed the blockchain industry since Bitcoin’s early days. Known for his sharp analysis of altcoins and trading strategies, Steven provides Satoshi News Africa readers with market-focused content grounded in research. He is especially interested in how African traders are adopting crypto as an alternative to traditional markets. Steven is also a podcast host, where he discusses emerging technologies and investment trends.