DEPLOYDatabase

Security

Can a Tesla Optimus be hacked?

What is actually on the record about hacking a Tesla Optimus, and the real, dated humanoid exploit that shows the class can be compromised.

Not on the Optimus record, proven for the class

No Optimus hack is on record, but yes, a home humanoid has been hacked: the Unitree G1 was rooted over Bluetooth in a real, disclosed 2025 exploit. Two honest halves. On Optimus specifically, Tesla has published no security disclosure, and the verified incident record holds zero incidents against it. That is an absence, not a clean bill of health. On the class, the answer is a documented yes: security researchers disclosed the 'UniPwn' Bluetooth attack on Unitree's G1 and H1 humanoids in September 2025, gaining root access over the air with a hardcoded key, wormable robot to robot. Optimus's own app code exposes a Bluetooth phone-key pairing flow, which is the same category of attack surface. Capability to be attacked is not the same as a known compromise, and we keep the two apart.

Last verified Jul 22, 20265 sources

Find out instantly when the record moves. Unsubscribe anytime.

The fear behind the question is concrete: a machine with cameras and hands, in your house, taken over by someone else. On Tesla's Optimus, there is no known case. Tesla has published no security architecture for it, and the verified incident record holds nothing against it, which we report as an honest absence rather than as safety. On the wider class of home humanoids, the answer is already documented. In September 2025, researchers disclosed 'UniPwn,' a Bluetooth exploit against Unitree's G1 and H1 robots that gave root access over the air using a hardcoded shared key, and that could spread from one robot to another. Independent reporting also described Unitree units sending telemetry to servers abroad. Optimus is a different robot, but its app code exposes a Bluetooth phone-key pairing surface, the same class of entry point UniPwn abused. The honest read: no Optimus compromise is known, and the class has already been broken once in public.

Courtesy of Tesla, Inc.

Production-design Tesla Optimus climbing factory stairs, demonstrating locomotion on non-flat terrain.

What actually exists today

Hacking a home humanoid, by status
What people ask aboutStatusThe reality
Does Optimus expose a Bluetooth pairing surface?Code-hintedTesla iOS app code (an app-decompile artifact reported 2026-07-22, attributed to @Tesla_App_iOS) exposes the strings robot_phone_key_pairing_intro_setup_label / robot_phone_key_error_too_many_keys_on_whitelist / robot_phone_key_connected: a Bluetooth phone-key pairing flow. A code hint, not a Tesla security statement, and the same class of attack surface the Unitree UniPwn exploit abused.
Has a Tesla Optimus been compromised?None on recordNo known case. Tesla has published no Optimus security disclosure, and the verified incident record holds zero incidents against it. An absence, not a guarantee.
Has any home humanoid been hacked?DemonstratedYes. The 'UniPwn' exploit against Unitree's G1 and H1 was disclosed in September 2025: root access over Bluetooth via a hardcoded shared key, wormable robot to robot. A real, dated humanoid compromise.
Do compromised humanoids exfiltrate data?Reported (class)Independent reporting described Unitree units transmitting telemetry to external servers at regular intervals. Reported for that class; not an Optimus finding.
Has Tesla addressed Optimus security publicly?None verifiedNone verified. Tesla has not published a security model, update policy, or hardening statement for Optimus that we can cite.
Verified: on the recordCode-hinted: an attributed signal, not a Tesla policyNone on record: no answer or case exists yet

See the reviewed claim in the Tesla Optimus claims ledger (resolved live from the registry, dated 2026-07-22).

How to read the hacking question

This question mixes a real, dated event with an honest absence, and the two get blurred together fast. Here is how to hold each piece at its true weight.

The class event

UniPwn was real

The Unitree G1 and H1 Bluetooth exploit, disclosed September 2025 by independent researchers, gave root access over the air with a hardcoded key and could spread between robots. This is verified, dated, and public.

The shared surface

Optimus has a Bluetooth pairing flow

Tesla app code exposes an Optimus phone-key pairing surface, attributed to the app. It is the same class of entry point UniPwn abused, which is why the class event is relevant to Optimus at all.

The Optimus absence

No known compromise

No Optimus hack is on record, and Tesla has published no security disclosure. We report that as an absence: it means nothing is known, not that nothing is possible.

Where it stands

Class broken, Optimus untested in public

The honest position: a home humanoid has already been hacked in public, and Optimus's security posture is undisclosed. If an Optimus compromise is ever disclosed, it becomes a dated line here.

Courtesy of Tesla, Inc.

Tesla Optimus reaching an open hand toward blocks on the sorting table during the autonomous colour-sorting demo.

