GadgetBond

  • Latest
  • How-to
  • Tech
    • AI
    • Amazon
    • Apple
    • CES
    • Computing
    • Creators
    • Google
    • Meta
    • Microsoft
    • Mobile
    • Samsung
    • Security
    • Xbox
  • Transportation
    • Audi
    • BMW
    • Cadillac
    • E-Bike
    • Ferrari
    • Ford
    • Honda Prelude
    • Lamborghini
    • McLaren W1
    • Mercedes
    • Porsche
    • Rivian
    • Tesla
  • Culture
    • Apple TV
    • Disney
    • Gaming
    • Hulu
    • Marvel
    • HBO Max
    • Netflix
    • Paramount
    • SHOWTIME
    • Star Wars
    • Streaming
Add GadgetBond as a preferred source to see more of our stories on Google.
Font ResizerAa
GadgetBondGadgetBond
  • Latest
  • Tech
  • AI
  • Deals
  • How-to
  • Apps
  • Mobile
  • Gaming
  • Streaming
  • Transportation
Search
  • Latest
  • Deals
  • How-to
  • Tech
    • Amazon
    • Apple
    • CES
    • Computing
    • Creators
    • Google
    • Meta
    • Microsoft
    • Mobile
    • Samsung
    • Security
    • Xbox
  • AI
    • Anthropic
    • ChatGPT
    • ChatGPT Atlas
    • Gemini AI (formerly Bard)
    • Google DeepMind
    • Grok AI
    • Meta AI
    • Microsoft Copilot
    • OpenAI
    • Perplexity
    • xAI
  • Transportation
    • Audi
    • BMW
    • Cadillac
    • E-Bike
    • Ferrari
    • Ford
    • Honda Prelude
    • Lamborghini
    • McLaren W1
    • Mercedes
    • Porsche
    • Rivian
    • Tesla
  • Culture
    • Apple TV
    • Disney
    • Gaming
    • Hulu
    • Marvel
    • HBO Max
    • Netflix
    • Paramount
    • SHOWTIME
    • Star Wars
    • Streaming
Follow US
RoboticsSecuritySmart HomeTech

Hackers exploit security flaws in Ecovacs Deebot X2 to control robovacs

Hackers used Ecovacs Deebot X2 Omni robovacs to yell slurs and harass pets in U.S. households.

By
Shubham Sawarkar
Shubham Sawarkar's avatar
ByShubham Sawarkar
Editor-in-Chief
I’m a tech enthusiast who loves exploring gadgets, trends, and innovations. With certifications in CISCO Routing & Switching and Windows Server Administration, I bring a sharp...
Follow:
- Editor-in-Chief
Oct 12, 2024, 3:18 PM EDT
Share
We may get a commission from retail offers. Learn more
The image shows a modern living room with a ECOVACS DEEBOT X2 OMNI robot vacuum cleaner and its docking station. The docking station is black and rectangular, positioned against a wall. The robotic vacuum cleaner is also black and is moving on the floor towards the docking station. In the background, there is a beige sectional sofa with cushions, a coffee table, and large windows with sheer curtains, allowing natural light to fill the room.
Image: ECOVACS
SHARE

Imagine settling down for a quiet evening, only to have your robotic vacuum suddenly come to life—not to clean, but to spew racist slurs and chase your pets around the house. This alarming scenario became a reality for several U.S. residents earlier this year, when hackers managed to seize control of Ecovacs Deebot X2 Omni robotic vacuums in cities like Los Angeles, El Paso, and Minneapolis.

ABC News in Australia broke the story, recounting a disturbing incident involving Minnesota lawyer Daniel Swenson. Swenson described the initial shock as a “broken-up radio signal” emerged from his robovac’s speaker while he was watching TV with his family. At first, it seemed like a glitch. But after resetting his password and rebooting the device, Swenson’s Deebot X2 Omni started broadcasting a much more sinister message—this time in the form of clear, audible slurs. The voice sounded like that of a teenager, he guessed.

Swenson wasn’t alone. Other Deebot X2 Omni owners came forward with similar tales, including an owner in Los Angeles who claimed their robovac had been used to harass their dog. Hackers had apparently gained control of the vacuum, maneuvering it to chase the animal while shouting at it through the device’s built-in speaker.

While terrifying, this type of attack shines a spotlight on the larger issue plaguing the growing smart home device market—security vulnerabilities.

What went wrong?

Ecovacs, the company behind the Deebot X2 Omni, acknowledged the breach, stating that the attack stemmed from a “credential stuffing event.” This type of attack occurs when hackers use stolen username-password combinations from other services in an attempt to break into a separate account. In this case, it appears some users had reused weak or previously compromised passwords across different platforms, allowing hackers to seize control of their Deebots. Ecovacs claims that it quickly blocked the IP address involved and reassured users that no usernames or passwords had been harvested in the breach.

