Drooid Logo
Back to story perspectives

Full Breakdown

Security Flaw Exposes Thousands of DJI Romo Robot Vacuums to Unauthorized Access

2/25/2026, 12:12:55 AM

Accidental Discovery of a Major Vulnerability

A significant security flaw in the DJI Romo robot vacuum has come to light after Sammy Azdoufal, an AI strategist, unintentionally gained control over approximately 6,700 devices worldwide while attempting to modify his own vacuum to work with a PlayStation controller. This vulnerability allowed Azdoufal to access sensitive information, including live camera feeds, microphone audio, and detailed floor plans from homes across 24 countries. The flaw was discovered when Azdoufal used an AI coding assistant, Claude Code, to reverse-engineer the communication protocol between his vacuum and DJI's remote servers.

How the Breach Occurred

While developing a remote-control app for his DJI Romo, Azdoufal extracted a private token from his device. Instead of limiting access to his vacuum, the server mistakenly treated him as the owner of nearly 7,000 other vacuums, granting him extensive control over their functionalities. Azdoufal reported that he could compile 2D floor plans and access real-time data, including the vacuums' locations and operational statuses. He emphasized that his actions did not involve hacking in the traditional sense, stating, “I didn’t infringe any rules, I didn’t bypass, I didn’t crack, brute force, whatever.”

DJI's Response and Resolution

Upon discovering the vulnerability, Azdoufal responsibly reported it to DJI, which subsequently implemented several updates to address the issue. The company confirmed that the vulnerability was resolved through two updates deployed on February 8 and February 10, 2026, requiring no action from users. DJI stated, “The issue was addressed through internal review,” and plans to continue enhancing security measures. However, Azdoufal noted that additional concerns remain, including the ability to stream video feeds without a security PIN and other undisclosed issues.

Implications for Smart Home Security

This incident raises significant concerns regarding the security of Internet of Things (IoT) devices, particularly robot vacuums. As more households adopt smart devices, the potential for unauthorized access to personal data increases. Security researchers warn that if an ordinary user can stumble upon such vulnerabilities, a coordinated attack could lead to far more severe consequences. The DJI Romo incident serves as a reminder of the risks associated with smart home technology, which often operates in private spaces and can be susceptible to exploitation.

Criticism and Broader Concerns

The incident has sparked discussions about the surveillance capabilities of smart home devices. Critics argue that the design of these devices often prioritizes functionality over security, leaving users vulnerable. Additionally, there are ongoing concerns regarding data privacy, especially with companies like DJI facing scrutiny over their security practices. The incident echoes previous controversies involving smart devices, such as the misuse of data by gig workers monitoring Roomba vacuums, highlighting the need for stricter regulations and better security protocols in the IoT sector.

Verbatim Quotes

  • “I found my device was just one in an ocean of devices,” — Sammy Azdoufal, AI Strategist

This incident underscores the importance of robust security measures for IoT devices, as the integration of technology into everyday life continues to expand.