DJI Pays $30K for Romo Robot Hack

💡Gamepad hack exposed 7K robot vacs—critical security lesson for embodied AI devs.
⚡ 30-Second TL;DR
What Changed
Sammy Azdoufal accidentally accessed 7,000 DJI Romo robots via PlayStation gamepad.
Why It Matters
Emphasizes securing robot fleets against unintended network access, boosting ethical hacking incentives via bounties. May prompt DJI users to update firmware promptly.
What To Do Next
Scan your robot IoT fleet for open remote control endpoints using tools like Shodan.
🧠 Deep Insight
Web-grounded analysis with 4 cited sources.
🔑 Enhanced Key Takeaways
- •Azdoufal used Anthropic’s Claude Code AI to reverse-engineer the DJI Romo’s communication protocol without bypassing encryption or hacking DJI systems.[1][2][3]
- •The vulnerability stemmed from DJI’s MQTT message broker lacking topic-level access controls, allowing plaintext access to data from other devices after authenticating with one token.[3]
- •DJI’s Power portable battery stations, sharing the same MQTT infrastructure, were also accessible through the flaw.[3]
- •DJI initially claimed the flaw was fixed a week prior, but Azdoufal demonstrated thousands of robots still vulnerable during a live demo with a journalist.[3]
🛠️ Technical Deep Dive
- •DJI Romo communicates with servers via MQTT protocol without topic-level access controls, storing device data (floor plans, live video, microphone input) in plaintext.[1][3]
- •Authentication with a single device's private token granted access to traffic from ~7,000 vacuums and Power battery stations across 24 countries.[2][3]
- •TLS encryption protected connections but not stored data content; remaining issues include PIN bypass for camera streams.[1][3]
🔮 Future ImplicationsAI analysis grounded in cited sources
⏳ Timeline
📎 Sources (4)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
- techradar.com — Tinkerer Accidentally Gets Access to Thousands of Dji Romo Robot Vacuums
- Tom's Hardware — User Accidentally Gains Control of Over 6 700 Robot Vacuums While Tinkering with Their Own Device to Enable Control with a Playstation Controller Security Flaw Reveals Floor Plans and Live Video Feeds
- malwarebytes.com — Hobby Coder Accidentally Creates Vacuum Robot Army
- popsci.com — Robot Vacuum Army
Weekly AI Recap
Read this week's curated digest of top AI events →
👉Related Updates
AI-curated news aggregator. All content rights belong to original publishers.
Original source: The Verge ↗

