Security Breach in Rabbit R1 AI Device Exposes User Data

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

The Rabbit R1 AI device is under scrutiny for hard-coded API keys, allowing unauthorized access to user data and company systems. The Rabbitude group exposed these vulnerabilities, enabling access to all AI responses and potential impersonation of the company, posing significant privacy and security risks.[AI generated]

Why's our monitor labelling this an incident or hazard?

This is a realized security breach of an AI system leading to unauthorized data access and potential privacy violations. The AI system’s compromise directly resulted in harm (confidentiality and integrity of user data), fitting the definition of an AI Incident.[AI generated]
AI principles
AccountabilityPrivacy & data governanceRespect of human rightsRobustness & digital security

Industries
Consumer productsDigital securityIT infrastructure and hosting

Affected stakeholders
ConsumersBusiness

Harm types
Human or fundamental rightsReputationalEconomic/Property

Severity
AI incident

Business function:
ICT management and information security

AI system task:
Interaction support/chatbotsContent generation


Articles about this incident or hazard

Thumbnail Image

Rabbit R1 : l'IA de poche est une catastrophe pour votre cybersécurité

2024-06-27
01net
Why's our monitor labelling this an incident or hazard?
This is a realized security breach of an AI system leading to unauthorized data access and potential privacy violations. The AI system’s compromise directly resulted in harm (confidentiality and integrity of user data), fitting the definition of an AI Incident.
Thumbnail Image

Échec critique, danger pour les données personnelles : le Rabbit R1 n'en finit pas avec les polémiques

2024-06-27
Frandroid
Why's our monitor labelling this an incident or hazard?
An AI system (the Rabbit R1 and its backend AI server) malfunctioned due to insecure development practices (hard-coded API keys) and was exploited by hackers. This led to actual unauthorized access to user data and the potential for widespread device tampering—constituting an AI Incident (privacy violation and service disruption).
Thumbnail Image

Un problème de sécurité dans le Rabbit R1 laisse des données sensibles accessibles au public

2024-06-27
Begeek.fr
Why's our monitor labelling this an incident or hazard?
The Rabbit R1 is an AI system as it is an autonomous assistant device with AI functionalities to perform tasks like ordering food or providing information. The discovery of hardcoded API keys that could allow unauthorized reading and modification of user data and device behavior constitutes a malfunction or security flaw in the AI system's development or deployment. This flaw directly risks harm to users' privacy and data security, which falls under harm to persons or groups. Even though no confirmed data breach has occurred, the vulnerability's existence and potential exploitation represent a plausible risk of harm. Therefore, this event qualifies as an AI Hazard because it could plausibly lead to an AI Incident if exploited, but no realized harm is confirmed yet.
Thumbnail Image

Rabbit R1 : une faille de sécurité exposerait les données des utilisateurs

2024-06-26
KultureGeek
Why's our monitor labelling this an incident or hazard?
The Rabbit R1 is an AI system integrating multiple AI services (text-to-speech, speech-to-text, etc.). The exposure of API keys and potential unauthorized access to user data represents a violation of user privacy and a breach of obligations to protect personal data, which fits the definition of harm to persons or groups. The malfunction caused by revoked keys further indicates harm linked to the AI system's use and management. Therefore, this event qualifies as an AI Incident due to realized harm stemming from the AI system's development and use.
Thumbnail Image

Gros problème de sécurité pour Rabbit R1 ?

2024-06-26
Informaticien.be
Why's our monitor labelling this an incident or hazard?
The event involves an AI system (Rabbit R1) that uses APIs including ElevenLabs for speech synthesis, which is part of the AI system's operation. The security flaw allows unauthorized access to data and control over the AI system's outputs and backend, leading to potential harm to users' privacy and device functionality. This constitutes direct harm through data leakage and disruption of service, fitting the definition of an AI Incident. The lack of company response and ongoing risk to users further supports this classification.
Thumbnail Image

Le rabbit r1 se retrouve à nouveau sous le feu de critiques pour codage en dur de clés d'API après de précédents rapports selon lesquels le dispositif est une arnaque à l'intelligence artificielle

2024-06-27
Developpez.com
Why's our monitor labelling this an incident or hazard?
The rabbit r1 is an AI-powered device that had critical API keys hard-coded and exposed. Attackers used those keys to send emails from Rabbit’s domain and retrieve device responses, demonstrating unauthorized access and misuse of an AI system’s credentials. This constitutes a realized harm (security breach and data exposure) due to the AI system’s misuse, qualifying it as an AI Incident.