Skip to content
SUNDAY, AUGUST 2, 2026
Consumer TechLegacy Report1 recorded source

DJI Pays $30K for Romo Vacuum Hack

Visual status: no verified article image is available. The reporting remains text-first.

A PlayStation gamepad unlocked a door into 7,000 Romo vacuum robots, letting a researcher peek into strangers’ homes.

DJI’s Romo line became the center of a public security scare and a bug-bounty win this week: the company disclosed it would pay $30,000 to a researcher who demonstrated that a single exploit could commandeer thousands of home vacuums. The researcher, Sammy Azdoufal, showed how a PlayStation controller could steer the fleet and, more chillingly, reveal how easily a connected device could turn into a privacy breach if other safeguards aren’t in place. The Verge’s reporting makes clear that the episode wasn’t merely about a one-off hack; it exposed a sprawling network of remote-control devices that could, in theory, allow a curious or malicious actor to peek into private spaces.

In DJI’s account, the pay was part of a broader vulnerability-disclosure effort designed to reward responsible researchers who surface weaknesses before they’re weaponized. The company said it had already begun addressing related vulnerabilities even before Azdoufal demonstrated the scope of access. The situation, however, underscores a stubborn tension in consumer robotics: the more capable a device becomes—moving from a simple vacuum to a connected sensor array that shares space with cameras and microphones—the more potential entry points exist for bad actors. The Romo episode isn’t a radical anomaly; it’s a vivid reminder that billions in connected devices can create a wide attack surface when security isn't baked in from the start.

The Verge notes that DJI’s decision to acknowledge and reward the findings comes amid scrutiny over how the company has handled disclosures in the past, including a widely cited 2017 episode involving a different security researcher. That history matters because it shapes how quickly users can expect patches to land and how transparent manufacturers are about what remains at risk. In practical terms, this incident shows that even carefully engineered “Smart Home 2.0” products require ongoing, sometimes costly, security work—work that lands on the user as software updates and on the company as bug-bounty administration and faster firmware rollouts.

From a consumer-technology standpoint, the episode amplifies several hard truths that practitioners and homeowners are weighing right now. First, patch latency matters. An OTA update that takes weeks or months to reach a large installed base can leave households vulnerable long after a flaw is disclosed. Second, the economics of bug bounties are nuanced. A $30,000 payout signals serious risk but also invites questions about scale and severity—how much should a vulnerability be valued when it could expose intimate privacy across thousands of homes? Third, the patch path for home robots isn’t purely software; it’s hardware-bound in many cases. A vulnerability that requires hardware-level changes or more invasive firmware could slow mitigations and force reliance on users to adopt timely updates or, worse, leave devices semi-exposed if they aren’t enrolled in automatic updates.

For practitioners, a few concrete takeaways emerge. One, security-by-design must be non-negotiable in product roadmaps that blend physical and digital spaces; the added convenience of remote access should never outpace privacy protections. Two, manufacturers should pair bug-bounty programs with transparent disclosure timelines and clear user-facing remediation steps, so households know when to expect fixes. Three, network hygiene matters: segmenting IoT devices from primary networks can limit exposure if a device is compromised. Four, future product cycles should anticipate a world of dense, multi-vendor ecosystems, where a vulnerability in one device can ripple across a home’s digital perimeter.

This episode isn’t just about a payout or a hack; it’s a case study in how the consumer robotics market is maturing. The industry is learning to reward careful researchers, patch faster, and communicate risk without fanning panic. Whether Romo-like vulnerabilities are the exception or the rule remains to be seen, but the takeaway is clear: everyday robots will clean rooms and, increasingly, guard privacy—if manufacturers design and defend them that way.

Sources & methodology
  1. DJI will pay $30K to the man who accidentally hacked 7,000 Romo robovacs
    theverge.com / Source role not classified / Published MAR 06, 2026 / Accessed MAR 07, 2026

Newsletter

The Robotics Briefing

New signups are closed while external email delivery is being verified. No email address is collected here.

Follow the live RSS feeds