Skip to main content

You may want to stop using the Rabbit R1

Someone holding the Rabbit R1 outside.
Joe Maring / Digital Trends

After it was launched in late April 2024, the Rabbit R1 got a mixed bag of reviews, with many reviewers describing it as an unhelpful gadget or only scarcely more useful than Humane’s AI Pin. Digital Trends’ Joe Maring rated it a single star, writing, “The Rabbit R1 was supposed to be one of the hottest AI gadgets of the year. Instead, it’s a buggy, flawed, and unsuccessful mess in every way imaginable.”

As if launching a product flop wasn’t bad enough, Rabbit is now facing reports of a data breach that may have revealed sensitive user data. Rabbitude, a reverse engineering project for the Rabbit R1, is reporting it was able to gain access to the Rabbit codebase and found several hardcoded API keys in its codes.

Recommended Videos

The below isn’t an exhaustive list, but it allows anyone to do any of the following:

  • Read every response every R1 has ever given, including ones containing personal information
  • Brick all R1s
  • Alter the responses of all R1s
  • Replace every R1’s voice

The following services also had their API keys exposed:

  • ElevenLabs (for text-to-speech)
  • Azure (for an old speech-to-text system)
  • Yelp (for review lookups)
  • Google Maps (for location lookups)
The Settings page on the Rabbit R1.
Joe Maring / Digital Trends

Rabbitude notes that the API keys for Elevenlabs give full privileges. These include getting a history of all past text-to-speech messages, changing voices, adding custom text replacements, deleting voices, and crashing the rabbitOS backend, essentially bricking all Rabbit R1 devices. Rabbit did, however, revoke the Elevenlabs API key, which also broke Rabbit devices for a period of time.

This is a fairly worrying set of permissions to allow on any device, but it’s extra troubling when it’s for an always-on voice-activated AI gadget loaded with cameras. Rabbitude says it reached out to the Rabbit Team, which is aware of the leaked API keys, but they “have chosen to ignore it,” and the API keys continue to be valid as of this writing.

all rabbit r1 responses could be read by us for the past month and rabbit knew about it and did nothing to fix it.https://t.co/r6NmhZJY5W

— xyzeva (@xyz3va) June 25, 2024

Endgadget similarly reached out to the company and received confirmation that Rabbit is aware of the “alleged” data breach as of June 25. “Our security team immediately began investigating it,” the company said. “As of right now, we are not aware of any customer data being leaked or any compromise to our systems. If we learn of any other relevant information, we will provide an update once we have more details.”

As far as security failures go, this seems to be a fairly serious one. While the Rabbit R1 is a neat device, it’s also heavily flawed, and the security issues are sufficient enough that we recommend that you stop using it, at least for now. After all, there’s nothing your $199 Rabbit R1 (separate data plan required) can do that your smartphone can’t.

Ajay Kumar
Former Digital Trends Contributor
Ajay has worked in tech journalism for more than a decade as a reporter, analyst, and editor.
Check your Samsung Galaxy S22 for a big update right now
The Samsung Galaxy S22 in a purple color.

Samsung Galaxy S22 Andrew Martonik / Digital Trends

Samsung is finally fulfilling its promise in the post-Galaxy S24 launch era. The company, via an official newsroom post, has confirmed that the generative AI tricks that made its latest flagship phones stand out are now rolling out for the two-generation-old Galaxy S22 series phones.

Read more
The Rabbit R1 is hiding a big secret
The Rabbit R1 standing upright on a wooden railing with its display turned on.

“This is supposed to be a simpler companion to my phone, yet the R1 often tells me to use my phone when asking it to do the most basic of tasks,” wrote Digital Trends’ Section Editor Joe Maring after taking the Rabbit R1 out for a spin. The biggest flaw here is not a slow interface or lack of functions, but what it adds to an average user's life on a day-to-day basis.

At this stage, it's not much, primarily because a budget Android phone can do the same tasks with apps — be it AI chores like summarizing an email chain or ordering a burger. "This could've been an AI app at best." That's a recurring theme in the online forums about the R1. And it seems the R1 itself proves that point.
The Rabbit R1's Android secret

Read more
I spent four days with the AI gadget of the future, and it was a mess
Someone holding the Rabbit R1 with its screen turned on.

This past January, a company called Rabbit took CES 2024 by storm. Rabbit used CES to announce its new gadget — the Rabbit R1 — and it was immediately captivating. With a retro design, bright orange paint job, and adorable rabbit logo, it was hard not to get excited about the R1 ... even if it wasn't immediately clear what it was supposed to do.

I've now spent the past four days living with the Rabbit R1. While I love its design, unapologetically orange color, and the bouncing rabbit on its display, almost everything else about the R1 has been, to put it nicely, a mess.
What the Rabbit R1 is supposed to do

Read more