Security
Can a Tesla Optimus be hacked?
What is actually on the record about hacking a Tesla Optimus, and the real, dated humanoid exploit that shows the class can be compromised.
No Optimus hack is on record, but yes, a home humanoid has been hacked: the Unitree G1 was rooted over Bluetooth in a real, disclosed 2025 exploit. Two honest halves. On Optimus specifically, Tesla has published no security disclosure, and the verified incident record holds zero incidents against it. That is an absence, not a clean bill of health. On the class, the answer is a documented yes: security researchers disclosed the 'UniPwn' Bluetooth attack on Unitree's G1 and H1 humanoids in September 2025, gaining root access over the air with a hardcoded key, wormable robot to robot. Optimus's own app code exposes a Bluetooth phone-key pairing flow, which is the same category of attack surface. Capability to be attacked is not the same as a known compromise, and we keep the two apart.
The fear behind the question is concrete: a machine with cameras and hands, in your house, taken over by someone else. On Tesla's Optimus, there is no known case. Tesla has published no security architecture for it, and the verified incident record holds nothing against it, which we report as an honest absence rather than as safety. On the wider class of home humanoids, the answer is already documented. In September 2025, researchers disclosed 'UniPwn,' a Bluetooth exploit against Unitree's G1 and H1 robots that gave root access over the air using a hardcoded shared key, and that could spread from one robot to another. Independent reporting also described Unitree units sending telemetry to servers abroad. Optimus is a different robot, but its app code exposes a Bluetooth phone-key pairing surface, the same class of entry point UniPwn abused. The honest read: no Optimus compromise is known, and the class has already been broken once in public.
Production-design Tesla Optimus climbing factory stairs, demonstrating locomotion on non-flat terrain.
What actually exists today
| What people ask about | Status | The reality |
|---|---|---|
| Does Optimus expose a Bluetooth pairing surface? | Code-hinted | Tesla iOS app code (an app-decompile artifact reported 2026-07-22, attributed to @Tesla_App_iOS) exposes the strings robot_phone_key_pairing_intro_setup_label / robot_phone_key_error_too_many_keys_on_whitelist / robot_phone_key_connected: a Bluetooth phone-key pairing flow. A code hint, not a Tesla security statement, and the same class of attack surface the Unitree UniPwn exploit abused. |
| Has a Tesla Optimus been compromised? | None on record | No known case. Tesla has published no Optimus security disclosure, and the verified incident record holds zero incidents against it. An absence, not a guarantee. |
| Has any home humanoid been hacked? | Demonstrated | Yes. The 'UniPwn' exploit against Unitree's G1 and H1 was disclosed in September 2025: root access over Bluetooth via a hardcoded shared key, wormable robot to robot. A real, dated humanoid compromise. |
| Do compromised humanoids exfiltrate data? | Reported (class) | Independent reporting described Unitree units transmitting telemetry to external servers at regular intervals. Reported for that class; not an Optimus finding. |
| Has Tesla addressed Optimus security publicly? | None verified | None verified. Tesla has not published a security model, update policy, or hardening statement for Optimus that we can cite. |
See the reviewed claim in the Tesla Optimus claims ledger → (resolved live from the registry, dated 2026-07-22).
How to read the hacking question
This question mixes a real, dated event with an honest absence, and the two get blurred together fast. Here is how to hold each piece at its true weight.
UniPwn was real
The Unitree G1 and H1 Bluetooth exploit, disclosed September 2025 by independent researchers, gave root access over the air with a hardcoded key and could spread between robots. This is verified, dated, and public.
Optimus has a Bluetooth pairing flow
Tesla app code exposes an Optimus phone-key pairing surface, attributed to the app. It is the same class of entry point UniPwn abused, which is why the class event is relevant to Optimus at all.
No known compromise
No Optimus hack is on record, and Tesla has published no security disclosure. We report that as an absence: it means nothing is known, not that nothing is possible.
Class broken, Optimus untested in public
The honest position: a home humanoid has already been hacked in public, and Optimus's security posture is undisclosed. If an Optimus compromise is ever disclosed, it becomes a dated line here.
Tesla Optimus reaching an open hand toward blocks on the sorting table during the autonomous colour-sorting demo.
What would change this
We track this question so you do not have to. Any one of these moves the answer, and each becomes a dated line on this page the week it happens:
- A security researcher discloses a real vulnerability or compromise of a Tesla Optimus.
- Tesla publishes a security architecture, update policy, or hardening statement for Optimus.
- A new humanoid exploit in the class is disclosed, the way UniPwn was for Unitree.
- A disclosed compromise would show up first as an incident. Right now the verified record holds zero safety incidents against the Tesla Optimus, and every new one is logged the week it lands.
How we know this
The class event is a real, dated security disclosure, cited as verified. The Optimus side is an honest absence, and its Bluetooth surface is a claimed app-code artifact attributed to @Tesla_App_iOS.
If an Optimus vulnerability is disclosed, or if you can show us we got something wrong, our corrections process logs the response on the record.
Common questions
Can a Tesla Optimus be hacked?
Has any humanoid robot actually been hacked?
Could a hacked home robot spy on me or exfiltrate data?
Is the Optimus Bluetooth pairing surface confirmed by Tesla?
Keep reading
Track this
Find out the instant Optimus security is tested.
Watch this question and we will tell you the moment a researcher discloses an Optimus vulnerability, Tesla publishes a security model, or a new humanoid exploit lands in the class. No robot required.
Canonical URL: /home-robots/optimus-can-be-hacked · machine-readable mirror: /home-robots/optimus-can-be-hacked.md