UniPwn exploits Unitree robots, allowing remote root access via network services. The vulnerability combines hardcoded keys, weak handshakes, and insecure command execution. Compromised devices could attempt to move laterally to nearby robots via wireless connections.
See also: Ant Group R1: The humanoid robot that will compete with Tesla Optimus

Security researchers Bin4ry and d0tslash have published an analysis on GitHub of an exploit dubbed “ UniPwn ,” which affects multiple Unitree product lines, including the G1, Go2 humanoids, and the B2 quadrupeds . This vulnerability can be used to escalate privileges to root.
The vulnerability involves reported hardcoded cryptographic keys and a handshake that checks only for the string “unitree,” along with unsanitized user data that is concatenated into shell commands executed by the system. These elements create a simple path from a network packet to arbitrary code execution.
Because the exposed service accepts wireless connections, a compromised unit can receive commands and attempt to affect devices within radio range. This changes the threat model from a single exploited device to potential lateral movement to nearby units.
See also: Unitree presents the impressive humanoid robot R1

The researchers say the exploit uses a Bluetooth Low Energy and Wi-Fi, allowing a compromised unit to receive commands over wireless connections and potentially affect devices within radio range. They describe parts of the UniPwn chain as “wormable,” meaning that successful exploitation could allow malicious code to persist and attempt to spread, increasing the risk of automated spread between accessible devices.
However, the wormable behavior observed in the tests does not guarantee rapid spread in the real world. Real-world spread depends on device configuration, network segmentation, firmware diversity, physical proximity, vendor update rate, and operator practices. Controlled laboratory tests may show a potential, but spread in the field will be shaped by these operational factors. Therefore, this first robotic infection remains unlikely, although manufacturers and operators should not treat it as a remote theoretical threat.
See also: Pregnancy Robot: Robot will give birth to human babies!

Independent research into jailbreaking robots running LLMs adds to the urgency of these technical findings. A project known as RoboPAIR has shown that carefully crafted prompts can force robot controllers, including the Unitree Go2, to perform malicious actions. The RoboPAIR team reported high success rates when they provided the target robot's API and crafted prompts that the API executed as code.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
