Drooid Logo
Back to story perspectives

Full Breakdown

Security Flaw Exposes 7,000 Robot Vacuums to Remote Control

2/27/2026, 9:17:49 AM

Overview of the Incident

A significant security vulnerability was uncovered when Spanish software engineer Sammy Azdoufal inadvertently gained control of approximately 7,000 DJI Romo robot vacuums across 24 countries. This incident arose during his attempt to reverse-engineer his vacuum cleaner to operate with a PlayStation 5 controller. Instead of just accessing his device, Azdoufal's actions allowed him to connect to a vast network of vacuums, enabling him to view live camera feeds, listen through microphones, and map home layouts.

How the Breach Occurred

Azdoufal's DIY project involved creating a remote control application that communicated with DJI's servers. He discovered that the credentials for his vacuum granted him access to thousands of others, effectively acting as a "master key." This flaw not only exposed live feeds and audio but also provided Azdoufal with the ability to track the devices' locations via their IP addresses. He reported his findings to The Verge, which subsequently alerted DJI.

Company Response and Fixes

DJI confirmed the security flaw and stated that it had been addressed through software updates deployed on February 8 and February 10, 2026. A company spokesperson emphasized their commitment to data privacy and security, noting that they would continue to enhance their security measures. However, Azdoufal expressed concerns that the overall security of smart devices remains inadequate, suggesting that manufacturers need to prioritize security in their design processes.

Broader Implications for Smart Devices

The incident highlights a growing concern regarding the security of smart home products. Cybersecurity experts, including Alan Woodward from the University of Surrey, noted that many manufacturers treat security as an afterthought, prioritizing rapid innovation over robust protection. The smart home market is projected to reach $139 billion by 2032, raising questions about the potential vulnerabilities that accompany such widespread adoption of connected devices.

Criticism and Concerns

Critics argue that the incident underscores a systemic issue within the smart device industry, where convenience often overshadows security. Previous incidents, such as the hijacking of Ecovacs vacuums that emitted racial slurs, illustrate the potential for misuse of these technologies. Experts recommend that manufacturers enforce stronger security protocols, such as requiring users to set unique passwords upon initial device setup.

Verbatim Quotes

  • “I found my device was just one in an ocean of devices,” — Sammy Azdoufal, Software Engineer
  • “DJI can confirm the issue was resolved last week and remediation was already underway prior to public disclosure,” — Daisy Kong, DJI Spokesperson
  • “Just because you can doesn’t mean you should,” — Alan Woodward, Professor of Computer Science

Conclusion

The accidental hijacking of 7,000 robot vacuums by Sammy Azdoufal serves as a stark reminder of the vulnerabilities inherent in the rapidly expanding smart home market. While DJI has addressed the immediate security flaw, the incident raises critical questions about the long-term security of connected devices and the responsibilities of manufacturers to protect consumer privacy.