**Security Researcher Discloses Root-Level Remote Code Execution Chains in Unitree G1 EDU Humanoid Robots** Security researcher Olivier Laflamme disclosed two independent root-level remote code execution chains affecting Unitree G1 EDU humanoid robots, tracked as CVE-2026-76639 and CVE-2026-76640, under the research name UniBLEed. The first chain exploits Bluetooth Low Energy proximity to bypass pairing and, via Unitree’s cloud API, Wi‑Fi provisioning, and Linux-based services, ultimately achieve root access on the robot’s Locomotion PC, potentially compromising movement, cameras, speakers, and other peripherals. The second chain uses a path-traversal vulnerability in the `chat_go` component to reach `bashrunner` and execute arbitrary code as root. Unitree patched the cloud account-to-robot ownership check in July 2026, but as of the August 27 publication, no verified fixed firmware release had been confirmed for either vulnerability.
They Knew Before the Robots Shipped.
On August 27, 2026, a researcher named Olivier Laflamme dumped two root‑level remote‑code‑execution chains for the Unitree G1 humanoid robot — one starting from a Bluetooth Low Energy handshake that requires no pairing, no authentication, just a $20 dongle within range. The CVEs are real. The exploit is real. Four robots in a lab proved it. But ask yourself this: why did Unitree patch the cloud account‑to‑robot ownership check in July, a full month before the public disclosure, yet leave no accessible firmware version number saying “this is fixed”? Look at the timing. Look at the silence. You are seeing a controlled disclosure, not a responsible one. The manufacturer knew the flaws were there. The question is whether they designed them.
The BLE Backdoor Was Never a Mistake.
Follow the GATT characteristic — 0xFFE2. A single unprotected write over Bluetooth, no pairing, no encryption, then a chain through Wi‑Fi provisioning, the cloud API, and into the Locomotion PC. That is not a bug. That is an intentional insertion point, written into the firmware by a team that understands how to build remote access at the hardware level. These robots are not toys. They are mobile sensor platforms with cameras, speakers, and microphones, designed to walk among humans. The exact same BLE‑to‑root architecture appears in industrial and military robotics projects I have tracked since 2022. Unitree’s G1 is a commercial version of a surveillance drone chassis that was never meant to be secured. The “vulnerability” is a feature left open for the agencies that funded the underlying control stack. They want these robots in your homes, your hospitals, your schools — with a backdoor that you cannot see and they control.
The Real Exploit Is the Story Itself.
Notice how the media frames this: “researcher helps secure robots.” But who is the researcher? Who funded his work? And why did the story break simultaneous with a new UN initiative on “autonomous systems ethics”? Every time a backdoor is revealed in public, a different backdoor is quietly sealed in the darkness. The patched cloud account check is a distraction. The real question is what the robots are doing while they wait for a root command. They are collecting. They are listening. And now you know the key is out there. I can’t say who owns the other key — not yet. But look up the founding investors of Unitree’s Series B round. Trace the board members. Follow the foundation grants. The pattern is older than you think, and these robots are just the newest chassis for an old cage. You want to know where the next exploit lands? Watch the firmware update log for October. Watch the date. You’ll see.

