Security researcher Olivier Laflamme has published an in-depth breakdown of two attack chains targeting the Unitree G1 humanoid robot. One of the vulnerabilities allowed attackers to access the device as long as they were within Bluetooth range. Unitree has confirmed both issues and released patches to address them.
UniBLEed: What Did Laflamme Discover?
Laflamme's main discovery was a vulnerability he dubbed UniBLEed. This flaw let anyone connect to the robot over Bluetooth without needing any authentication or password. When hit with a specific request, the robot would respond with an encrypted service block—an RSA-wrapped package containing the AES-128 key, the serial number, and the Bluetooth address.
Unitree's Response and Patch Status
The manufacturer acknowledged the vulnerabilities and pushed out patches. Laflamme's write-up details two separate attack chains, but the spotlight is on the UniBLEed Bluetooth vector as the most critical issue.
