Securing our robotics future.
A compromised server leaks data; a compromised robot can kill — it welds, lifts, drives, or operates on a person. In robotics, a security flaw is a safety flaw. That is why robot cybersecurity matters more than in any other field — and why we quantify, in the open, how fast that frontier is widening.
≈ one new robot vulnerability disclosed every 9 days over the last three years — and the pace is rising.
The humanoid frontier
A commercial humanoid — the Unitree G1 — was shown to hand an attacker root access over Bluetooth, ship static cryptographic keys, and stream telemetry to overseas servers: a helper turned into a mobile surveillance and cyber-operations platform. This is where robot cybersecurity stops being theoretical.
The cybersecurity of a humanoid ↗ Humanoids as attack vectors ↗
A cyberattack that ends in the physical world
Robot intrusions follow the classic attack lifecycle — with two robotics twists. Many robots grant root on first access, so the privilege-escalation step simply vanishes; and the chain doesn't end in stolen data. It ends in actuation — a machine that welds, lifts or drives. That is why we treat every robot security flaw as a safety defect.
Stages after the Cyber Kill Chain and the ROS 2 threat model; robot techniques drawn from the Akerbeltz ransomware and humanoid case studies.Why robots are different
In IT, a breach costs you data. A robot is where cybersecurity and safety stop being separate problems: it is a networked computer — fusing IT, OT and IoT attack surfaces — bolted to a body that welds, lifts and drives. Compromise the computer and you command the body, so a robot's security flaw is a safety defect. That overlap — not any single new vulnerability — is what makes robot cybersecurity uniquely consequential.
Grounded in the lab's review of robot cybersecurity and Safety requires security in robotics — and traced in the Milestones of how the threat escalated.
The robot attack surface is already counted in millions
This is not a forecast. The IFR counts 4.66 million industrial robots already operating worldwide, with roughly half a million more installed every year. And humanoids — the most sensor-dense, network-connected and AI-driven class yet — are scaling from 24,000 in 2025 to a projected 248,000 by 2030. Every unit fuses a network stack, perception and actuation into one body that can be attacked and can cause harm. Securing them is not premature — it is overdue.
Operational stock: IFR World Robotics 2025 (4.664M industrial robots, 2024). Humanoid installed base 24k→248k (2025–2030): ABI Research. Forecasts are directional.Security is becoming a legal requirement — yet obsolete?
Regulators and standards bodies now encode a thesis this lab pushed early: back at ISO/TC 299/WG6 in Kyoto (June 2018), Víctor Mayoral-Vilches lobbied to recognise cybersecurity in ISO 22166 (modularity) and ISO 10218 (collaborative robots) as a precondition to safety. Seven years on, ISO 10218:2025 makes it binding — recognising cybersecurity as a mandatory precondition to safety — and the EU Cyber Resilience Act (first proposed 15 September 2022, mere weeks before OpenAI's ChatGPT upended how vulnerabilities are found) makes secure-by-design binding for any product with digital elements — and from 20 January 2027 the EU Machinery Regulation 2023/1230 folds a cybersecurity risk assessment into the conformity assessment a robot needs to earn its CE mark: no assessment, no European market. In robotics, a security flaw is now — in law — a safety defect. This stops being abstract on 11 September 2026: a maker that learns its robot carries an actively-exploited flaw then has 24 hours to warn ENISA — with penalties reaching €15M or 2.5% of global turnover. A security bug becomes a reportable, finable incident. Yet a regime whose vulnerability-discovery model was fixed in that pre-ChatGPT moment may already be outrun: as the lab's analysis below shows, generative-AI agents now find and exploit robot flaws faster than any certification cycle can keep pace — the law arriving, and perhaps obsolescing, at once.
Read the lab's analysis: Certifying Ghosts — how AI agents break the CRA ↗
EU CRA (Reg. 2024/2847): proposed 15 Sep 2022 (COM/2022/454), ~11 weeks before ChatGPT (30 Nov 2022); reporting duties from 11 Sep 2026 (Art. 14 — 24h/72h/14-day cascade), full application 11 Dec 2027, penalties to €15M/2.5% (Art. 64) · ISO 10218-1/-2:2025 (in force Apr 2025) references IEC TS 63074 → IEC 62443 · EU Machinery Regulation (EU) 2023/1230 applies 20 Jan 2027 — cybersecurity in the conformity assessment for machinery.Robot vulnerabilities over time
New disclosures per year (bars) and the cumulative total (line), aggregated across the world's robot-vulnerability records. It is the tip of what the lab tracks — severity, sources, most-affected makers and the closing window to patch all live in the explorer.
Sources: RVD, NVD (robot keywords), EUVD, CISA ICS advisories, FDA surgical-robot cybersecurity recalls & curated research — 395 records, deduplicated by CVE.