Cybersecurity RoboticsRobot cybersecurity research lab

How robot cyber-risk escalated

From a single hacked toy to humanoids used as attack platforms — the landmark moments and disclosed incidents that turned robot security from a curiosity into a safety imperative.

From nation-state hijacks to weaponized fleets

Robot cyber-risk runs deep — militants were intercepting US military drone feeds as early as 2009, and by 2011 a nation-state captured a stealth drone outright — and the ceiling keeps climbing: ransomware on factory floors, humanoids weaponized, and AI that finds the flaws by itself. Each numbered point is a landmark below — click any number to jump to it; the purple line tracks the worst-case frontier over time.

1 · Proof of concept2 · Single robot3 · Fleets & vendors4 · Operational / ransom5 · Autonomous & weaponized123456789101112131518202227242526323329303134353738394641454243444950514847200920102011201220132014201520162017201820192020202120222023202420252026
2017
Consumer robots
IOActive shows remote takeover of NAO/Pepper — robots can be made to move unsafely.
2019
First robot ransomware
Akerbeltz encrypts and ransoms Universal Robots cobots on the factory floor.
2020
Fleets at risk
80+ issues in Universal Robots and 14 in MiR expose robots in hospitals and industry.
2022
The bus breaks
12 DDS CVEs hit ROS 2 and OT; a Unitree Go1 ships with a hidden kill switch.
2025
Humanoids weaponized
A commercial humanoid (Unitree G1) is turned into a surveillance & cyber-ops platform.

The frontier of that curve: one rooted robot becomes patient zero. A wormable takeover (UniPwn) plus a hijacked AI voice-agent lets it scan for and infect its neighbours with no user action — robot-to-robot, the botnet turns physical.

ROBOT BOTNETspreads with no user actionpatient zerorooted · AI voice-agentscans wireless rangeauto-infects neighbours in range
Wormability: UniPwn (CVE-2025-35027 chain) · live robot-to-robot spread demonstrated by DARKNAVY at GEEKCon Shanghai, Dec 2025.

Robot-security milestones, 2009–2026

Two threads on one timeline: this lab's own contributions (solid dark-purple circles — Alias Robotics' disclosures and the tools it built: RVD, RVSS, BlackBox, RIS, CAI) and everything else (lighter outlined circles — the same numbers as the escalation curve above). All share one chronological numbering; click any number to jump to its entry; source linked per entry.

