The garage is becoming a robot’s workspace, and that changes vehicle security. Robotic pit stops that service self-driving cars and teleoperation consoles that let humans steer robots from miles away are arriving with the next wave of autonomous vehicle startups, and both stretch the attack surface of the road in new directions.
A compromised charging arm or a hijacked teleoperation session is no longer a data breach, it is a physical safety risk. When a machine controls the vehicle, whoever controls the machine effectively controls the vehicle. That reality is now shaping how investors look at the autonomy supply chain, and it is the lens through which a new wave of automotive security research is being funded.
Robinhood is placing a broad bet on that supply chain. Robinhood Ventures Fund II, the trading platform’s second venture vehicle, holds 80 portfolio companies and writes $250K SAFE investments with a heavy Y Combinator focus. The fund begins trading on the NYSE on August 13 under the ticker RVII.
Among the fund’s automotive plays is Aseon Labs, which is building robotic pit stops for self-driving cars. The startup’s automated service bays are designed to charge, clean, and swap tires on autonomous fleets without a human crew on site. For fleet operators, that promises lower downtime and predictable maintenance. For security teams, it introduces a new physical-digital boundary: the bay’s control network becomes a trusted point of contact with the vehicle, and a compromise there could reach far beyond a single car. Servicing robots that plug into onboard networks for diagnostics or firmware updates are, in effect, gaining privileged access to every vehicle they touch, which makes the pit stop a chokepoint worth defending as carefully as the vehicle itself. A bad software update pushed through a compromised bay could, in theory, propagate across an entire fleet overnight.
Avea Robotics takes the opposite approach to the same problem. The company builds human-in-the-loop teleoperation for robots, letting remote operators take over when autonomy hits an edge case it cannot resolve on its own. That makes the teleoperation link a critical security surface: the wireless channel between operator and machine can be jammed, spoofed, or hijacked, turning a remote assistant into a remote attacker. Authentication, encryption, and session integrity are not optional extras here, they are the difference between a useful safety net and a wide-open door into the vehicle. Teleoperation also raises accountability questions, since a single remote session can span multiple vehicles and jurisdictions, and every one of those sessions is a potential entry point if the operator platform itself is breached. Even the human factor cuts both ways, because a remote operator who cannot verify what the robot is seeing is making split-second safety decisions on partial information.
Both companies sit in the infrastructure layer of autonomy, the parts of the ecosystem that rarely make headlines but control physical outcomes. Charging stations, maintenance robots, and teleoperation consoles are all becoming network-connected endpoints, which means they are all becoming targets. The same pattern that played out across connected vehicles over the past decade is now repeating in the machinery that services them, and regulators are only beginning to catch up. The security case for the autonomous vehicle was always about the software in the car; the next chapter is about the software in the world around the car, where a single unpatched endpoint can hand an attacker physical influence over traffic.
With 80 holdings and a YC-heavy roster, Robinhood Fund II is signaling where the agent economy meets the road. Autonomous vehicle startups were already a crowded field; the newer bets are on the robots that fix, fuel, and supervise the fleet. For vehicle security researchers, that is the next frontier, and this time it is being funded at $250K a ticket.