When Code Bugs Become Physical Harm: Embodied AI's Perilous Leap
In April 2026, a security test demonstration left a deep impression on the audience: a commercial quadruped robot was hijacked through non-contact network means, silently switched on its camera to collect and transmit data back, and then suddenly attacked a dummy model.
Zhou Hongyi, founder of 360 Group, said the essence of embodied AI security is converting "code vulnerabilities" into "physical destructive power," upgrading the nature of the problem from "data security" to "production safety" and "safety of life."
That assessment is being validated in practice. In April 2026, independent security research institute DARKNAVY released its White Paper on Embodied AI Security Technology.
The figures it disclosed are striking: breaking into a flagship smartphone takes a professional team months, and penetrating a smart car takes even longer — yet for a well-known brand's commercially available embodied AI robot, the full cycle from vulnerability identification to complete remote compromise took under eight hours.
The white paper notes that mainstream domestic robots have not yet reached the basic protection level of early smart terminals or IoT devices. Some quadruped robots ship with fixed, unchangeable hotspot passwords, so any passerby can connect a phone and seize control; others have flawed cloud permission management, letting attackers remotely view camera feeds of any connected device — or even manipulate robotic arms into dangerous motions.
In September, a more serious problem surfaced. Researchers found a vulnerability chain dubbed "UniBLEed" in Unitree's G1 humanoid robot, letting an attacker within Bluetooth range take full control and gain root access to the motion-control computer, controlling its movement, camera, speaker and voice functions. The team reproduced the attacks on four G1 robots and warned the flaw may be "wormable," with an infected robot attacking other robots within Bluetooth range.
Security investment, meanwhile, shows a blank on the books. iResearch puts the global embodied AI market at 19.2 billion yuan in 2025, with a 73% five-year compound growth rate and trillion-yuan demand expected within about a decade. Tianyancha shows more than 70 financing deals in China's embodied AI sector since 2026, up 279% year on year and worth about 17.4 billion yuan — yet the stated uses of funds make no explicit mention of security.
Li Binbin, a senior engineer at the China Electronics Standardization Institute, says the industry's prominent problem is "a strong body and a weak brain": excellent lab performance, but insufficient ability to handle unexpected situations in the real world.
Standardization is accelerating to fill the gap. In February 2026, the Humanoid Robot and Embodied AI Standards System (2026 Edition) was released, and the national standard project Humanoid Robot Safety Requirements Part 1: General Safety was approved, covering risk assessment and hazard identification for mechanical, electrical, functional and information security as well as interaction and decision safety.
Notably, the Network Security Technology — Embodied AI Security Guidelines was published for comment in August 2026, drafted by Unitree, the China Electronics Standardization Institute and the Pujiang National Laboratory, covering the full chain of "input, understanding, decision, execution and physical impact."
Meanwhile, the 2026 China Cybersecurity Conference and the National Cybersecurity Awareness Week collaborative defense forum will be held in Jinan on September 15-16, with a dedicated embodied AI security sub-forum.
Security firms are already positioning. NSFOCUS, through its Gewu Lab, has assessed KUKA, ABB and FANUC industrial robots and submitted multiple high-risk vulnerabilities to the national industrial information security vulnerability database CIDSVD; its "Fengyunwei" AI security platform detects risks and anomalous behavior in robot scheduling platforms and embodied AI models.
Zhou Hongyi advocates "using models to govern models" — AI against AI, agents defending against agents. 360's AI security framework simulates attacker thinking to build security agents that automatically find vulnerabilities and analyze risk, enabling proactive defense before attacks occur.
The deeper challenge is a shift in mindset. As robots move from digital space into the physical world, security is no longer the software industry's "patch" model but must be embedded in every stage of design, development, deployment and operation. A robot is itself an ecosystem interacting with people, data, software, infrastructure and regulations, so the boundary of security governance should extend from a single device to the entire connected network.