Insights from the sentdex episode “Unitree G1 Security Disaster”, published September 30, 2025.
Research confirms that Unitree G1 robots suffer from hard-coded Bluetooth AES keys, allowing anyone in range to execute commands as root. The host demonstrates how these security flaws enable unauthorized remote access and bricking of devices. While Unitree claims these issues are being addressed, the fundamental vulnerability persists because of identical, non-modifiable encryption keys across the entire fleet.
Topics: robotics, cybersecurity, Unitree, IoT, remote code execution