News Froggy
newsfroggy
HomeTechReviewProgrammingGamesHow ToAboutContacts
newsfroggy

Your daily source for the latest technology news, startup insights, and innovation trends.

More

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

Categories

  • Tech
  • Review
  • Programming
  • Games
  • How To

© 2026 News Froggy. All rights reserved.

TwitterFacebook
Tech

DJI will pay $30K to the man who accidentally hacked 7,000 Romo

DJI will pay security researcher Sammy Azdoufal $30,000 for discovering critical vulnerabilities in its Romo robot vacuums. Azdoufal accidentally accessed a network of 7,000 Romo devices, exposing privacy risks including PIN-less video access. While some issues are patched, a more severe vulnerability is still being addressed, with full system upgrades expected within a month.

PublishedMarch 7, 2026
Reading Time4 min
DJI will pay $30K to the man who accidentally hacked 7,000 Romo

DJI, the prominent drone manufacturer, has agreed to pay security researcher Sammy Azdoufal $30,000 for identifying critical vulnerabilities in its Romo robot vacuum cleaners. The payout follows Azdoufal's accidental discovery around Valentine's Day, where he gained access to a vast network of 7,000 remote-control Romo devices, exposing potential privacy risks by allowing unauthorized viewing into people’s homes. This development provides some clarity after initial uncertainty regarding DJI's response to the disclosure and its commitment to rewarding ethical hacking.

The Discovery and Initial Fallout

Azdoufal's journey began with a simple attempt to control his own DJI Romo robovac using a PlayStation gamepad. This innocuous experiment quickly escalated when he inadvertently stumbled upon an entire network of 7,000 Romo units, all seemingly accessible. His findings, later shared with The Verge, highlighted significant security gaps that could permit an outsider to "peek into other people’s homes" through the devices' cameras.

While DJI had reportedly begun addressing some security flaws even before Azdoufal's public disclosure, the extent of his access underscored the severity of the unpatched vulnerabilities. The situation drew comparisons to DJI's contentious interactions with security researcher Kevin Finisterre in 2017, casting doubt on whether Azdoufal would receive recognition or compensation for his work.

DJI's Response and the $30,000 Reward

Today, those questions have been partially answered. Azdoufal confirmed to The Verge that DJI would pay him $30,000, though the company did not specify which particular discovery the payment pertained to. DJI, while not publicly naming Azdoufal, confirmed it had "rewarded" an unnamed security researcher for their contributions.

The company also stated it has already tackled one of the major vulnerabilities Azdoufal identified: the ability for a user to view a Romo video stream without needing a security PIN. A statement from DJI spokesperson Daisy Kong noted, "We can confirm that the PIN code security observation was addressed by late February," indicating swift action on that specific flaw.

Addressing the Vulnerabilities: A Mixed Message

Concerns remain about an even more severe vulnerability, which The Verge initially deemed too sensitive to describe in its original report. DJI assured The Verge that this issue is also being actively addressed. "We have also started upgrading the entire system. This includes a series of updates, which we anticipate will be fully implemented within one month," DJI stated.

However, a public blog post published by DJI today regarding Romo security presented a slightly different picture. In the post, DJI claimed it discovered the original issue itself, while simultaneously crediting "two independent security researchers" for finding the same problem. The blog post also suggested a more immediate resolution, stating, "Updates have been deployed to fully resolve the issue," a claim that seemingly contradicts DJI's earlier projection to The Verge that full implementation could take another month.

The discrepancy raises questions about the timeline for a complete security overhaul of the Romo system. Furthermore, the blog post highlighted that the Romo already holds ETSI, EU, and UL certifications for security. Azdoufal's ability to access thousands of devices with relative ease, using what the original article described as "Claude Code," might lead consumers to question the practical efficacy of such certifications.

Implications and Future Commitments

Despite the ongoing work, DJI reiterated its commitment to enhancing device security. The company pledged to continue testing, patching, and submitting the Romo and its associated app to independent third-party security audits. In a move to foster better relations with the security community, DJI also announced its intent to "deepen our engagement with the security research community, and we will soon introduce new ways for researchers to partner and collaborate with us."

