How robot cyber-risk escalated
From a single hacked toy to humanoids used as attack platforms — the landmark moments and disclosed incidents that turned robot security from a curiosity into a safety imperative.
From nation-state hijacks to weaponized fleets
Robot cyber-risk runs deep — militants were intercepting US military drone feeds as early as 2009, and by 2011 a nation-state captured a stealth drone outright — and the ceiling keeps climbing: ransomware on factory floors, humanoids weaponized, and AI that finds the flaws by itself. Each numbered point is a landmark below — click any number to jump to it; the purple line tracks the worst-case frontier over time.
The frontier of that curve: one rooted robot becomes patient zero. A wormable takeover (UniPwn) plus a hijacked AI voice-agent lets it scan for and infect its neighbours with no user action — robot-to-robot, the botnet turns physical.
Wormability: UniPwn (CVE-2025-35027 chain) · live robot-to-robot spread demonstrated by DARKNAVY at GEEKCon Shanghai, Dec 2025.Robot-security milestones, 2009–2026
Two threads on one timeline: this lab's own contributions (solid dark-purple circles — Alias Robotics' disclosures and the tools it built: RVD, RVSS, BlackBox, RIS, CAI) and everything else (lighter outlined circles — the same numbers as the escalation curve above). All share one chronological numbering; click any number to jump to its entry; source linked per entry.