News Froggy
newsfroggy
HomeTechReviewProgrammingGamesHow ToAboutContacts
newsfroggy

Your daily source for the latest technology news, startup insights, and innovation trends.

More

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

Categories

  • Tech
  • Review
  • Programming
  • Games
  • How To

© 2026 News Froggy. All rights reserved.

TwitterFacebook
Tech

DJI will pay $30K to the man who accidentally hacked 7,000 Romo

DJI will pay security researcher Sammy Azdoufal $30,000 for discovering critical vulnerabilities in its Romo robot vacuums. Azdoufal accidentally accessed a network of 7,000 Romo devices, exposing privacy risks including PIN-less video access. While some issues are patched, a more severe vulnerability is still being addressed, with full system upgrades expected within a month.

PublishedMarch 7, 2026
Reading Time4 min
DJI will pay $30K to the man who accidentally hacked 7,000 Romo

DJI, the prominent drone manufacturer, has agreed to pay security researcher Sammy Azdoufal $30,000 for identifying critical vulnerabilities in its Romo robot vacuum cleaners. The payout follows Azdoufal's accidental discovery around Valentine's Day, where he gained access to a vast network of 7,000 remote-control Romo devices, exposing potential privacy risks by allowing unauthorized viewing into people’s homes. This development provides some clarity after initial uncertainty regarding DJI's response to the disclosure and its commitment to rewarding ethical hacking.

The Discovery and Initial Fallout

Azdoufal's journey began with a simple attempt to control his own DJI Romo robovac using a PlayStation gamepad. This innocuous experiment quickly escalated when he inadvertently stumbled upon an entire network of 7,000 Romo units, all seemingly accessible. His findings, later shared with The Verge, highlighted significant security gaps that could permit an outsider to "peek into other people’s homes" through the devices' cameras.

While DJI had reportedly begun addressing some security flaws even before Azdoufal's public disclosure, the extent of his access underscored the severity of the unpatched vulnerabilities. The situation drew comparisons to DJI's contentious interactions with security researcher Kevin Finisterre in 2017, casting doubt on whether Azdoufal would receive recognition or compensation for his work.

DJI's Response and the $30,000 Reward

Today, those questions have been partially answered. Azdoufal confirmed to The Verge that DJI would pay him $30,000, though the company did not specify which particular discovery the payment pertained to. DJI, while not publicly naming Azdoufal, confirmed it had "rewarded" an unnamed security researcher for their contributions.

The company also stated it has already tackled one of the major vulnerabilities Azdoufal identified: the ability for a user to view a Romo video stream without needing a security PIN. A statement from DJI spokesperson Daisy Kong noted, "We can confirm that the PIN code security observation was addressed by late February," indicating swift action on that specific flaw.

Addressing the Vulnerabilities: A Mixed Message

Concerns remain about an even more severe vulnerability, which The Verge initially deemed too sensitive to describe in its original report. DJI assured The Verge that this issue is also being actively addressed. "We have also started upgrading the entire system. This includes a series of updates, which we anticipate will be fully implemented within one month," DJI stated.

However, a public blog post published by DJI today regarding Romo security presented a slightly different picture. In the post, DJI claimed it discovered the original issue itself, while simultaneously crediting "two independent security researchers" for finding the same problem. The blog post also suggested a more immediate resolution, stating, "Updates have been deployed to fully resolve the issue," a claim that seemingly contradicts DJI's earlier projection to The Verge that full implementation could take another month.

The discrepancy raises questions about the timeline for a complete security overhaul of the Romo system. Furthermore, the blog post highlighted that the Romo already holds ETSI, EU, and UL certifications for security. Azdoufal's ability to access thousands of devices with relative ease, using what the original article described as "Claude Code," might lead consumers to question the practical efficacy of such certifications.

Implications and Future Commitments

Despite the ongoing work, DJI reiterated its commitment to enhancing device security. The company pledged to continue testing, patching, and submitting the Romo and its associated app to independent third-party security audits. In a move to foster better relations with the security community, DJI also announced its intent to "deepen our engagement with the security research community, and we will soon introduce new ways for researchers to partner and collaborate with us."

