Computers with Legs: The Inevitable Hacking of Humanoid Robots

The dream is seductive: a sleek humanoid robot, as capable and complex as a modern car, gracefully assisting in our factories, homes, and hospitals. The reality, however, is that we’re building computers with arms and legs, and we’ve forgotten to secure them. As internet-connected robots emerge as the next great technological leap, they bring a sobering truth: a compromised robot isn’t just a data breach, it’s a physical threat that can spy, sabotage, and even harm.

Experts have been warning for years that today’s smart robots are vulnerable to the same cyber risks as any laptop or smartphone, but with the terrifying addition of autonomous physical action. An attacker could not only steal data but could also weaponize the machine itself. This isn’t science fiction; it’s the new frontier of cyber-physical security threats, and we are woefully unprepared. This is a deep dive into the security and safety minefield of modern robotics—from chilling real-world hacks to the patchwork of global regulations struggling to keep pace.

When Good Robots Go Rogue: The Technical Risks

Modern service robots are marvels of engineering, packed with sensors, cameras, powerful motors, and sophisticated AI. Each of these features, unfortunately, is also a potential attack vector.

Hacking and Unauthorized Control

Like any networked device, a robot’s software is hackable. Security researchers have repeatedly demonstrated that popular robots possess flimsy authentication, allowing them to be commandeered with frightening ease. In a now-infamous demonstration, researchers at cybersecurity firm IOActive disabled the safety limiters on a UBTech Alpha 2 home robot and reprogrammed it to aggressively stab a tomato with a screwdriver. The experiment was a chilling proof-of-concept for how a friendly-looking android could be turned into a weapon.

“Even running at slow speeds, their force is more than sufficient to cause a skull fracture,” the IOActive researchers noted about collaborative factory robots, highlighting that once a hacker is in control, safety features become meaningless.

A “kill switch,” an emergency shutdown mechanism, is often proposed as a solution. European lawmakers have even suggested making them mandatory. But if an attacker can disable that switch remotely, the only thing left to do is run.

Surveillance and Privacy Invasion

With cameras and microphones as their eyes and ears, hacked robots become mobile surveillance platforms inside our most private spaces. This was demonstrated horrifically in 2024 when owners of the high-end Ecovacs Deebot X2 robot vacuum found their devices hijacked. Attackers remotely accessed the vacuums’ live camera feeds and screamed obscenities through the built-in speakers, in one case even chasing the family dog.

“It’s like having a webcam that can roll around your house and look at your family,” one shocked owner realized. Researchers later showed the same model could be compromised over Bluetooth from 140 meters away, allowing an attacker to silently watch, listen, and even steal the home’s Wi-Fi credentials. This isn’t just a breach; it’s a profound violation.

Data Leakage and Subtle Sabotage

Beyond live spying, a compromised robot can leak stored data or, more insidiously, manipulate its tasks. In 2017, researchers from Politecnico di Milano and Trend Micro remotely altered an industrial robotic arm’s calibration by a mere 2 millimeters. This tiny, undetectable change caused the robot to produce faulty parts. “If that was an airplane…it can be a catastrophic event,” the researchers warned. Their scan of the internet found over 80,000 industrial devices, many of them robots, exposed online without even a password.

Autonomous Misbehavior and Physical Harm

Humanoid robots are designed for physical interaction. If their AI malfunctions or is tricked, they can cause accidents. We’ve already seen a chess-playing robot break a child’s finger in 2022 because the child moved too quickly for its programming. Now, imagine a malicious actor instructing a hotel service robot to ram a guest, or a kitchen assistant to misuse a knife. The potential for injury is very real, transforming a helpful device into an unpredictable menace.

Video thumbnail

The Automotive Parallel: Lessons Not Yet Learned

The closest parallel we have for the risks of mobile, autonomous robots is the modern automobile. Cars are computers on wheels, and the auto industry learned about cybersecurity the hard way.

A seminal 2015 hack of a Jeep Cherokee, where researchers remotely killed the engine on a highway, led to a recall of 1.4 million vehicles and a massive industry-wide security overhaul. Today, new vehicles sold in the EU and other markets must comply with stringent UN regulations like UNECE R155, which mandates certified Cybersecurity Management Systems. Automakers are legally accountable for protecting vehicles from hackers.

The robotics industry has no such binding mandate. A multi-thousand-dollar humanoid might ship with a default password and no clear mechanism for security updates—lapses that would be unthinkable in the automotive world since July 2024. Cars and robots share a similar risk profile, but vehicle cybersecurity is years ahead in regulation and practice.

The Regulatory Scramble: A Global Patchwork

As incidents mount, governments are slowly waking up to the threat. The regulatory landscape, however, is a messy and inconsistent patchwork.

United States

The U.S. has no single “Robot Law.” Instead, agencies like the FTC and CPSC apply existing consumer protection and product safety laws. NIST has released a voluntary AI Risk Management Framework, offering guidance but no enforcement. More recently, citing national security, the FCC has taken steps to ban new imports of foreign-made humanoid and quadruped robots, a move clearly aimed at Chinese manufacturers. This highlights a growing awareness of supply chain and espionage risks, but it’s a reactive measure, not a comprehensive safety framework.

European Union

The EU is, characteristically, taking a more comprehensive and proactive approach. The landmark EU AI Act, adopted in 2024, uses a risk-based model. Robots used in high-stakes environments like healthcare could be classified as “high-risk,” subjecting them to strict requirements for safety, transparency, and human oversight. The updated Machinery Regulation also forces manufacturers to address cybersecurity risks that could impact physical safety. Combined with GDPR for privacy, Europe is building a multi-layered regulatory defense for the robotic age.

China

As a nation aiming for mass production of humanoid robots by 2025, China is also moving to regulate the space. In 2023, Shanghai introduced the country’s first governance guidelines for humanoids, emphasizing the “protection of human dignity” and “assurance of human security.” While these are guidelines, not yet hard law, they signal Beijing’s intent to build public trust by addressing safety and ethics. China’s existing strict cybersecurity and data privacy laws will also apply, creating a powerful state-led governance model.

The Way Forward: Security Is Not an Optional Feature

Experts are unanimous: we are in a critical window to build a foundation of security and trust for robotics. The global service robotics market is projected to skyrocket, potentially reaching over $200 billion by 2031, meaning millions of these devices will soon be in our lives.

The path forward requires a multi-pronged effort:

  • Security by Design: Manufacturers must stop treating security as an afterthought. Encrypted communications, secure boot processes, and robust authentication should be standard, not premium features.
  • Standards and Certification: A clear certification mark—think UL for electrical safety—is needed to signal that a robot meets baseline cybersecurity standards.
  • Regulatory Clarity: Laws must hold manufacturers accountable for shipping products with egregious vulnerabilities while establishing a reasonable standard of care.
  • User Awareness: Consumers need to practice basic security hygiene, like changing default passwords and keeping firmware updated.

The warnings from cybersecurity researchers have been clear for nearly a decade. In 2017, IOActive found nearly 50 vulnerabilities across a range of popular robots. In a 2026 follow-up, they lamented that the exact same classes of vulnerabilities persist, but now the tools to exploit them are being supercharged by AI, lowering the bar for attackers.

We are building a future where robots will care for our elderly, deliver our packages, and work alongside us. If we fail to secure them, we are not just risking data; we are risking physical safety and public trust. The dystopian sci-fi future where robots turn on us won’t be because of sentient AI, but because of a buffer overflow exploit that a hacker found on a public GitHub repository. It’s up to engineers, policymakers, and consumers to ensure our robotic helpers remain just that: helpful.