Skip to content
SUNDAY, AUGUST 2, 2026
Consumer TechLegacy Report1 recorded source

DJI Pays $30K After Romo Vacuum Hack Exposed 7,000 Devices

Visual status: no verified article image is available. The reporting remains text-first.

A hacker unlocked 7,000 Romo vacuums, and DJI paid up.

In a striking reminder that “smart” can mean exposed, a security researcher demonstrated that thousands of DJI Romo robot vacuums could be steered remotely—and even used to peek into people’s homes. The Verge reports that Sammy Azdoufal showed how a PlayStation gamepad could control the devices, revealing a sprawling network of 7,000 remote-controlled robovacs that could potentially expose video feeds and other sensitive data. DJI acknowledged the issue and has begun addressing related vulnerabilities, and the company confirmed it would compensate the researcher with a $30,000 payout as part of its disclosure process. The details underscore a growing tension in consumer IoT: convenience often amplifies attack surfaces.

What happened, in plain terms, is that a vulnerability in Romo vacuums allowed attackers who could reach the devices to take control and, in some scenarios, access the devices’ video streams. The researcher’s test highlighted a reality many households live with—our cleaning robots aren’t just cleaners; they’re networked devices with cameras, app controls, and cloud links that can become entry points for intruders if not properly secured. DJI says it began addressing some of these vulnerabilities even before the disclosure, but the existence of a 7,000-device network on the surface paints a sobering picture of scale.

For consumers, the takeaway is twofold. First, the risk isn’t just about one botched firmware update; it’s about how many devices in a modern home can be accessed remotely if a single flaw exists. A network of Romo vacuums implies that a vulnerability isn’t isolated to a single address or account. Second, the way companies handle bug disclosures matters. DJI’s $30,000 bounty signals an intent to reward researchers and close gaps, but it also raises questions about patch timelines, accountability, and how quickly affected users will see fixes deployed across all affected units.

From a practitioner’s perspective, this incident illustrates several concrete realities about consumer robotics and IoT security. One, the attack surface for floor-cleaning robots is expanding as devices gain remote-control features and cameras. Two, patch velocity matters more than ever: even a well-intentioned vendor can lag behind threats if firmware updates aren’t rolled out broadly and quickly. Three, bug-bounty incentives help bring attention to flaws, but researchers and users alike need clear timelines and transparent disclosure practices. Four, households should consider basic mitigations—keep devices updated, disable unnecessary remote access when not needed, and segment IoT gear on guest networks to limit blast radius if a device is compromised.

In the broader market, this episode adds to a growing body of evidence that security must be baked into everyday gadgets, not bolted on as an afterthought. As robots and cameras proliferate in homes, manufacturers will need robust vulnerability-disclosure programs, faster update mechanisms, and safer default configurations. For buyers, the prudent move is to treat these devices as potential access points and to demand clear, timely firmware patches and straightforward privacy controls from vendors.

Bottom line: this isn’t just a quirky bug—it’s a warning about how many connected devices share a single home’s security perimeter. DJI’s payout is a keystone detail, but what matters most is how quickly the Romo line—and others like it—become demonstrably safer for real homes.

Sources & methodology
  1. DJI will pay $30K to the man who accidentally hacked 7,000 Romo robovacs
    theverge.com / Source role not classified / Published MAR 06, 2026 / Accessed MAR 07, 2026

Newsletter

The Robotics Briefing

New signups are closed while external email delivery is being verified. No email address is collected here.

Follow the live RSS feeds