Skip to main content

You may want to stop using the Rabbit R1

Someone holding the Rabbit R1 outside.
Joe Maring / Digital Trends

After it was launched in late April 2024, the Rabbit R1 got a mixed bag of reviews, with many reviewers describing it as an unhelpful gadget or only scarcely more useful than Humane’s AI Pin. Digital Trends’ Joe Maring rated it a single star, writing, “The Rabbit R1 was supposed to be one of the hottest AI gadgets of the year. Instead, it’s a buggy, flawed, and unsuccessful mess in every way imaginable.”

Recommended Videos

As if launching a product flop wasn’t bad enough, Rabbit is now facing reports of a data breach that may have revealed sensitive user data. Rabbitude, a reverse engineering project for the Rabbit R1, is reporting it was able to gain access to the Rabbit codebase and found several hardcoded API keys in its codes.

The below isn’t an exhaustive list, but it allows anyone to do any of the following:

  • Read every response every R1 has ever given, including ones containing personal information
  • Brick all R1s
  • Alter the responses of all R1s
  • Replace every R1’s voice

The following services also had their API keys exposed:

  • ElevenLabs (for text-to-speech)
  • Azure (for an old speech-to-text system)
  • Yelp (for review lookups)
  • Google Maps (for location lookups)
The Settings page on the Rabbit R1.
Joe Maring / Digital Trends

Rabbitude notes that the API keys for Elevenlabs give full privileges. These include getting a history of all past text-to-speech messages, changing voices, adding custom text replacements, deleting voices, and crashing the rabbitOS backend, essentially bricking all Rabbit R1 devices. Rabbit did, however, revoke the Elevenlabs API key, which also broke Rabbit devices for a period of time.

This is a fairly worrying set of permissions to allow on any device, but it’s extra troubling when it’s for an always-on voice-activated AI gadget loaded with cameras. Rabbitude says it reached out to the Rabbit Team, which is aware of the leaked API keys, but they “have chosen to ignore it,” and the API keys continue to be valid as of this writing.

all rabbit r1 responses could be read by us for the past month and rabbit knew about it and did nothing to fix it.https://t.co/r6NmhZJY5W

— xyzeva (@xyz3va) June 25, 2024

Endgadget similarly reached out to the company and received confirmation that Rabbit is aware of the “alleged” data breach as of June 25. “Our security team immediately began investigating it,” the company said. “As of right now, we are not aware of any customer data being leaked or any compromise to our systems. If we learn of any other relevant information, we will provide an update once we have more details.”

As far as security failures go, this seems to be a fairly serious one. While the Rabbit R1 is a neat device, it’s also heavily flawed, and the security issues are sufficient enough that we recommend that you stop using it, at least for now. After all, there’s nothing your $199 Rabbit R1 (separate data plan required) can do that your smartphone can’t.

Ajay Kumar
Former Digital Trends Contributor
Ajay has worked in tech journalism for more than a decade as a reporter, analyst, and editor.
This is the worst smartphone camera I used in 2024, and it’s not even close
Promotional image for OuttaFocus. Photo of a collection of smartphone cameras.

I’ve already named my favorite camera phone of 2024, and the crown went to the fantastic Xiaomi 14 Ultra. The versatile Photography Kit makes it really special, and it has even replaced my DSLR several times when taking photos published on Digital Trends.

However, what about my worst camera phone of 2024? It turns out this was a much harder question to answer, but in the end, there could only be one.
So many phones have decent cameras
CMF Phone 1 Andy Boxall / Digital Trends

Read more
I tested Google Gemini and Apple Intelligence. Here’s which one you should use
Pixel Studio tools on a Pixel.

This year feels like a turning point for smartphones with all the new AI features being rolled out by Apple, Google, and basically every other tech company. I've been particularly intrigued by Apple Intelligence, which has introduced some promising new AI capabilities that will be rolled out to select devices over the coming months.

Google's Gemini AI system for the Pixel 9 Pro and other Android devices also shows promise and seems slightly further along than Apple's product. Both tools claim to make our lives easier and enhance our interaction with our devices when fully implemented.

Read more
The iPhone 18 may get a big redesign you won’t be able to see
The back of the Apple iPhone 16 Plus.

The design of the iPhone can only be described as iconic. That rectangular shape has been a major influence on phone aesthetics and design since the first iPhone came onto the market back in 2007, and that isn't likely to change. The internal design of the iPhone might radically shift, however. Apple is supposedly planning to change how the iPhone hardware is designed to accommodate better AI performance.

Essentially, Apple wants to use discrete memory rather than integrated memory. Those are technical terms that basically mean separate and together. On the internal system on a chip (SoC), any memory that is stacked on top is considered integrated memory. Discrete memory would be RAM that is packaged separately from the SoC. If reports are correct, Apple will begin using discrete memory in 2026, and the shift would result in faster memory and better AI performance, according to The Elec.

Read more