DJI Pays $30K for Romo Vacuum Flaw, Begins System-wide Fix

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- DJI agreed to pay $30,000 to security researcher Sammy Azdoufal for a discovery related to its Romo robot vacuums, as confirmed in an email shared with The Verge.
- DJI said it had already addressed a vulnerability that allowed viewing a Romo video stream without a security PIN, with the fix completed by late February.
- DJI announced it is upgrading the entire Romo system to fix another vulnerability, expecting full implementation within one month.
- DJI published a blog post stating that it discovered the original issue itself while also crediting two independent security researchers for finding the same problem.
- DJI highlighted that the Romo has ETSI, EU, and UL security certifications, and pledged ongoing third‑party security audits and deeper engagement with the research community.
Why it matters: The payout incentivizes security researchers to report flaws, while DJI’s rapid patching restores confidence in its Romo line and mitigates privacy risks for owners of the 7,000 affected vacuums. It also signals DJI’s commitment to engage with the research community, potentially reducing future exposure and reinforcing the value of bug‑bounty programs.



