2027 is emerging as the definitive turning point for humanoid robotics. What has so far been confined to research laboratories or demonstration prototypes will officially enter assembly lines, logistics warehouses, and the first commercial environments open to the public. Technology giants and advanced startups in the sector, from Tesla Optimus projects to Figure AI models, as well as Boston Dynamics and Asian manufacturers such as Unitree, are converging toward production roadmaps that identify 2027 as a key milestone:
-
Mass production: Transition from handcrafted production to industrial assembly lines to reduce unit costs.
-
Enterprise sales and leasing: Widespread adoption across manufacturing, last-mile logistics, and healthcare.
-
Multimodal integration: Systems based on Large Physical Models (LPMs) and continuous spatial vision to operate alongside humans.
However, when software acquires a mechanical body equipped with strength, mobility, and complex sensors, the risk equation changes radically. A bug or vulnerability no longer results solely in a data breach: it can cause physical damage to environments and people.
From Robot Dogs to Humanoids: When Hardware Gets Hacked
The threat of hacking in robotics is not a science-fiction hypothesis; it is an already documented reality, particularly with the first quadruped robots (the so-called "robot dogs"), which are widely used for surveillance and security.
The most significant cases involve robots from Chinese manufacturer Unitree Robotics, among the most widely deployed worldwide in civilian, industrial, and research environments:
-
The hidden backdoor in the Unitree Go1 (2025): Researchers Andreas Makris and Kevin Finisterre discovered a pre-installed and undocumented remote access tunnel based on the CloudSail service. Once connected to the Internet, the robot dog automatically connected to external servers. Anyone with the API key could take control of the device, access live camera feeds, and connect via SSH. More than 1,900 units were found to have used the service, including devices at U.S. universities such as MIT, Princeton, and Carnegie Mellon (CVE-2025-2894).
-
UniPwn: the “wormable” vulnerability (September 2025): A serious flaw in the Bluetooth Low Energy (BLE) protocol made it possible to obtain root privileges wirelessly on the Go2 and B2 models (robot dogs) and the G1 and H1 humanoids. The most concerning aspect? The attack was wormable: an infected robot could automatically scan and compromise other nearby Unitree devices, potentially creating a botnet of physical machines.
-
Subsequent demonstrations and physical hijacking: At a cybersecurity conference in Shanghai, a Unitree G1 humanoid was taken over and made to strike a mannequin. In 2026, additional Remote Code Execution chains targeting the G1 EDU model emerged, again starting via Bluetooth. As early as 2022, a researcher had demonstrated how to instantly shut down an armed Unitree robot dog using a simple Flipper Zero.
These are in addition to already known vulnerabilities:
-
Communication interception and hijacking: Penetration testing on commercial quadrupeds has revealed vulnerabilities in proprietary Wi-Fi and radio protocols, allowing attackers to bypass the legitimate controller, take control of movement, and remotely shut down or sabotage the device.
-
Sensor and LiDAR manipulation (Sensor Spoofing): By sending calibrated laser signals or optical flashes, researchers have deceived the LiDAR systems and cameras of quadrupeds, creating "phantom obstacles" or making real barriers invisible, potentially causing falls and dangerous deviations.
-
Physical Data Exfiltration: Robots integrate HD cameras, audio sensors, and three-dimensional environmental mapping. Compromising the endpoint turns the robot into a physical spy inside industrial facilities or operational bases, transmitting video feeds and sensitive floor plans externally.
-
Jailbreaking onboard models: With the integration of LLMs for voice control, researchers have demonstrated the possibility of using voice-based prompt injection to force robots to ignore safety restrictions embedded in the firmware.
If a 15–30 kg quadruped can create serious risks, a 70 kg humanoid robot equipped with articulated arms and human-comparable strength represents a critical attack surface for civilian and industrial infrastructure.
The Challenge of the Decade: Why Cybersecurity Needs New Experts
The intersection of artificial intelligence, robotic operating systems (ROS/ROS2), industrial firmware, and cloud computing is creating unprecedented demand for Cybersecurity professionals. The profiles most sought after by the market are no longer limited to defending web servers or corporate databases, but must also protect:
-
Hardware & Firmware Security: Protection of chips, Secure Boot, and onboard memory encryption.
-
Operational Technology (OT) & IoT Security: Monitoring M2M (Machine-to-Machine) traffic and telemetry channels.
-
AI & Model Defense: Protection against adversarial attacks, data poisoning, and physical prompt injection.
-
Incident Response & Digital Forensics: The ability to isolate a compromised mobile device before it causes physical damage.
Celebrating 10 Years by Looking to the Future: Opportunities with Geeks Academy
To bridge the gap between demand and practical skills, specialized training plays a decisive role. Geeks Academy, a higher-education hub for digital professions, is celebrating its 10th anniversary this year (2016–2026). Over ten years of activity focused on keeping pace with emerging technologies, Geeks Academy has developed practical and specialized training programs in Cybersecurity & Cloud:
-
Ethical Hacking and Penetration Testing: Offensive and defensive techniques to identify vulnerabilities in systems before cybercriminals can exploit them.
-
Cyber Security Analyst: Threat monitoring, SOC management, and security protocols for complex networks.
-
Master in Cybersecurity & Cloud: A comprehensive program that starts with the fundamentals and specializes you in Offensive Security, Defensive Security, and Cybersecurity Governance.
New for 2026: robotics module and AI labs
To celebrate its 10th anniversary, the Academy has made several dedicated scholarships available, enabling young talents, students, and professionals undergoing reskilling to access master's courses and post-diploma programs.
Humanoid robots are about to enter everyday life and the productive ecosystem; protecting these machines will be one of the most delicate and strategic tasks for the next generation of IT professionals.