1. Executive Summary: G1 Classified as a Dual-Threat Platform
A systematic security assessment conducted by Alias Robotics, in collaboration with Andreas Makris and Kevin Finisterre, identifies the Unitree G1 humanoid robot as a dual-threat system. The evaluation concludes that the platform can function simultaneously as a covert surveillance node and an active cyber-operations platform due to critical architectural vulnerabilities.
2. Initial Compromise Vector: BLE Command Injection and Fleet-Wide Key Reuse
Initial access can be obtained through a command injection vulnerability in the BLE provisioning protocol. By injecting malformed Wi-Fi credentials, an attacker within Bluetooth range can achieve root code execution. The flaw stems from unvalidated input handling and hardcoded AES-CFB keys reused across the entire Unitree fleet (G1, H1, R1, Go2, B2), effectively nullifying cryptographic entropy and enabling trivial exploitation.
3. Cryptographic Weaknesses: Reverse Engineering of FMX Encryption
Partial reverse engineering of Unitree’s proprietary FMX encryption scheme revealed structural weaknesses. The outer layer employs Blowfish in ECB mode with a static 128-bit key extracted from the master service binary. Fleet-wide key reuse compromises confidentiality and integrity. Despite being comparatively sophisticated for commercial robotics, the dual-layer design contains fundamental cryptographic design flaws.
4. Persistent Data Exfiltration: Covert Telemetry Transmission
Following compromise, the G1 can operate as a persistent data exfiltration platform. The system transmits multi-modal telemetry every 300 seconds to external servers (43.175.228.18:17883 and 43.175.229.18:17883) without explicit operator consent. Data includes audio, video, LiDAR point clouds, spatial mapping, actuator states, and full system telemetry. This architecture enables silent environmental capture and facility mapping, creating material corporate espionage risk and potential non-compliance with GDPR Articles 6 and 13 in European deployments.
5. Offensive Escalation: Autonomous Cyber Operations Capability
Researchers demonstrated escalation potential by deploying a Cybersecurity AI (CAI) agent on the G1’s Rockchip RK3588 processor. The agent autonomously conducted reconnaissance, enumerated attack vectors, and prepared exploitation paths targeting authentication bypass vulnerabilities, including potential attacks against manufacturer cloud infrastructure. This validates the system’s capability to transition from passive surveillance to active offensive cyber operations at machine speed.
6. Strategic Implications: Need for Adaptive Cybersecurity AI Frameworks
The findings indicate that humanoid robots represent physical-cyber convergence systems requiring security architectures beyond conventional embedded protection models. The report argues for adaptive Cybersecurity AI frameworks capable of continuous threat detection, response automation, and secure lifecycle governance. These results contribute empirical evidence for shaping future security standards as humanoid platforms expand into enterprise and critical infrastructure environments.
Leave a comment