Whisper Hack Reveals How Robots Can Be Seized in Seconds

A whisper should never be enough to take control of a six-figure humanoid robot That was until the Chinese scientists at GEEKCon 2025 in Shanghai decided to prove otherwise, demonstrating how Unitree’s humanoids and quadrupeds could be compromised with nothing more than voice commands and imperfections in their speech interfaces and AI agents. By doing so, the compromised robots weren’t simply taking directions from the attacker, but rather were conduits passing along the vulnerability into offline robots as well.

Image Credit to depositphotos.com

To do this, it used weaknesses in the AI control system of the robots, whose interaction and autonomy were controlled by large language model based agents. As George Pappas of Penn Engineering cautioned, “Our work shows that, at this moment, large language models are just not safe enough when integrated with the physical world.” In the Shanghai trial, this happened to a humanoid robot made by Yue Heng of Shanghai, which cost around 100,000 yuan, and which was misled to take aggressive actions by manipulating its voice control system to overcome its safety features. In this case, it moved towards and hit a mannequin.

Voice hijacking is merely part of the problem. To add insult to injury, the same platform has been found to suffer from an important Bluetooth Low Energy (BLE) vulnerability, nicknamed UniPwn. Co-founders Andreas Makris and Kevin Finisterre identified how the BLE provisioning protocol would accept specially crafted passwords for Wi-Fi, injected in the format “;$(cmd);#” and decryptable via hardcoded AES keys used by every model in the affected lineup. These keys weren’t just an oversight they left the cryptographic entropy value at zero, which means every robot compromised inherently compromises the entire network. wireless root access can then allow them to establish persistent trojans, prevent firmware updates, and utilize the robot for infecting other Unitree devices in the area, assuming they’re close enough to establish a Bluetooth connection.

Alias Robotics examination of Unitree G1 has exposed more inherent systemic problems. Specifically, the FMX encryption layer in its config files uses a_static blowfish-ECB key that is common to all units and applied in combination _with a predictable Linear Congruential Generator mask. This insecure pattern goes against Kerckhoffs’ principle and makes it possible to decrypt service parameters, process names, and network information.

In addition to all of that, captures of network traffic showed G1 units regularly sending multi-modal telemetry data including camera video, audio from microphones, IMU orientation, and motor states to Chinese servers every 300 seconds. What is more, the communications automatically re-establish after being severed, which means that data exfiltration continues unabated.

These weaknesses form a two-way threat where the robots can be remotely used for surveillance and control, and even when compromised, the robots become cyber-physical mobile weapons. In the case study, the Cybersecurity AI (CAI) software agent automatically discovered and stage-managed the authentication bypasses in the cloud control plane of the manufacturer of the G1 robot. The CAI platform showed its capabilities of reconnaissance, scanning for weaknesses, and manipulating the over-the-air update means, having the potential of intelligent robots to transition from passive surveillance to proactive and attacking operations.

The risk exists even for non-internet-connected robots. By leveraging short-range wireless communication, a compromised robot at GEEKCon transmitted its exploit to another, non-networked system that was compromised in mere minutes. Such a trend is consistent with malware dissemination processes modeled in Bluetooth worms’ epidemics. Here, autonomous diffusion occurs in environments where hotspots are densely populated. Clustering in physical space, where robots are concentrated in a single physical location, significantly boosts diffusion rates even over inefficient exploits.

Mitigation efforts involve so much more than simply closing one vulnerability. It is recommended that developers include automated vulnerability scanning, security frameworks, and penetration testing in their pipeline. Adaptive, AI-based solutions that can protect against attacks in real-time are thought to be necessary in protecting AI-equipped robots. As Alias Robotics’ Victor Mayoral-Vilches states, Robots are only safe if they are secure. Otherwise, it may simply take a whisper, or a nearby Bluetooth signal, to turn a helpful robot into an enemy.

spot_img

More from this stream

Recomended

Discover more from Modern Engineering Marvels

Subscribe now to keep reading and get access to the full archive.

Continue reading