Robots at home: data, security and how to protect yourself (2026)
A robot in your home sees, hears and remembers more than a surveillance camera: it has cameras, a LiDAR that reconstructs the floor plan of your rooms, microphones for voice commands and, on models with 4G, a GPS. This data goes through the manufacturer's app and often through its servers. Between 2025 and 2026 researchers documented, on some Unitree robots, telemetry being sent to servers in China and flaws that allow the robot to be taken over via Bluetooth; on 28 July 2026 the US FCC blocked new authorisations for Chinese humanoid and quadruped robots, while Europe has no equivalent measure. You don't need to give up the robot: you need a separate Wi-Fi network, Bluetooth switched off after set-up, updates installed and care about what you film. Here are the facts, with dates, and the countermeasures.
What a robot records: cameras, LiDAR, microphones, home maps, GPS/4G position
The sensors declared by the manufacturers, from the Robolero catalogue (verified on 18 September 2026):
| Model | What it sees and hears | Network and position | Recognition |
|---|---|---|---|
| Unitree Go2 Air | 360° 4D LiDAR | Wi-Fi and the Unitree app; no 4G | — |
| Unitree Go2 Pro / X | 4D LiDAR, voice commands, intercom, speaker | 4G with GPS | — |
| Unitree Go2 EDU | 4D LiDAR, depth camera, Jetson Orin | Wi-Fi, full SDK | — |
| Unitree G1 | 3D LiDAR + depth camera | Wi-Fi, Unitree app and cloud | — |
| Dobot Rover X1 | Front and rear 1080p cameras at 30 fps | Wi-Fi, app; UWB on the Pro | Follows a person |
| Xiaomi CyberDog 2 | 19 sensors, Jetson Xavier NX | Wi-Fi, Xiaomi app (China only) | Faces |
| KEYi Loona | 720p camera, 3D ToF, 4 microphones | Wi-Fi; ChatGPT in the cloud | Faces |
| Booster K1 | Stereo depth camera, 3 microphones | Wi-Fi, SDK | — |
A LiDAR does not take photos, but it builds a three-dimensional map of your home: walls, furniture, doors. Combined with the camera, it is a detailed plan of where you live. With 4G and GPS, the Go2 Pro and Go2 X can be reached and located even away from your Wi-Fi.
Where the data goes: app, manufacturer's cloud, servers abroad (the Unitree telemetry case)
Every robot in the table is set up from an app with an account; from there the data's path depends on the manufacturer, and it is not always declared.
The best-documented case is the Unitree G1. In the report "Cybersecurity AI: Humanoid Robots as Attack Vectors" (September 2025), Víctor Mayoral-Vilches (Alias Robotics), Andreas Makris and Kevin Finisterre analysed the traffic of a G1 and found persistent MQTT connections to the servers 43.175.228.18:17883 and 43.175.229.18:17883, with flows of 1.03 and 0.39 Mbps (ZME Science, 27 Sep 2025): audio, video, sensor data, GPS coordinates, battery and joints, about every five minutes, without notifying the user (Interesting Engineering, 1 Oct 2025). The connections are encrypted; the researchers read the content before encryption (RoboticsBiz, 11 Aug 2026).
Unitree disputes this: it says it does not collect private or sensitive data without authorisation, and no independent audit has closed the matter (Humanoid.guide, 5 Sep 2026). The point, as the researchers put it, is not the spying but the consent: does the person with the robot at home know what leaves and where it goes?
For the other manufacturers the picture is less documented. KEYi's privacy notice (Loona), last updated on 5 February 2023, does not say where the data is stored or whether voice requests go through third parties: n/a. Xiaomi sells the CyberDog 2 only in China, with a Chinese app and Chinese support.
