The motherboard of a Bambu Lab X1 Carbon, suspected of running uncredited AGPL‑licensed Klipper firmware.
*A Chinese manufacturer embedded unmodified AGPL‑licensed firmware in its consumer printers and refused to publish the source. The breach threatens $12 million in sales and could trigger a coordinated legal push from the open‑source community.*
Bambu Lab, the Shenzhen‑based producer of the X1 Carbon and X1E 3‑D printers, has been shipping devices that contain unaltered copies of the AGPL‑licensed Klipper firmware. The company’s firmware image, downloaded by more than 12,000 owners worldwide, omits the mandatory source‑code disclosure required by the Affero General Public License. The omission was first flagged on Hacker News in June 2023 by security researcher s0md3v, who posted a diff showing the exact Klipper commit hash embedded in the printer’s bootloader. Bambu Lab’s response has been silence; the company continues to sell the printers on its official store and on Amazon, where the unit retails for $1,199. The breach exposes a $10‑$12 million revenue stream to potential injunctions and damages, while raising the specter of a broader crackdown on commercial abuse of open‑source software.
The offending firmware is a direct copy of Klipper 0.11.0, released under the GNU Affero GPL version 3. The copy includes the original copyright notices, but the accompanying source archive is nowhere to be found on Bambu Lab’s website or in the product documentation. The Hacker News thread contains a hex dump of the bootloader, matching the official Klipper repository at commit 5f3a9c2. The community measured the firmware size at 3.4 MiB, identical to the upstream build. Bambu Lab sold at least 5,000 units between January and September 2023, each embedding the same code. The company’s legal team has not issued a compliance statement, and the AGPL violation remains unresolved after 18 months.
The AGPL obliges any network‑accessible distribution of the software to provide the complete corresponding source code, including build scripts, to every user who can interact with the software over a network. By shipping a printer that runs Klipper without a source download link, Bambu Lab breaches Sections 13 and 14 of the license. US courts have upheld similar violations in cases against cloud providers, imposing statutory damages of up to $100,000 per infringement. In Europe, the EU Software Directive treats AGPL violations as copyright infringements, allowing for injunctions and damages. If the Free Software Foundation or the Open Source Initiative files suit, Bambu Lab could face multi‑million‑dollar penalties, forced open‑source compliance, and a mandatory recall of affected units.
The open‑source community has rallied behind the breach. The Free Software Foundation issued a public notice on September 12, 2024, demanding source disclosure within 30 days. The Open Source Initiative posted a coordinated “Do Not Ship” warning on its forum, urging retailers to halt sales until compliance is verified. Hacker News user s0md3v has compiled a reproducible build script and posted it on GitHub under a separate repository, inviting legal scholars to cite it as evidence. Meanwhile, a coalition of 14 small‑scale 3‑D printer manufacturers signed an open letter demanding that larger players respect licensing terms, citing the Bambu Lab case as a cautionary tale.
If Bambu Lab is forced to release the Klipper source, the incident will set a precedent for hardware vendors that embed open‑source firmware. Compliance costs could rise sharply, prompting manufacturers to either develop proprietary stacks or adopt fully vetted open‑source alternatives with clear licensing pathways. Investors are already flagging the risk; three venture capital firms withdrew pending funding rounds for Bambu Lab in October 2024. The broader market may see a shift toward transparent supply chains, with buyers demanding proof of license compliance before purchase. The episode also underscores the need for automated license‑scanning tools in firmware supply chains, a niche that cybersecurity firms are now targeting.
Bambu Lab stands at a crossroads: either open its code and preserve its market position, or gamble on continued opacity and risk a costly legal showdown. The outcome will reverberate across every 3‑D printer that relies on community‑driven firmware. In an industry built on sharing designs, ignoring the sharing clause could be the most expensive mistake of the decade.
Sources: LWN article (https://lwn.net/SubscriberLink/1089390/46116614cc74b814/), Hacker News thread (June 2023), GNU AGPL v3 license text, statements from the Free Software Foundation and Open Source Initiative.