Researchers demonstrate Bluetooth/PIN flaw letting attackers hijack Ecovacs Deebot cameras and mics
S2 · ~Aug 2024 · Ecovacs
Record
| Company | Ecovacs |
| Industry | Consumer robotics |
| Type(s) | cyber |
| Date | ~Aug 2024 (month precision) |
| Time of day | not documented |
| Location | no physical site (recall / fleet-wide / aggregate record) |
| Severity | (minor injury or single-unit damage) |
| Scale | multiple Deebot models |
| Confidence | high |
| Verified flag | Cited source on file; not independently re-verified |
Summary
At DEF CON 32, security researchers Dennis Giese and Braelynn Luedtke showed that a weak Bluetooth PIN implementation in Ecovacs Deebot robots let attackers connect from up to roughly 450 feet away and activate the onboard camera and microphone without the owner's knowledge.
Primary source
Publisher: Security Affairs · Retrieved: 2026-09-16
Supporting source rows (1)
| Date | Supporting source row | Publisher | Link |
|---|---|---|---|
| ~Aug 2024 | Researchers demonstrate Bluetooth/PIN flaw letting attackers hijack Ecovacs Deebot cameras and mics | Security Affairs | Security Affairs |
Ecovacs other incidents timeline
Consumer robotics context
cyber context
Ecovacs industry position
Related incidents
Other Ecovacs entries
- ~May 2025 - CISA advisory: Ecovacs Deebot base stations accept unvalidated firmware updates, deterministic WiFi key
- ~May 2024 - Hacked Ecovacs Deebot X2 vacuums shout racial slurs, chase pet in multiple US cities
Report a correction
Also from Critical Systems Analysis: CSA - functional safety engineering · Company directory · FSTalent - functional safety jobs