The known flaws: UniPwn (September 2025), the 2026 CVEs and the state of the patches as of 18 Sep 2026
| Flaw | Published | Robot | Severity | Status as of 18 Sep 2026 |
|---|---|---|---|---|
| CVE-2025-2894, "CloudSail" backdoor | 28 Mar 2025 | Unitree Go1 (out of production) | CVSS 6.6 | Hidden service with remote control for whoever holds the API key. The Go1 lives on only in the used market: firmware to be checked |
| UniPwn | 20 Sep 2025 | Unitree Go2, B2, G1, H1 | Root via Bluetooth, without pairing, within about 30 m; spreads from robot to robot | Unitree on 29 Sep 2025: "most of the fixes" completed. As of 5 Sep 2026 no public patch documented by third parties; the vulnerable authentication is still in the production firmware |
| CVE-2026-76639 and CVE-2026-76640 | 27 Aug 2026 | Unitree G1 EDU, firmware up to 1.5.2 (tested up to 1.5.4.x) | CVSS 8.8 and 7.5 | Firmware 1.5.5.0 of 1 Sep 2026: blocks the chain according to the researcher, without independent verification |
| CVE-2026-8153 | 8 May 2026 | Universal Robots PolyScope 5 (industrial cobots) | CVSS 9.8 | Fixed in PolyScope 5.25.1 |
UniPwn changed the conversation. Unitree robots receive Wi-Fi credentials over Bluetooth Low Energy during set-up; the interface does not filter what it receives and every unit shares the same encryption key, already published online. Encrypting the word "unitree" with that key is enough to pass as an authorised user and inject commands with root privileges. A compromised robot can look for other Unitrees within Bluetooth range and infect them on its own (Interesting Engineering, 1 Oct 2025; Archyde, 26 Sep 2025).
The two 2026 CVEs, found by Olivier Laflamme on the G1 EDU, go one via Bluetooth and the other through an unauthenticated network bridge with a static AES key. This time Unitree responded: it validated the reports, paid a $5,000 bounty on 6 August 2026, fixed a flaw in the cloud API and released firmware 1.5.5.0 on 1 September 2026 (Boschko, 27 Aug 2026). CVE-2026-8153 does not touch home robots, but it shows the industry's problem: a robot's safety limits are software, and software can be rewritten (RoboticsBiz, 11 Aug 2026).
What the authorities have done: the FCC order in the USA (July 2026) and what applies in the EU (AI Act, GDPR)
United States. On 28 July 2026 the FCC added Chinese humanoid and quadruped robots and connected inverters to its "Covered List", citing Unitree and UBTech: new models cannot obtain authorisation for import, sale and marketing. It is not retroactive: robots already in use stay in use, flaws and all (Tech Times, 28 Jul 2026).
European Union. No specific measure (Humanoid.guide, 5 Sep 2026). The general rules apply, read on EUR-Lex on 18 September 2026:
- AI Act, Regulation (EU) 2024/1689: applies from 2 August 2026 (art. 113). Art. 50 requires that anyone interacting with an AI system be told so, unless it is obvious. A robot that talks through ChatGPT falls within the case.
- Cyber Resilience Act, Regulation (EU) 2024/2847: from 11 September 2026 manufacturers must notify actively exploited vulnerabilities, with a first alert within 24 hours (art. 14); the rest applies from 11 December 2027 (art. 71).
- Machinery Regulation (EU) 2023/1230: applies from 14 January 2027 (art. 54).
- GDPR: for use at home for purely personal purposes it does not apply (FAQ 12 of the Italian data protection authority, the Garante); it applies to whoever makes the robot and processes its data on their own servers, wherever they are.
Robots with ChatGPT and teleoperation: who listens (Loona) and who watches (NEO)
Loona (KEYi, $499 on the US store, €549 on the Italian store) has four microphones, a 720p camera and converses through ChatGPT, which runs in the cloud: your voice necessarily leaves the house. KEYi writes that "as much of the data processing as possible is done directly by Loona" (keyirobot.com, 18 Sep 2026), but does not say where the servers are or who receives the voice requests. A robot that recognises faces and keeps listening for its name is an always-on microphone in the living room.
NEO (1X Technologies, $20,000 or $499 a month, US deliveries from 2026) is the home humanoid that folds the laundry. It works partly through teleoperation: 1X calls it "Scheduled Expert Mode", a company expert "can remotely supervise its actions at scheduled times" (1x.tech/neo, 18 Sep 2026). The Wall Street Journal, testing it, reported that a human operator can look inside your home through the robot's eyes; the CEO said the company needs users' data to improve it (Euronews, 30 Oct 2025). Agenda Digitale (3 Aug 2026) sums up the risk: teleoperators and company archives take "data, images, sounds, habits and emotions" out of the most private room we have.
