In August, a security researcher named Olivier Laflamme aka Boschko published a detailed account of how he took full control of a Unitree G1 humanoid robot over Bluetooth, without pairing, without a cable, and without knowing anything about the robot beforehand. He also showed that once you have that control, you can use it to disable the robot's collision detection. Then he showed that a compromised G1 can run the same attack on the next G1 within Bluetooth range. He tested that on two robots in his living room.
Quick clarification before we go further
This research concerns the Unitree G1 EDU, not the R1. If you read my earlier piece on the R1, that work came from a separate team at Alias Robotics and dealt with surveillance and a robot quietly sending audio, video, and room maps to servers in China. Surveillance is passive. This article is about someone else being able to move the robot.
How Laflamme got the robot
He didn't buy it. Unitree sent it to him.
Earlier in 2026, Laflamme and a co-researcher named Ruikai found vulnerabilities in Unitree's Go2 robot dog. As part of settling that disclosure, Unitree's security team sent Laflamme a G1 EDU (a $43,900 humanoid robot) as payment. He notes in his writeup that this almost never happens in robotics. Vendors don't send researchers hardware. Unitree did, which is directly why this research exists at all.
He spent about three months with it. No AI tools for the actual vulnerability hunting. Just time and a steady diet of Jim Beam and animal crackers, by his own account.
The first vulnerability
The G1 EDU runs a conversational AI service called chat_go. It lets you upload "knowledge" to the robot as text snippets the AI can reference later in conversation. You send it a filename and some content, and it saves a file on the robot's computer.
The problem is that nothing checks where the file gets saved. By using path traversal in the filename (basically telling the system to navigate up and out of the expected directory) Laflamme could write files anywhere on the robot's main computer. He wrote a script into the directory of another service called bashrunner.
Bashrunner's job is to run shell scripts on behalf of other services on the robot. It builds its list of allowed scripts once at startup by scanning the directory โ so Laflamme wrote his script there, restarted bashrunner so it would pick up the new file, and then told bashrunner to run it. The script executed with full system privileges.
That's CVE-2026-76639. A root shell on the computer that controls a humanoid robot's movement, delivered through its AI chatbot knowledge upload feature.
The second vulnerability
CVE-2026-76640 is the more severe one, because it starts from Bluetooth range with no physical access and no prior knowledge of the target robot. Laflamme named the exploit chain "UniBLEed", referring to the core bluetooth attack.
The G1's Bluetooth server accepts incoming write commands without requiring the connecting device to pair first. From there, Laflamme found that he could recover the robot's unique encryption key, which secures both its Bluetooth and Wi-Fi communications, by exploiting a gap in Unitree's cloud API.
The cloud checked that you had a valid Unitree account. It did not check that your account owned the robot you were asking about. So a free account was enough to ask Unitree's servers to decrypt the key for any G1 nearby. Unitree patched that in July 2026 by adding an ownership check.
With the key, Laflamme could reach the robot's Wi-Fi configuration commands over Bluetooth. He sent a password deliberately longer than 63 characters, which tricked the robot's Wi-Fi setup script into a fallback mode that wrote his input directly into a configuration file. The robot connected to his hotspot.
From his own network, he used the chatbot exploit to read where the robot's software had loaded in memory. Then, across three Bluetooth connections, he sent 1,050 bytes into a buffer that could only hold 500. The robot kept accepting data past the limit without checking whether it had room. That overflow let him overwrite two values in memory that control what the software does when it shuts down. When it did shut down, it ran his command instead of its own cleanup routine. The Bluetooth server crashed. The shell stayed open. The whole chain takes about 45 seconds.
Then the robot becomes the weaponized link
After compromising one G1, Laflamme modified the Bluetooth chain so the compromised robot could run the same exploit against another G1 within Bluetooth range. This is why he calls UniBLEed "wormable."
Laflamme only demonstrated the chain across two G1s in one room. He explicitly says he does not know how many robots could be daisy-chained or how far the attack could spread. So the responsible version of the claim is not "G1s can infect an entire fleet." It is: the robot-to-robot propagation mechanism was demonstrated.
Why this is a good thing
Unitree is a rare humanoid robot manufacturer with a public record of independent security research. Its robots probably aren't less secure than anyone else's. They're just among the only ones a researcher can actually get their hands on.
Figure, Boston Dynamics, Apptronik: their robots live inside closed commercial deployments. An independent researcher can't walk into a store and buy an Atlas. No hardware access, no audit. No audit, no published findings. Nothing gets found, nothing gets fixed. The absence of published vulnerabilities for those platforms is not evidence of security.
Unitree sent a researcher a $43,900 robot, got audited, moved quickly through triage, patched the cloud gap before public disclosure, paid a $5,000 bounty on August 6. On September 1 they released firmware 1.5.5.0, which Unitree says addresses the exploit chain, though that fix hasn't been independently verified yet.
The bar in humanoid robotics right now is low enough that fixing what you break and thanking the person who found it counts as leadership. Unitree cleared it.
