Sort of, but with caveats.
From The Verge:
> This week, we repeatedly watched live footage from two of our own Eufy cameras using that very same VLC media player, from across the United States — proving that Anker has a way to bypass encryption and access these supposedly secure cameras through the cloud.
Missing is how they connected "VLC can play a stream" to "Anker has a way to bypass encryption". The ability to open a stream in VLC does not automatically imply it is encryption-free.
> There is some good news: there’s no proof yet that this has been exploited in the wild, and the way we initially obtained the address required logging in with a username and password before Eufy’s website will cough up the encryption-free stream. (We’re not sharing the exact technique here.)
Things continue to be fuzzy and it's not clear what they believe "encryption-free" means. Since everyone is being understandably cautious about releasing the actual details, all of this is still frustratingly incomplete information.
On the LTT side, they went full rage mode in their coverage and it became difficult to take them seriously based on how they were discussing the thumbnail issue.
We desperately need an end-to-end review and summary from a reputable security person.