Hackers Can Take Full Control of Unitree G1 Humanoid Robots Over Bluetooth
Brief
A critical attack chain could let attackers within Bluetooth range take full control of Unitree G1 humanoid robots , gaining root-level code execution on the locomotion computer that controls movement, cameras, speakers, voice features, and other peripherals.
The flaws could allow a nearby attacker to obtain root-level code execution on the robot’s locomotion computer, which manages major hardware functions, including movement, cameras, speakers, voice features, and other peripherals.
The research, dubbed UniBLEed, describes a multi-stage exploit involving Bluetooth Low Energy , Unitree’s cloud API, Wi-Fi provisioning system, and services running on the robot’s Linux-based control environment.
Hackers Control Unitree G1 Robots
The attack was assigned CVE-2026-76639 and CVE-2026-76640 and was reportedly reproduced on four Unitree G1 robots.