How to protect yourself: separate Wi-Fi network, Bluetooth off after set-up, updates, accounts, what not to film
The countermeasures recommended by the UniPwn researchers (Archyde, 26 Sep 2025; Interesting Engineering, 1 Oct 2025), plus the common sense of anyone buying used.
- Separate Wi-Fi network. A guest network or VLAN, isolated from computers, NAS and cameras: if the robot is compromised, it stays locked in there.
- Bluetooth off after set-up. UniPwn goes through Bluetooth. Once the first connection is made, switch it off from the app; if the model does not allow it, keep it away from crowded places (attack range about 30 m).
- Updates. Install firmware as soon as it comes out: on the G1 EDU, 1.5.5.0 closes the 2026 CVEs. On a used robot ask for the installed version (see the used guide).
- Accounts. A used robot arrives with the previous owner's account unlinked in front of you, otherwise they see what the robot sees. A unique password for the app.
- Cloud and telemetry. The Go2 Air and Pro walk and respond to commands even offline: leave the robot without internet when it doesn't need it. On the router you can block outbound connections to addresses you don't recognise.
- What not to film. Don't point cameras and LiDAR at landings, courtyards, the neighbours' gardens or the street: the Garante forbids filming them (see below). At home, keep the robot out of the rooms where you wouldn't want a camera.
- Children and guests. Microphones also record people who agreed to nothing: tell whoever comes in, and switch the robot off when it isn't needed.
What the law says in Italy: the legal guide and the Garante's FAQ on home video surveillance
Owning and using a robot dog in Italy is legal: we explain it in the legal guide. For filming, the Garante's video-surveillance FAQ apply (garanteprivacy.it, read on 18 September 2026):
- FAQ 12: the use of cameras "in one's own home for purely personal monitoring and security purposes" is outside the scope of the GDPR. Domestic helpers and workers must still be informed.
- FAQ 10: the field of view "must in any case be limited to spaces that are exclusively one's own", excluding common areas (courtyards, landings, stairs, garages) and third parties' areas; "it is also forbidden to film public areas or areas of public passage".
The FAQ do not cover audio: for microphones the prudent rule is not to record others without telling them. For work, events or videos to be published, the domestic exemption falls away and the full GDPR returns.
ℹ️ This article is for information purposes and is neither legal advice nor a security audit. Flaws and updates change: the dates are those of the sources consulted on 18 September 2026.
Frequently asked questions
Can a Unitree robot dog be hacked? Yes, it is documented: UniPwn (September 2025) gives root access via Bluetooth to the Go2, B2, G1 and H1, and two 2026 CVEs hit the G1 EDU. For the latter there is firmware 1.5.5.0; for UniPwn, as of 18 September 2026, no patch is documented by third parties. A separate network and Bluetooth off greatly reduce the risk.
Does the robot send my data to China? For the Unitree G1 researchers measured connections to two Chinese servers with audio, video, sensors and GPS about every five minutes (September 2025); Unitree denies collecting sensitive data without authorisation. For the other manufacturers the privacy notice often doesn't say: n/a.
Can I buy a Unitree robot in Italy after the FCC ban? Yes. The order of 28 July 2026 applies in the United States and concerns new authorisations, not robots already sold. In Europe there is no equivalent ban; the AI Act, the Cyber Resilience Act, CE marking and the GDPR apply.
Does a robot with a camera at home breach privacy? No, if it films only your own spaces for personal purposes (FAQ 12 of the Garante). It becomes a problem if it frames landings, courtyards, the neighbours' property or the street (FAQ 10), or if you publish videos with recognisable people.
What do I check on a used robot for security? Firmware version, account unlinked from the previous owner, Bluetooth that can be disabled, no undocumented changes to the system. On a used Go1, check that the CloudSail backdoor (CVE-2025-2894) is not active.
