
Thanks @Korben , nice writeup. I would like to point you to some things. Benn Jordan only re-used my BLE hack and also the go1 backdoor. Original research to both hacks is here: #UniPwn: https://takeonme.org/cves/cve-2025-35027/ Go1 Backdoor: https://takeonme.org/cves/cve-2025-2894/ Benn only added the credits to the work after we reached out to him via email and @d0tslash publicly called him out here on X and LI. It is linked in the video description of the video now, please take a look ;) Git repos for the work are here: https://github.com/Bin4ry/UniPwn and https://github.com/MAVProxyUser/YushuTechUnitreeGo1/blob/main/Unitree_report.pdf you can see screenshots of my repos in his video. The #UniPwn repo is shown for a brief second at 12:20 while he narrates the story as if he did the hack. The #UniPwn hack was covered by Spectrum and other big outlets: https://spectrum.ieee.org/unitree-robot-exploit https://hackaday.com/2025/09/30/unitree-humanoid-robot-exploit-looks-like-a-bad-one/ UniPwn was the first hack of an humanoid robot and also wormable. The whole privacy concerns are all covered in the paper that was written in cooperation with @vmayoralv and was victors findings: https://arxiv.org/abs/2509.14139 Hope this info helps you to put things into the right order :) First was the Go1 backdoor back in March 2025, then #UniPwn in September 2025.
Post summary
The entry highlights the original author’s work on CVE‑2025‑35027 and CVE‑2025‑2894, offering direct links to PoC repositories and documentation, but it does not discuss active exploitation or a patch, focusing instead on disclosure.