200912201020113420125201367201420158910201611201712132018141516171820192019212223202026272425202128202229313330322023343520243739363820254144454640424320264849505147
51
2026-05
Yarbo robot lawnmowers: a researcher remotely hijacks a 200-lb blade-equipped mower from 6,000 miles away — overriding the physical emergency-stop and driving it over a person — with ~11,000 units worldwide exposed via a shared hardcoded root password that firmware updates keep resetting. source ↗
50
2026-05
Universal Robots PolyScope 5: an unauthenticated command-injection flaw (CVE-2026-8153, CVSS 9.8) yields remote code execution on cobot control boxes. source ↗
49
2026-04
Hugging Face LeRobot (CVE-2026-25874, CVSS 9.3): the popular open-source robot-learning framework deserializes untrusted model files with Python 'pickle', so loading a malicious robot policy gives an unauthenticated attacker remote code execution — reaching the compute host and the physical robot hardware it drives. source ↗
48
2026-03
PX4 Autopilot (CVE-2026-1579, CVSS 9.8): the widely-used open-source drone flight stack doesn't authenticate its MAVLink command channel, so an attacker on the same network can inject commands and hijack a drone mid-flight — full control of navigation across research, commercial and defense UAVs (CISA advisory). source ↗
47
2026-03
Cybersecurity AI autonomously discovers 38 vulnerabilities across three consumer robots. read on this site → · source ↗
46
2025-12
WHILL Model C2/F electric wheelchairs: a missing-authentication Bluetooth flaw (CVE-2025-14346) lets an attacker in range seize full physical control — researchers disabled the safety limits and drove a powered wheelchair off a flight of stairs, turning an assistive mobility robot against the person who depends on it. source ↗
45
2025-10
Ghost Robotics Vision 60: the first cyber-takeover disclosure for a military robot 'dog' (a Q-UGV fielded by US and allied forces) — an unauthenticated, unencrypted MAVLink control channel (CVE-2025-41108, CVSS 9.2) lets an attacker impersonate the operator tablet over Wi-Fi or 4G/LTE and seize full control; coordinated via Spain's INCIBE-CERT. source ↗
44
2025-09
'UniPwn': a wormable BLE takeover chain (CVE-2025-35027 / -60250 / -60251) roots Unitree quadrupeds and humanoids and spreads robot-to-robot — a self-propagating robot botnet. source ↗
43
2025-09
Unitree G1 humanoid repurposed as a surveillance and cyber-operations platform (humanoids as attack vectors). read on this site → · source ↗
42
2025-09
Cybersecurity of a humanoid robot: encryption flaws and unauthorized telemetry uncovered in a commercial humanoid. read on this site → · source ↗
41
2025-08
Pudu Robotics — the world's leading commercial service-robot maker (BellaBot/FlashBot in restaurants, hotels and hospitals): missing authorization checks on the fleet-management API let anyone with a trial-account token control ANY Pudu robot worldwide, redirecting deliveries or shutting down entire fleets in a 'DDoS food attack'. source ↗
40
2025-04
Cybersecurity AI (CAI): the first open, agentic LLM-powered cybersecurity AI — an autonomous defender (and attacker) for robots and beyond; open-sourced by Alias Robotics, it went on to rank #1 at multiple security CTF competitions. read on this site → · source ↗
39
2024-10
RoboPAIR (University of Pennsylvania): the first algorithm to jailbreak LLM-controlled robots — bypassing safety guardrails at up to 100% success to make a commercial Unitree Go2 robot dog, a Clearpath Jackal UGV and a self-driving LLM carry out harmful physical actions, including 'delivering a bomb'. source ↗
38
2024-08
Ecovacs vacuum and lawn robots: broken encryption, missing certificate verification and unauthorized live-camera access. source ↗
37
2024-02
A children's AI companion robot is shown remotely hijackable (Kaspersky): a weak nine-character device ID lets an attacker obtain tokens to video-call ANY unit — seeing and speaking to the child — enumerate every owner (children's names, ages and home locations), and push unsigned firmware to all robots as root. source ↗
36
2024-01
Robot Immune System (RIS): the first nature-inspired 'immune system' for robots — a defense-in-depth endpoint protection platform (next-gen AV, hardening, intrusion prevention, forensic logging) certified to IEC 62443 (Alias Robotics, EIC-funded). source ↗
35
2023-11
Cow-milking robot ransomware (Switzerland): criminals encrypt a dairy farm's robotic milking system and demand $10,000; with the herd's health and insemination records locked, a cow that retained a dead calf had to be euthanized — a real-world robot attack that killed an animal. source ↗