This incident underscores the complex balance between innovation in connected devices and ensuring robust user privacy and security. While the payment to Azdoufal signals a positive step towards recognizing ethical hacking, the ongoing work to fully patch all vulnerabilities and the mixed messaging surrounding their resolution highlight the challenges inherent in securing a vast network of smart home devices.

FAQ

Q: Who is Sammy Azdoufal?

A: Sammy Azdoufal is the security researcher who, while attempting to control his own DJI Romo robot vacuum, accidentally discovered a network of 7,000 accessible Romo devices, revealing significant security vulnerabilities.

Q: What was the primary vulnerability Azdoufal discovered?

A: Azdoufal's initial discovery was the ability to access a large network of Romo robovacs, including viewing live video streams without requiring a security PIN. A more severe vulnerability, not fully described publicly, is also being addressed.

Q: Has DJI fully resolved all identified security issues?

A: DJI states that the vulnerability allowing PIN-less video stream viewing was addressed by late February. For a more critical, undisclosed vulnerability, DJI is implementing an "entire system upgrade" expected to be fully deployed within one month. However, there are discrepancies between public blog posts and statements to The Verge regarding the timeline for complete resolution.

#DJI#Romo#Cybersecurity#Security Research#Robot Vacuums

Related articles

OpenAI's Bubeck Denies Credit Stripping, Apologizes Amidst
Tech
The Next WebSep 10

OpenAI's Bubeck Denies Credit Stripping, Apologizes Amidst

OpenAI's Sébastien Bubeck denies attempting to strip Anthropic mathematician Levent Alpöge of credit for his work on the Navier-Stokes problem, apologizing for a remark made during contentious private discussions. OpenAI CEO Sam Altman backed Bubeck, but Alpöge and his collaborator, Tristan Buckmaster, present a conflicting account of events. The dispute also raises questions about OpenAI's data handling policies, as the mathematicians claim to have used OpenAI's Codex tool during their research.

New Masculinity Standards Drive Men to Risky DIY Health Trends
Tech
The VergeSep 10

New Masculinity Standards Drive Men to Risky DIY Health Trends

New masculinity standards are pushing men to risky DIY health experiments, Victoria Song reports. Online communities promote 'looksmaxxing' with unapproved substances like testosterone, posing significant health risks and mirroring historical exploitation of insecurities.

Ace Combat 8 Takes Flight with Star-Studded Prequel Series
Games
IGNSep 10

Ace Combat 8 Takes Flight with Star-Studded Prequel Series

Ace Combat 8: Wings of Theve is launching soon, but not before a live-action prequel miniseries, Hour Zero, drops exclusively on IGN. Starring Josh Holloway, Brandon Routh, and Tamlyn Tomita, this four-part show will build narrative context for the game's campaign, starting September 15. Holloway shared his renewed love for gaming and a desire to adapt games into movies.

in-depth: Best Bluetooth Speaker (2026): JBL, Sonos, Marshall, and
Tech
WiredSep 10

in-depth: Best Bluetooth Speaker (2026): JBL, Sonos, Marshall, and

WIRED's 2026 guide names the JBL Flip 7 the top Bluetooth speaker, recognizing its balance of sound, durability, and affordability. The updated list highlights significant advancements across the portable audio market, with specialized picks from Sonos, Marshall, and KEF offering enhanced smart features, battery life, and sound quality for diverse user needs.

Failing NASA Satellite Embarks on Its Final Cosmic Mission
Tech
WiredSep 10

Failing NASA Satellite Embarks on Its Final Cosmic Mission

NASA's Swift Observatory Begins Final Observations Before Atmospheric Reentry NASA's Neil Gehrels Swift Observatory, a venerable sentinel of the cosmos for 21 years, is embarking on its final mission as it inexorably

Apple Unleashes iPhone Duo: Three-Screen Foldable Debuts at $2,000
Tech
Washington Post TechnologySep 9

Apple Unleashes iPhone Duo: Three-Screen Foldable Debuts at $2,000

Apple has introduced its first foldable smartphone, the iPhone Duo, on September 9, 2026. Featuring three screens and a book-like hinge, this $1,999 device is the most significant iPhone design change since 2007, establishing a new ultra-premium tier for Apple.

Back to Newsroom

Stay ahead of the curve

Get the latest technology insights delivered to your inbox every morning.