Want to know what your robot is worth, with up-to-date firmware and a clean account? Get Robolero's free valuation: model, year, hours and battery condition, and you have the estimate in a minute. If you then want to sell it, Robolero's marketplace is open to private sellers and dealers.
Sources
- Interesting Engineering, "Security flaw in Unitree humanoids", 1 Oct 2025: https://interestingengineering.com/innovation/security-flaw-unitree-humanoids-china (accessed 18 Sep 2026)
- ZME Science, Alias Robotics report on the G1 (telemetry addresses and flows), 27 Sep 2025: https://www.zmescience.com/science/news-science/cybersecurity-experts-say-these-humanoid-robots-secretly-send-data-to-china-and-let-hackers-take-over-your-network/ (18 Sep 2026)
- Archyde, "Unitree Robot Hack: Risks, Security & What to Do Now", 26 Sep 2025: https://www.archyde.com/unitree-robot-hack-risks-security-what-to-do-now/ (18 Sep 2026)
- RoboticsBiz, "What CVE-2026-8153 and UniPwn reveal about robot safety", 11 Aug 2026: https://roboticsbiz.com/robot-cybersecurity-vulnerabilities-what-cve-2026-8153-and-unipwn-reveal-about-robot-safety/ (18 Sep 2026)
- Tech Times, FCC order of 28 Jul 2026: https://www.techtimes.com/articles/321890/20260728/fcc-bans-chinese-humanoid-robots-power-inverters-linked-confirmed-backdoors.htm (18 Sep 2026)
- Humanoid.guide, "Unitree exhibits G1 at IFA amid unresolved security questions", 5 Sep 2026: https://humanoid.guide/unitree-exhibits-g1-at-ifa-amid-unresolved-security-questions/ (18 Sep 2026)
- Boschko, "UniBLEed" (CVE-2026-76639 and CVE-2026-76640, timeline and firmware 1.5.5.0), 27 Aug 2026: https://boschko.ca/g1-ble-rce/ (18 Sep 2026)
- MITRE CVE: CVE-2025-2894 (28 Mar 2025, CVSS 6.6), CVE-2026-8153 (8 May 2026, CVSS 9.8), CVE-2026-76639 (CVSS 8.8) and CVE-2026-76640 (CVSS 7.5), both of 27 Aug 2026: https://cveawg.mitre.org/api/cve/CVE-2026-76639 (18 Sep 2026)
- Agenda Digitale, "Robot in casa: chi vede e ascolta davvero quello che facciamo?", 3 Aug 2026: https://www.agendadigitale.eu/sicurezza/privacy/robot-in-casa-chi-vede-e-ascolta-davvero-quello-che-facciamo/ (18 Sep 2026)
- Garante per la protezione dei dati personali, video-surveillance FAQ (FAQ 10 and 12): https://www.garanteprivacy.it/faq/videosorveglianza (18 Sep 2026)
- Euronews, "This humanoid robot does your cleaning, but a human may peek into your home", 30 Oct 2025: https://www.euronews.com/next/2025/10/30/sci-fi-meets-chores-this-humanoid-robot-does-your-cleaning-but-human-may-peek-into-your-ho (18 Sep 2026)
- 1X, NEO page ("Scheduled Expert Mode", $200 deposit): https://www.1x.tech/neo (18 Sep 2026)
- KEYi, Loona page (sensors, $499) and privacy notice of 5 Feb 2023: https://keyirobot.com/en-us/products/petbot (18 Sep 2026)
- EUR-Lex, Regulation (EU) 2024/1689 (AI Act), art. 50 and 113: https://eur-lex.europa.eu/eli/reg/2024/1689/oj (18 Sep 2026)
- EUR-Lex, Regulation (EU) 2024/2847 (Cyber Resilience Act), art. 14 and 71: https://eur-lex.europa.eu/eli/reg/2024/2847/oj (18 Sep 2026)
- EUR-Lex, Regulation (EU) 2023/1230 (machinery), art. 54: https://eur-lex.europa.eu/eli/reg/2023/1230/oj (18 Sep 2026)
- Robolero catalogue, `public/models.js` (sensors, prices, statuses), verified on 18 Sep 2026.