34
2023-04
Russia–Ukraine war: GPS 'spoofing' becomes a mass battlefield weapon against drones — fake satellite signals hijack the navigation of Shahed/Geran-2 attack drones and redirect swarms off target (drones diverted into Belarus by the hundreds), mainstreaming navigation attacks on robots in warfare. source ↗
33
2022-12
iRobot Roomba J7: private household images (including a person on a toilet) captured by test robots leaked online. source ↗
32
2022-08
Unitree Go1 quadruped: a hidden 433 MHz remote 'kill switch' and backdoor tunnel discovered. source ↗
31
2022-04
JekyllBot:5 (Cynerio): five zero-days in Aethon TUG autonomous hospital robots deployed across hundreds of hospitals let an unauthenticated attacker remotely drive the robots, watch patients through their cameras, and block medication deliveries (CVE-2022-1070, CVSS 9.8). source ↗
30
2022-04
ROS 2 / DDS: RTPS message-parsing flaws enable denial of service, network amplification and spoofing across the six DDS implementations powering ROS 2. source ↗
29
2022-04
DDS middleware: 12 CVEs across six implementations powering ROS 2 and industrial systems; ~640 exposed devices found online. source ↗
28
2021-06
BlackBox: the first-ever forensics 'flight recorder' for robots — a ruggedized device that continuously captures robot network traffic so attacks, incidents and malfunctions can be reconstructed after the fact (Alias Robotics). source ↗
27
2020-11
LidarPhone (National University of Singapore & University of Maryland): the first attack to turn a robot vacuum's navigation LiDAR into a covert laser microphone — reading the minute sound vibrations it induces on nearby objects to eavesdrop on private speech, recovering spoken digits and identifying TV content at around 90% accuracy with no camera or microphone. Demonstrated on a Xiaomi Roborock at ACM SenSys 2020, it turns a robot's own navigation sensor into a device to spy on its owner.. source ↗
26
2020-08
Rogue Automation (Trend Micro × Politecnico di Milano): the first demonstration that malware can be written in industrial robots' own programming languages (ABB RAPID, KUKA KRL, and others) — self-propagating, persistent 'task-program' malware hidden inside the robot's automation logic. source ↗
25
2020-06
Mobile Industrial Robots (MiR): 14 vulnerabilities affecting fleets of autonomous mobile robots in hospitals and airports. source ↗
24
2020-03
Universal Robots cobots: 80+ security issues disclosed, including unauthenticated control of the robot arm. source ↗
23
2019-12
Robot Vulnerability Database (RVD): the first open database for responsibly disclosing robot bugs and vulnerabilities — the foundation that let Alias Robotics become the first robot-focused CVE Numbering Authority (2020). read on this site → · source ↗
22
2019-12
Akerbeltz: the first industrial-robot ransomware, demonstrated against Universal Robots UR3/UR5/UR10 cobots. read on this site → · source ↗
21
2019-11-07
Real-time ≠ real-fast: a ROSCon 2019 reflection by Alias Robotics reframes robot security as preserving control deadlines under attack — not simply achieving low latency. read on this site → · source ↗
20
2019-10
Henn na Hotel 'Tapia' in-room robots (Japan): the first hack of a hotel service robot — independent researcher Lance R. Vick found that tapping an NFC tag behind the bedside concierge robot's head breaks it out of its kiosk app into Android, letting anyone enable untrusted apps and install a hidden streaming app for persistent remote camera and microphone access to every future guest of the room. The vendor ignored the report, so Vick disclosed the 0-day publicly on 12 October 2019 and H.I.S. Group modified all 100 egg-shaped units at its Maihama Tokyo Bay 'robot hotel'.. source ↗
19
2019-05
SROS2: the first practical security tooling for ROS 2, the dominant robot framework — brings DDS-Security (PKI authentication, per-node access-control 'enclaves' and AES-GCM encryption) to robot computational graphs, so a robot's nodes can no longer be freely spoofed or eavesdropped. read on this site → · source ↗
18
2018-11
Robot hazards: a safety-and-security risk assessment shows attacks can turn robots into physical hazards. read on this site → · source ↗
17
2018-07
Robot Vulnerability Scoring System (RVSS): the first severity-scoring system built for robots — it extends CVSS with safety and robot-specific factors so a flaw's physical-harm potential is actually captured (Alias Robotics). read on this site → · source ↗