This incident underscores the complex balance between innovation in connected devices and ensuring robust user privacy and security. While the payment to Azdoufal signals a positive step towards recognizing ethical hacking, the ongoing work to fully patch all vulnerabilities and the mixed messaging surrounding their resolution highlight the challenges inherent in securing a vast network of smart home devices.

FAQ

Q: Who is Sammy Azdoufal?

A: Sammy Azdoufal is the security researcher who, while attempting to control his own DJI Romo robot vacuum, accidentally discovered a network of 7,000 accessible Romo devices, revealing significant security vulnerabilities.

Q: What was the primary vulnerability Azdoufal discovered?

A: Azdoufal's initial discovery was the ability to access a large network of Romo robovacs, including viewing live video streams without requiring a security PIN. A more severe vulnerability, not fully described publicly, is also being addressed.

Q: Has DJI fully resolved all identified security issues?

A: DJI states that the vulnerability allowing PIN-less video stream viewing was addressed by late February. For a more critical, undisclosed vulnerability, DJI is implementing an "entire system upgrade" expected to be fully deployed within one month. However, there are discrepancies between public blog posts and statements to The Verge regarding the timeline for complete resolution.

#DJI#Romo#Cybersecurity#Security Research#Robot Vacuums

Related articles

Xi pitches open-source AI to BRICS amid domestic curb debates
Tech
The Next WebSep 13

Xi pitches open-source AI to BRICS amid domestic curb debates

Chinese President Xi Jinping proposed a China-led open-source AI community and invited BRICS nations to join the World AI Cooperation Organization (WAICO) at the recent BRICS summit. This push for global collaboration contrasts sharply with Beijing's ongoing internal debates about restricting its own advanced AI models. Meanwhile, the EU's comprehensive AI Act, with its clear, enforceable rules for open-source AI, highlights a significant divergence in global AI governance approaches.

Tesla Set to Finally Unveil Second-Generation Roadster on October 1
Tech
TechCrunchSep 13

Tesla Set to Finally Unveil Second-Generation Roadster on October 1

The much-anticipated second generation of the Tesla Roadster, a halo vehicle promising revolutionary performance, is finally slated for a public unveiling on October 1. After years of delays and a protracted development

Seattle Warned on Big Tech Reliance; Microsoft/OpenAI Sued; Apple's
Tech
GeekWireSep 13

Seattle Warned on Big Tech Reliance; Microsoft/OpenAI Sued; Apple's

A new City of Seattle study warns of the city's risky economic over-reliance on a few dominant tech companies. Simultaneously, the Seattle Times and Newsday are suing Microsoft and OpenAI for alleged AI training data theft, while Apple's new foldable iPhone Duo evokes memories of Microsoft's defunct Surface Duo.

in-depth: The Best 3-in-1 Apple Charging Stations After Testing 30
Tech
WiredSep 12

in-depth: The Best 3-in-1 Apple Charging Stations After Testing 30

Wired has released its top picks for 3-in-1 Apple charging stations, extensively tested for iPhone, Apple Watch, and AirPods. The guide highlights six leading models, from premium speedy options to budget-friendly and compact designs, all focused on decluttering and optimizing charging for Apple users.

Nscale Adds Former OpenAI Exec Fidji Simo to Board Ahead of IPO
Tech
TechCrunch AISep 12

Nscale Adds Former OpenAI Exec Fidji Simo to Board Ahead of IPO

Nscale, the U.K.-based AI data center startup, has appointed former OpenAI, Meta, and Instacart executive Fidji Simo to its board of directors. This high-profile addition comes as Nscale prepares for a potential IPO this fall, leveraging Simo's extensive experience in scaling major tech platforms and guiding a company through a successful public offering.

Microsoft comms chief Frank Shaw to exit after nearly three decades
Tech
GeekWireSep 12

Microsoft comms chief Frank Shaw to exit after nearly three decades

Frank X. Shaw, Microsoft's long-serving chief communications officer, will exit at year-end after nearly three decades shaping the company's message through pivotal periods. Shaw, 64, is not retiring but plans a break before his next move, leaving behind a legacy of adapting communications for a digital age and embracing AI tools. Microsoft is now searching for his successor.

Back to Newsroom

Stay ahead of the curve

Get the latest technology insights delivered to your inbox every morning.