RobotRisk Autonomous Systems Incident & Risk Register
RobotRisk / Ecovacs / 2024-05

Hacked Ecovacs Deebot X2 vacuums shout racial slurs, chase pet in multiple US cities

S2 · 05/2024 · Ecovacs

Record

CompanyEcovacs
Categoryconsumer robotics
Typecyber
Date05/2024
Time of daynot documented
Locationno physical site (recall / fleet-wide / aggregate record)
SeverityS2 (minor injury or single-unit damage)
Scaleat least 2 households across multiple cities
Confidencehigh
VerificationCited source on file; not independently re-verified
SourceTom's Guide

What happened

Exploiting a known Bluetooth/PIN vulnerability, an attacker remotely took over Deebot X2 vacuums in at least two US cities; in Minnesota a hacked unit broadcast racial slurs near a child and accessed the live camera feed, and in Los Angeles a hacked unit chased a family dog while emitting offensive audio.

Ecovacs record context

Entries by year and severity

122024 S2: 22242025 S1: 1125
S1S2S3S4S5

By incident type

By severity

Ecovacs vs consumer robotics alternatives

consumer robotics context

consumer robotics: entries by year

252018 S1: 11182020 S3: 11202021 S1: 11212022 S3: 11222023 S3: 22232024 S2: 22024 S4: 13242025 S1: 12025 S2: 23252026 S2: 12026 S3: 12026 S4: 12026 S5: 2526
S1S2S3S4S5

consumer robotics: failure modes

consumer robotics: most entries

cyber context

cyber: by category

cyber: by year

cyber: severity profile

Comparable cyber events in consumer robotics

SevDateCompanyEvent
S52026-07-13SharkNinjaShark robot vacuum flaw allows remote code execution via stolen certificate
S22026-05YarboSecurity vulnerability exposed in ~6,000 Yarbo robot lawn mowers
S22025-09-02Dreame TechnologySecurity flaws found in Dreame (and Ecovacs) robot vacuums with cameras
S12025-05EcovacsCISA advisory: Ecovacs Deebot base stations accept unvalidated firmware updates, deterministic WiFi key
S22024-08EcovacsResearchers demonstrate Bluetooth/PIN flaw letting attackers hijack Ecovacs Deebot cameras and mics
S12021-09-15RoborockRoborock discloses insecure random-number generator flaw in Tuya IoT cloud connection
S12018-05-29SoftBank RoboticsSecurity researchers find Pepper robot lacks basic authentication/security controls

Other Ecovacs entries

Also from Critical Systems Analysis: CSA - functional safety engineering · Company directory · FSTalent - functional safety jobs