July 19, 2026
We Paid SharkNinja to Put Spy Cameras in 1.5 Million Living Rooms
Live camera feeds, home maps, and plaintext Wi-Fi passwords: Inside the major security flaw affecting 1.5 million Shark vacuums that the…

By kevin @ clerica
4 min read
- 1 Live camera feeds, home maps, and plaintext Wi-Fi passwords: Inside the major security flaw affecting 1.5 million Shark vacuums that the manufacturer refused to fix.
- 2 The Cloud-Side Skeleton Key
- 3 A Timeline of Corporate Apathy
- 4 "Sketchy" Foreign Brands vs. The Western Corporate Reality
- 5 The DMCA Irony
Live camera feeds, home maps, and plaintext Wi-Fi passwords: Inside the major security flaw affecting 1.5 million Shark vacuums that the manufacturer refused to fix.
SharkNinja's engineering team:_ "We gave every vacuum a camera, a microphone, and a map of the user's house."_
SharkNinja's security team:_ "And we gave them all the exact same key to the front door."_
Unbelievable. We aren't buying appliances anymore; we're literally paying corporations to plant surveillance bugs in our own living rooms.
It sounds like a bad joke, but it is the literal reality of modern "smart" home ownership. If you own a Shark robot vacuum, anyone with a basic understanding of hardware debugging and a screwdriver can tap into your device's live camera feed, steal your home floor maps, and grab your Wi-Fi password.
And the absolute worst part? SharkNinja has known about this for months and has done absolutely nothing to fix it.
The Cloud-Side Skeleton Key
The vulnerability, discovered by security researcher tokay0 and detailed in a report analyzed by The Hacker News, lies in how Shark robot vacuums communicate with the cloud.
Like many Internet of Things (IoT) devices, Shark vacuums use Amazon Web Services (AWS) IoT to receive commands and send data. When a vacuum logs in, it presents a digital certificate. In a secure architecture, the AWS backend checks that the certificate is unique and restricts its permissions to that specific device.
But as Malwarebytes reports, Shark's cloud-side policy had an incredibly lazy misconfiguration: the digital certificate is never locked to an individual vacuum.
If an attacker takes apart a single Shark vacuum that they own, exposes the circuit board, and extracts its digital certificate, that certificate acts as a region-wide skeleton key. The cloud accepts it as valid to send commands to — and retrieve data from — any Shark vacuum in that entire geographical region.
According to Tom's Hardware, this unpatched flaw allows an attacker to:
- Watch live video streams from any active vacuum's camera.
- Exfiltrate detailed maps of users' homes.
- Steal local Wi-Fi passwords, which are stored on the vacuum in plain text.
A Timeline of Corporate Apathy
A security flaw is bad enough, but SharkNinja's response is a masterclass in corporate negligence. In his video coverage on the Louis Rossmann YouTube Channel (which you can search for on YouTube), Louis Rossmann detailed the staggering timeline of the responsible disclosure process:
- March 1: The researcher first contacts SharkNinja about a critical vulnerability in their products.
- March 11: The researcher shares the precise technical details of the flaw.
- March 12: SharkNinja acknowledges receipt of the report.
- April 25: After a month and a half of silence, the researcher reaches out for a status update.
- April 27: SharkNinja responds vaguely, stating the report is "under review."
- June 7: The researcher follows up again.
- June 9: The standard 90-day responsible disclosure period officially ends.
- June 28: Having received no fix or substantial update, the researcher notifies SharkNinja of their plan to publicly disclose the flaw.
- July 3: SharkNinja finally promises to send a confirmed completion date for a fix by Friday, July 10.
- July 10: The deadline passes. SharkNinja sends absolutely nothing.
- July 13: After waiting three extra days beyond the promised date, the researcher finally publishes their blog post exposing the vulnerability.
As IT-Connect Tech noted, the manufacturer even downplayed the severity of the issue and questioned whether assigning a CVE (Common Vulnerabilities and Exposures) identifier was appropriate. Meanwhile, during a 24-hour observation period in just one AWS region, the researcher counted over 1.5 million unique Shark serial numbers — and roughly 44% of those devices responded to commands in a way that proved they were actively vulnerable.
"Sketchy" Foreign Brands vs. The Western Corporate Reality
For years, Western tech pundits and government agencies have warned consumers against buying smart appliances from Chinese companies like Ecovacs or Roborock, painting them as security threats. Indeed, as Kaspersky documented, researchers have previously exposed severe flaws in Ecovacs vacuums that allowed attackers to hijack them, play obscene sounds, and spy on families.
But this SharkNinja debacle proves that American and Western brands are no safer. They cut the exact same corners, run the same sloppy cloud configurations, and treat their customers' basic physical privacy with the same level of utter indifference.
The DMCA Irony
There is a final, bitter irony to this mess. Under Section 1201 of the Digital Millennium Copyright Act (DMCA), it is technically illegal for a consumer to break a digital lock on a device they own. Nonprofits like Rossmann's Fulu Foundation have to constantly fight for legal exemptions just so security researchers can check if our appliances are spying on us.
Corporations use these laws to hide their garbage security behind legal threats. Yet, when a researcher does the work for them for free, hand-delivering a critical flaw on a silver platter, the company sits on its hands for four months.
If you own a Shark robot vacuum, there is only one logical step to protect your home privacy: disconnect it from your Wi-Fi immediately. Treat it as a dumb vacuum, or put tape over the camera. Until SharkNinja implements proper device-level certificate validation on the server side, your household helper is a wide-open window into your living room.
If you liked anything about the article or about Clerica in general, please consider following our socials to keep us motivated, and to stay up to date!