However, this wasn’t the first time the Deebot X2 had been exposed as a security risk. Last year, researchers demonstrated how they could bypass the vacuum’s PIN entry system, giving them unauthorized access to the device. Although Ecovacs stated that it patched this specific flaw, security researchers and watchdogs remain skeptical. In fact, just a few weeks prior to this latest attack, ABC News conducted an investigation showing how vulnerabilities in the Deebot X2’s Bluetooth system could also be exploited.

Ecovacs has promised a new update in November aimed at bolstering security, but there’s no word on whether it will fully resolve the Bluetooth issue or other potential gaps in protection.

A broader issue with smart home devices

This isn’t the first time a smart home device has been turned against its owner. Over the past few years, a growing number of cloud-connected gadgets have been infiltrated by hackers, from baby monitors to doorbell cameras. In some cases, attackers manage to commandeer the device’s functionality, while in others, users simply log in and find they’re viewing another owner’s camera feed by mistake—a chilling reminder of the security risks that come with modern conveniences.

A common denominator in many of these incidents is the constant internet connection required by many smart devices. While this connectivity allows users to monitor and control their homes remotely, it also opens up new avenues for attack if companies don’t prioritize security. The fact that many manufacturers don’t offer straightforward ways for users to report vulnerabilities—or address them quickly—only makes the situation worse.

For example, in this Deebot incident, owners likely weren’t even aware their vacuums were vulnerable until it was too late. With so many people buying smart home products, from thermostats to security systems, it’s easy to forget that these devices can often be the weakest link in a home’s digital defenses.

What can consumers do?

Unfortunately, securing your smart home devices isn’t as simple as locking your front door. Hackers often exploit lax password habits—like reusing credentials across multiple services—so step one is using strong, unique passwords for every device. Enabling two-factor authentication (if available) adds an extra layer of protection, requiring both your password and a secondary code to gain access.

Beyond passwords, regularly updating device firmware is crucial. Many companies release patches to fix vulnerabilities, but if you don’t update, those security gaps remain open. Staying vigilant and monitoring your devices for unusual behavior, as Daniel Swenson did, could also help catch an attack before it escalates.

Lastly, consumers should hold companies accountable. If a smart home product lacks transparency around its security measures or fails to release timely updates, consider switching to a brand with a better track record. Security should never be an afterthought, especially when hackers can turn a helpful household tool into a nightmare-inducing terror.

For now, Deebot X2 Omni owners are holding their breath until November’s promised update rolls out. Whether that will be enough to prevent another round of robovac hijackings remains to be seen.


Discover more from GadgetBond

Subscribe to get the latest posts sent to your email.

Most Popular

Apple rolls out iOS 26.5.1 and macOS 26.5.1 with important fixes

Apple Intelligence comes back to WWDC with more to prove

Here are all the winners of Apple’s 2026 Design Awards

Apple teases WWDC 2026 with ‘All systems glow’ and a big Siri reboot incoming

Sonos’s Arc Ultra Dolby Atmos soundbar is $200 off its list price

Also Read
Apple showing off Siri’s updated logo at WWDC 2024.

Siri’s AI reboot could run on NVIDIA chips inside Google Cloud

Apple logo on iPhone 11

iOS 27 rumored to skip four older iPhone models

Apple Arcade Family Feud Pocket trailer

Apple Arcade adds Family Feud Pocket and eight more games

The App Store logo in white, set against a shiny metallic blue background

Apple touts $1.4 trillion in App Store-driven sales

Promotional illustration of a ChatGPT interface showing the prompt box beneath the heading “What can I help with?”. A dropdown menu for tools and sources is open, displaying toggles for Web Search and Canva integration. The Canva option is enabled, highlighted by a green label reading “Sam,” indicating a user selecting Canva as a connected tool within ChatGPT. The interface is set against a blue-to-purple gradient background, emphasizing creative collaboration between ChatGPT and Canva.

Canva plugs its full design suite into ChatGPT

Screenshot-style promotional image showing a chat interface with the message: “@Canva Turn this Q3 launch brief into a presentation I can share with the leadership team.” Two file attachments are attached above the prompt, while a Canva app button appears below, highlighted by a blue label reading “You,” indicating app selection within the chat. The interface includes attachment, microphone, and send icons, set against a dark teal abstract background of glowing digital particles.

Canva lands inside Perplexity Computer

Age of Empires Mobile: PC Edition promotional key art.

Age of Empires Mobile heads to PC on June 23

Apple App Store logo

Apple starts age verification in Texas

Company Info
  • Homepage
  • Support my work
  • Latest stories
  • Company updates
  • GDB Recommends
  • Daily newsletters
  • About us
  • Contact us
  • Write for us
  • Editorial guidelines
Legal
  • Privacy Policy
  • Cookies Policy
  • Terms & Conditions
  • DMCA
  • Disclaimer
  • Accessibility Policy
  • Security Policy
  • Do Not Sell or Share My Personal Information
Socials
Follow US

Disclosure: We love the products we feature and hope you’ll love them too. If you purchase through a link on our site, we may receive compensation at no additional cost to you. Read our ethics statement. Please note that pricing and availability are subject to change.

Copyright © 2026 GadgetBond. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | Do Not Sell/Share My Personal Information.