DJI patches security flaw exposing 7,000 Romo vacuums

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- Sammy Azdoufal used an AI coding assistant to reverse‑engineer the DJI Romo’s cloud communication while building a joystick controller, discovering his token also granted access to other devices.
- DJI’s backend mistakenly treated the token as valid for an entire fleet, allowing Azdoufal to view live camera feeds, microphone audio, floor‑plan maps and approximate locations of nearly 7,000 Romo vacuums in 24 countries.
- DJI identified the vulnerability in an internal review in late January and deployed two automatic updates—first on February 8, then on February 10—to patch the flaw without requiring user action.
- The Verge was alerted by Azdoufal and reported the issue, prompting DJI to confirm the fix to Popular Science and to pledge further security enhancements.
- Smart‑home experts have warned that internet‑connected robots like the Romo are attractive targets for hackers, and the incident underscores broader privacy concerns as more households adopt devices with cameras and microphones.
- US lawmakers have long cited Chinese‑made tech such as DJI as potential security threats, a narrative that has helped justify bans on certain products despite “murky” evidence.
Why it matters: The patch prevents hackers from turning thousands of DJI Romo vacuums into covert surveillance devices, protecting the privacy of owners in 24 countries; meanwhile, DJI’s quick response aims to restore trust but highlights the broader risk of insecure smart‑home robots.



