DJI Robot Vacuum Security Flaw Exposed Thousands of Homes to Remote Access
San Francisco, CA – A hobby coder’s attempt to control his robot vacuum with a PlayStation 5 controller inadvertently revealed a significant security vulnerability in DJI’s Romo robot vacuum, granting him access to live camera feeds, microphones, and floor plans from approximately 7,000 devices across 24 countries. The incident, which unfolded in February 2026, highlights the growing security risks associated with the proliferation of internet-connected devices and the potential for even amateur hackers to exploit vulnerabilities in the Internet of Things (IoT).
Sammy Azdoufal, the coder responsible for the discovery, initially sought to reverse-engineer the communication protocols of his newly purchased DJI Romo vacuum using Anthropic’s Claude Code AI coding assistant. His intention was simply to gain manual control of the device. However, the process unexpectedly connected his custom application to DJI’s servers, unlocking access to a vast network of Romo vacuums. Azdoufal was able to pinpoint the location of a journalist’s device, confirm its battery level, and generate a map of their home – all without their knowledge or consent. The vulnerability stemmed from a lack of topic-level access controls on DJI’s MQTT message broker, allowing authenticated users to view traffic from other devices in plaintext. Malwarebytes reported that this meant anyone with a device token could potentially access data from thousands of other connected devices.
How the Breach Occurred: A Breakdown of the Vulnerability
The core issue lay in DJI’s backend permission validation. Azdoufal discovered that once authenticated with a single device token, he could access data streams from numerous other Romo vacuums. This lack of granular access control meant that the system didn’t differentiate between legitimate requests from a user’s own device and unauthorized access attempts. The MQTT infrastructure, commonly used in IoT devices for messaging, lacked the necessary security layers to prevent this widespread exposure. MSN reported that the flaw allowed unauthorized users to potentially control the devices as well as access homeowner cameras.
The situation was further complicated by the fact that DJI’s Power portable battery stations, which also utilize the same MQTT infrastructure, were also vulnerable. These battery stations, capable of expanding to 22.5kWh, are designed to provide backup power during outages, adding another layer of potential risk. The ability to access these devices could have allowed malicious actors to disrupt power supplies or gather information about energy consumption patterns.
AI Coding Assistants Lowering the Barrier to Entry
What sets this incident apart is the role of AI coding tools in facilitating the discovery. Azdoufal leveraged Anthropic’s Claude Code to decompile DJI’s mobile app, understand its communication protocol, and extract his authentication token. This demonstrates how AI-powered coding assistants are lowering the technical barrier to entry for security research – and, unfortunately, for malicious actors as well. The population capable of probing IoT protocols is expanding rapidly, eroding the security benefits of obscurity. As Malwarebytes noted, this incident underscores a growing concern: the ease with which advanced offensive security techniques are becoming accessible.
DJI’s Response and Mitigation
DJI acknowledged the vulnerability and released two patches on February 8 and 10, 2026, to address the issue. The company issued a statement confirming the backend permission validation problem and outlining the steps taken to secure its devices. However, the incident raises broader questions about the security practices of IoT manufacturers and the need for more robust security measures in connected devices. The fact that a hobbyist was able to uncover such a significant flaw highlights the importance of proactive security testing and vulnerability management.
The Wider Implications for IoT Security
This breach isn’t an isolated incident. Robot vacuum cleaners have been targeted by hackers before, demonstrating a consistent vulnerability in the IoT landscape. The ease with which Azdoufal gained access to thousands of devices underscores the potential for these devices to be turned into surveillance tools, collecting sensitive data about homeowners without their knowledge or consent. The incident serves as a stark reminder that convenience and connectivity come with inherent security risks.
The lack of robust security protocols in many IoT devices is a growing concern for cybersecurity experts. Many manufacturers prioritize speed to market over security, leaving devices vulnerable to exploitation. This incident is likely to fuel calls for stricter regulations and industry standards to ensure the security of connected devices. Consumers are increasingly reliant on IoT devices for everyday tasks, making it crucial to address these vulnerabilities before they can be exploited on a larger scale.
What This Means for Consumers
For consumers, this incident highlights the importance of being aware of the potential security risks associated with IoT devices. While it’s not always possible to prevent these vulnerabilities, there are steps you can take to mitigate the risks:
- Keep your devices updated: Regularly install firmware updates to patch security vulnerabilities.
- Change default passwords: Use strong, unique passwords for all your IoT devices.
- Review privacy settings: Understand what data your devices are collecting and how it’s being used.
- Consider network segmentation: Isolate your IoT devices on a separate network to limit the potential impact of a breach.
- Research brands: Before purchasing an IoT device, research the manufacturer’s security track record.
Looking Ahead: The Future of IoT Security
The DJI Romo incident is a wake-up call for the IoT industry. As the number of connected devices continues to grow, the potential for security breaches will only increase. Manufacturers need to prioritize security from the outset, implementing robust security measures and conducting thorough vulnerability testing. AI-powered security tools will likely play an increasingly important role in identifying and mitigating these risks. Greater collaboration between manufacturers, security researchers, and regulators is essential to ensure a more secure IoT ecosystem.
DJI has not yet announced any plans for compensating affected users, but the company is reportedly investigating the incident further. The full extent of the data compromised remains unclear, and it is likely to take time to assess the impact of this breach. The incident serves as a potent reminder that the security of our connected homes is only as strong as the weakest link in the chain.
The next update from DJI regarding the investigation and potential remediation efforts is expected by March 15, 2026. We encourage readers to share their thoughts and experiences with IoT security in the comments below.
Related reading