Researchers have developed a method to eavesdrop on wireless headphones from up to 30 meters away, and encryption offers no protection against it. The attack exploits hardware nonlinearity rather than software vulnerabilities, making it a fundamentally different class of threat.
How the Attack Works
A team from Hong Kong University of Science and Technology in Guangzhou and Hong Kong Polytechnic University demonstrated the method in a paper titled "Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity." The researchers send a carefully crafted electromagnetic signal toward the target headphone's internal circuitry. That injected signal interacts with the headphone's own audio processing hardware, causing the audio to leak through unintended electromagnetic radiation.
The leaked signal can then be captured by a receiver up to 30 meters away. The key insight is that the attack targets the analog domain after decryption, so the encryption layer has no effect on the leaked information. This side-channel approach bypasses all software-based protections.
Why This Matters
This vulnerability represents a fundamental shift in how wireless audio privacy is understood. Users who rely on encryption for confidential phone calls, video conferences or personal voice recordings now face a threat that encryption cannot solve. The attack turns the headphone itself into an unintentional transmitter.
For businesses and governments, the implications are serious. Secure meeting rooms that ban phones but allow wireless headphones may still be vulnerable to remote eavesdropping. The researchers recommend hardware-level shielding and redesign of analog audio pathways to mitigate the leak. Until such fixes arrive, the only reliable defense is using wired headphones in sensitive environments.
Who Is at Risk
Virtually all wireless headphones are potentially affected because the attack exploits a fundamental property of analog electronics, not a specific software bug. The researchers tested several consumer headphone models and confirmed the attack worked on all of them. The technique does not require physical access to the target device, making it suitable for covert surveillance.
Users should be aware that common privacy measures such as turning off Bluetooth or using encrypted calling apps provide no protection. The electromagnetic injection hijacks the device's own hardware, making it an active beacon for the audio being played.