What would change this

We track this question so you do not have to. Any one of these moves the answer, and each becomes a dated line on this page the week it happens:

  • A security researcher discloses a real vulnerability or compromise of a Tesla Optimus.
  • Tesla publishes a security architecture, update policy, or hardening statement for Optimus.
  • A new humanoid exploit in the class is disclosed, the way UniPwn was for Unitree.
  • A disclosed compromise would show up first as an incident. Right now the verified record holds zero safety incidents against the Tesla Optimus, and every new one is logged the week it lands.
How we know this

The class event is a real, dated security disclosure, cited as verified. The Optimus side is an honest absence, and its Bluetooth surface is a claimed app-code artifact attributed to @Tesla_App_iOS.

Help Net Security: Unitree G1/H1 'UniPwn' Bluetooth exploitIEEE Spectrum: security researchers root a humanoid over BluetoothUniPwn coordinated disclosure (Andreas Markis, Kevin Finisterre)Tesla Optimus: the verified registry record (0 incidents, sources)DEPLOY verified incident record

If an Optimus vulnerability is disclosed, or if you can show us we got something wrong, our corrections process logs the response on the record.

Common questions

Can a Tesla Optimus be hacked?
No Optimus hack is on record, and Tesla has published no security disclosure, so we report that as an honest absence. But the class is provably hackable: researchers disclosed the 'UniPwn' Bluetooth exploit against Unitree's G1 and H1 humanoids in September 2025, gaining root access over the air. Optimus exposes a Bluetooth pairing surface of the same class.
Has any humanoid robot actually been hacked?
Yes. The Unitree G1 and H1 were compromised via 'UniPwn,' a Bluetooth exploit disclosed in September 2025 that gave root access using a hardcoded shared key and could spread from robot to robot. It is a real, dated, public humanoid compromise.
Could a hacked home robot spy on me or exfiltrate data?
For the Unitree class, independent reporting described units transmitting telemetry to external servers at regular intervals, and root access would expose cameras and microphones. There is no such finding for Optimus; its security posture is simply undisclosed.
Is the Optimus Bluetooth pairing surface confirmed by Tesla?
No. It comes from strings in a decompile of the Tesla iOS app, attributed to @Tesla_App_iOS. We label it claimed. It matters here because Bluetooth pairing is exactly the class of entry point the Unitree UniPwn exploit abused.

Keep reading

What does a Tesla Optimus record in your home?Undisclosed What is captured and kept.Can a Tesla Optimus watch and record you?Undisclosed The always-on question.Is a Tesla Optimus safe? The verified recordThe verified record Every logged incident.Tesla Optimus: the full registry recordThe record Sources, maturity, and 0 incidents, verified vs claimed.Tesla Optimus claims ledgerThe ledger The Bluetooth phone-key strings, dated.Is there insurance for a Tesla Optimus?No product exists yet Insurance & liabilityDoes homeowners insurance cover a home robot?Untested Insurance & liabilityDoes renters insurance cover a home robot?Untested Insurance & liabilityWho's liable if your Optimus injures someone or damages your home?Unsettled Insurance & liabilityWhat insurance exists for business and warehouse robots?Yes, for businesses Insurance & liabilityWhat does a Cybercab record while you're in it?Undisclosed Rider privacyDoes a Tesla Optimus train on your home data?Claimed, not confirmed Data & privacyOptimus or Figure 03: which home robot is more private?Too little disclosed to crown one ComparisonDoes a Tesla Optimus have a privacy policy?No policy published Data & privacyWho can see through a Tesla Optimus?Undisclosed for Optimus, proven for the class Access & teleoperationIs a human watching through a Tesla Optimus?Verified at a demo, undisclosed for the home Access & teleoperationIs it legal for a home robot to record your guests?The law is real, compliance is undisclosed Bystanders & consentCan a home robot record your children?Stricter law is real, compliance is undisclosed Bystanders & consentIs a home robot creepier than Alexa or Ring?Optimus undisclosed; the precedents are real ComparisonDoes a Tesla Optimus have cameras and microphones?Cameras confirmed, mics undisclosed Data & privacyDoes a Tesla Optimus map your home?Undisclosed Data & privacyDoes a Tesla Optimus send your video to Tesla?Undisclosed for Optimus, proven for the class Data & privacyCan you turn off a Tesla Optimus camera?No off-switch on the record Data & privacyCan you delete your Tesla Optimus data?The right exists in law, no Optimus mechanism does Data & privacyDoes a Tesla Optimus ask before it collects data?A consent surface is code-hinted, not confirmed Data & privacyWhat does a Tesla Optimus know about you?Undisclosed, with claimed app signals Data & privacy

Track this

Find out the instant Optimus security is tested.

Watch this question and we will tell you the moment a researcher discloses an Optimus vulnerability, Tesla publishes a security model, or a new humanoid exploit lands in the class. No robot required.

Find out instantly when the record moves. Unsubscribe anytime.

Canonical URL: /home-robots/optimus-can-be-hacked · machine-readable mirror: /home-robots/optimus-can-be-hacked.md