During an independent security investigation, I managed to identify and analyze in detail two serious attack chains on the humanoid robot Unitree G1. Both allow full control over the device, with one of them working remotely, within Bluetooth signal range. The manufacturer has already confirmed the issues and released corresponding security updates.

UniBLEed Vulnerability: Authentication Bypass

The first and most critical finding, which I named UniBLEed, involves the ability to connect to the robot via Bluetooth without any confirmation or password. Upon request, the device sends an encrypted service block — an RSA-wrapped bundle containing an AES-128 key, serial number, and Bluetooth address. As intended by the architects, only Unitree's cloud infrastructure could decrypt this data.

However, my analysis revealed a fundamental flaw: the service accepts this block and returns the decrypted data to any registered user, without verifying whether they are the owner of the specific robot. This is a classic example of an error where authentication exists, but authorization does not. The G1's serial number is easily extracted from Bluetooth advertisements, which the device broadcasts in plaintext, or via a separate unencrypted request. Thus, an attacker with a free Unitree account can recover the key of a specific robot and gain full access to its encrypted channel, including Wi-Fi configuration commands.

Escalation and the Second Attack Chain

Further development of the attack involves the wpa_connect.sh script. If a Wi-Fi password of 121 bytes is passed to it, the robot switches to an insecure manual mode for processing network settings. In this mode, data enters the wpa_supplicant configuration without any filtering or escaping. In practice, this allows network parameters to be substituted so that the G1 connects to the attacker's hotspot, forcibly moving the robot into a network controlled by the attacker.

After this, the second chain (CVE-2026-76639) is triggered. The conversational AI service chat_go allows the mobile application to send text notes for the internal knowledge base. Instead of a regular note, it is possible, through path substitution, to write an arbitrary file into the directory of another service. After a restart, it sees the planted file and adds it to the allowed list, opening the way for further manipulations.

Separately, it is worth considering an alternative vector (CVE-2026-76640), starting with a buffer overflow in the Bluetooth server itself. By sending an "extra" 1050 bytes, I overwrote adjacent structures in memory, caused the main event processing loop to terminate, and substituted a fake cleanup record. As a result, the process invokes a system command with root privileges. It is worth emphasizing that the chain is end-to-end: after compromising one G1, it can use the same scenario to attack other robots within Bluetooth range. I reproduced the vulnerabilities on different G1 instances, confirming their stability.

For this work, I received a bounty of $5000.

My comment: The found issues are a vivid example of how the race for functionality in consumer robotics outpaces security. Particularly alarming is the possibility of horizontal attack propagation between robots. The industry needs to reconsider its approach to threat modeling for physical devices, where the consequences of hacking go far beyond data leaks.