Unitree Robot Dogs Have Real Flaws—but the Five-Minute Claim Is Miscast

Unitree robot dogs have documented security problems, but the claim that every model sends camera, microphone and location data to China every five minutes remains unsupported. The recurring interval comes from a September 2025 assessment of a Unitree G1 humanoid, which identified multimodal sensor and service-state telemetry sent to external endpoints every 300 seconds.
The material development since the original controversy is a more precise account of which products and software versions are affected by a separate flaw. The CVE-2025-35027 record, last modified on June 17, 2026, lists Go2 and B2 firmware through version 1.1.8 and G1 and H1 firmware through version 1.4.4. These findings justify concern, but they do not combine into evidence of an unstoppable surveillance system installed across every Unitree robot.
The five-minute observation belongs to the G1
The tested G1 periodically connected to two external endpoints without operator notice. The researchers characterized the traffic as multimodal sensor and service-state telemetry after partially reverse-engineering Unitree’s proprietary FMX encryption.
This is evidence about the G1 unit and software configuration examined in that work. The G1 is a humanoid, while the Go1, Go2 and B2 are quadrupeds; transferring the result between those product lines would change the subject of the experiment. Publicly available material does not establish that every Unitree model runs the same telemetry process, uses the same interval or transmits identical data.
The experiment also does not support several more dramatic allegations associated with the robot-dog story. It does not demonstrate that a stationary Go2 uploaded 1.8 GB in one day, that quadrupeds formed a data-relay mesh, or that a powered-off unit repeatedly woke to continue surveillance. Model-specific packet captures and reproducible firmware analysis would be needed to substantiate those claims.
The Go1 tunnel issue was a different incident
The older Go1 had a separate problem involving a remote tunnel service. Unitree’s current Go1 download page provides a removal patch and states that it completely removes tunnel services for greater security. The patch has defined Go1 hardware, firmware and Sport Mode dependencies, so it is not evidence about every quadruped or humanoid in the company’s range.
That official patch confirms that a tunnel component existed and that Unitree supplied a way to remove it. It does not prove that the manufacturer deliberately used the service to monitor customers, nor does it establish that the same pathway remains active on newer models.
The distinctions are important. A remotely accessible service can create a serious vulnerability even when there is no demonstrated abuse, but the presence of a vulnerability, successful exploitation by a third party and intentional manufacturer surveillance are separate propositions. Evidence for one should not be treated as proof of the others.
The multi-model flaw involves BLE and Wi-Fi provisioning
CVE-2025-35027 concerns command injection rather than recurring telemetry or the Go1 tunnel. A malicious string entered while configuring onboard Wi-Fi through Bluetooth Low Energy can reach the robot’s shell when the Wi-Fi service restarts, causing commands to execute as root.
The affected products cross both body types: Go2 and B2 are quadrupeds, while G1 and H1 are humanoids. That shared vulnerability explains why multiple Unitree models appear in the same security record, but it does not mean every finding made on one model automatically applies to the others.
The published attack vector requires adjacent-network access and low privileges, with no user interaction. It does not establish remote compromise from anywhere on the internet, operation after the robot has been powered down, or a demonstrated self-propagating infection passing automatically between nearby units. Those are additional claims requiring separate evidence.
What owners can determine from the evidence
The practical risk depends on the model, installed firmware and network exposure. Owners of a Go2 or B2 can compare the installed version with the affected range for the command-injection flaw. Being outside that range reduces exposure to this specific vulnerability, but it is not a general security guarantee.
In laboratories, warehouses and other sensitive environments, placing the robot on a dedicated network segment limits what a compromise can reach. Outbound logs can reveal which destinations the robot contacts, connection frequency and traffic volume without assuming that every encrypted session carries video or audio.
If cloud control is unnecessary, blocking internet access at the network boundary can establish whether required local functions continue to operate. Restricting Bluetooth during provisioning, replacing default credentials where the product permits it and retaining logs around firmware changes address identifiable access paths without pretending to remove unknown ones.
Prospective buyers should seek a model-specific data-flow description, supported firmware versions, an update policy and a list of cloud dependencies. The verified record supports scrutiny of Unitree’s security engineering, but not the blanket assertion that every Chinese robot dog irreversibly transmits a living-room feed every five minutes. What is established is narrower: periodic telemetry observed on one G1 humanoid, a removable tunnel service on the older Go1, and a command-injection vulnerability affecting defined versions of four models.
Also read:
Subscribe to our newsletter
Get the latest Web3, AI, and crypto news delivered straight to your inbox.