16
2018-06
ISO/TC 299/WG6 (Kyoto): Víctor Mayoral-Vilches lobbies to recognise cybersecurity in the robot safety standards ISO 22166 (modularity) and ISO 10218 (collaborative robots) as a precondition to safety — the first push to fold security into robot functional-safety standards, finally adopted in ISO 10218:2025. source ↗
15
2018-06
Aztarna: thousands of ROS and industrial robot endpoints found exposed on the public Internet. read on this site → · source ↗
14
2018-01
HoneyBot: the first honeypot built for robots — a decoy robotic system (Georgia Tech) that physically carries out only the safe commands and merely simulates the dangerous ones, luring attackers into believing they're in control while logging everything for attribution. source ↗
13
2017-05
Trend Micro × Politecnico di Milano 'Rogue Robots': the first remote compromise of standard industrial robots (ABB IRB140, plus Fanuc/Yaskawa/Kawasaki/Mitsubishi) — a spoofed configuration file silently sabotages production into defective parts and shows the arm can endanger nearby workers. source ↗
12
2017-03
IOActive: robots hacked before Skynet — remote code execution and unsafe movement in SoftBank NAO/Pepper and UBTECH Alpha consumer/service robots. source ↗
11
2016-02
Russia's Khmeimim airbase (Syria): the first forensically-documented real-world battlefield GPS spoofing against drones — thousands of fake-signal events repel attacking UAVs by faking an airport location (drones are geofenced to avoid airports); traced from the ISS by C4ADS with UT Austin. source ↗
10
2015-08
Rocking drones with sound (Son et al., KAIST): the first attack on a robot's physical sensors — a tuned acoustic tone resonates a drone's MEMS gyroscope at its resonant frequency, corrupting attitude control and crashing the drone in flight, with no access to its software or network. source ↗
9
2015-05
Raven II teleoperated surgical robot hijacked in a University of Washington study — man-in-the-middle and malicious emergency-stop attacks over public networks overrode and halted a surgeon's commands: the first experimental takeover of a surgical robot. source ↗
8
2015-01
MalDrone (Rahul Sasi, Nullcon): the first backdoor malware resident on a drone itself — it kills the autopilot and wedges between the drone's brain and its motors and sensors, survives a reset, and beacons to a remote bot-master (demonstrated on the Parrot AR.Drone). source ↗
7
2013-12
SkyJack (Samy Kamkar): the first drone built to autonomously seek out and hijack other drones in mid-air, turning them into an 'army of zombie drones' — the conceptual origin of the wormable robot botnet, a decade before such self-propagating takeovers reached commercial legged robots. source ↗
6
2013-05
First cyber-physical security assessment of the Robot Operating System (ROS): Los Alamos researchers — via a DEF CON 20 robot 'honeypot' contest — show that ROS's publish/subscribe core has no authentication or integrity, the foundational warning that the field's dominant robot framework was insecure by design. source ↗
5
2012-06
First public GPS-spoofing hijack of a civilian drone (Todd Humphreys, UT Austin): invited by DHS, the team commandeers a UAV's navigation at White Sands with a counterfeit satellite signal — the confirmed proof that civil GPS can capture drones, later cited in congressional testimony. source ↗
4
2011-12
Iran captures a US RQ-170 Sentinel stealth drone deep inside its territory — reportedly by jamming its satellite link and spoofing GPS to force an autonomous landing: the landmark nation-state hijack of a military robot. source ↗
3
2011-10
A persistent keylogging virus infects the Predator and Reaper drone ground-control stations at Creech Air Force Base — the first known malware inside U.S. military drone cockpits, logging pilots' keystrokes and resisting repeated removal. source ↗
2
2009-12
Iraqi insurgents intercept live video from US Predator drones using $26 'SkyGrabber' software — the military's unencrypted downlinks let Iran-backed fighters see exactly what the drones were watching: the first publicly known cyber compromise of a military robot. source ↗
1
2009-09
A Spotlight on Security and Privacy Risks with Future Household Robots (Denning, Kohno et al., University of Washington): the first security study of consumer robots — the team remotely discovers, eavesdrops through, and hijacks three off-the-shelf home robots (WowWee Rovio, Erector Spykee, RoboSapien V2), warning that robots could be turned against their owners years before anyone else was looking. source ↗