Researchers have developed a method to eavesdrop on wireless headphones from up to 30 meters away, and encryption offers no protection against it. The attack exploits hardware nonlinearity rather than software vulnerabilities, making it a fundamentally different class of threat.

What You Need to Know

The attack, presented at USENIX Security 2026, uses electromagnetic injection to induce side-channel leakage from the headphone's analog components. Because the signal is intercepted after decryption, even strong encryption cannot block the eavesdropping. The technique works at distances up to 30 meters and requires only off-the-shelf equipment. This affects virtually all wireless headphones that rely on Bluetooth or similar wireless protocols.

How the Attack Works

A team from Hong Kong University of Science and Technology in Guangzhou and Hong Kong Polytechnic University demonstrated the method in a paper titled "Injected and Leaked: Actively Inducing Side-Channel Leakage Using Electromagnetic Injection and Hardware Nonlinearity." The researchers send a carefully crafted electromagnetic signal toward the target headphone's internal circuitry. That injected signal interacts with the headphone's own audio processing hardware, causing the audio to leak through unintended electromagnetic radiation.

The leaked signal can then be captured by a receiver up to 30 meters away. The key insight is that the attack targets the analog domain after decryption, so the encryption layer has no effect on the leaked information. This side-channel approach bypasses all software-based protections.

  • Range: Attack works from up to 30 meters, allowing covert surveillance from outside a room.
  • Bypassed protections: Encryption and Bluetooth pairing are irrelevant because the leak occurs after audio is decoded.
  • Equipment: Researchers used standard electromagnetic injection tools and a software-defined radio receiver.

Why This Matters

This vulnerability represents a fundamental shift in how wireless audio privacy is understood. Users who rely on encryption for confidential phone calls, video conferences or personal voice recordings now face a threat that encryption cannot solve. The attack turns the headphone itself into an unintentional transmitter.

For businesses and governments, the implications are serious. Secure meeting rooms that ban phones but allow wireless headphones may still be vulnerable to remote eavesdropping. The researchers recommend hardware-level shielding and redesign of analog audio pathways to mitigate the leak. Until such fixes arrive, the only reliable defense is using wired headphones in sensitive environments.

Who Is at Risk

Virtually all wireless headphones are potentially affected because the attack exploits a fundamental property of analog electronics, not a specific software bug. The researchers tested several consumer headphone models and confirmed the attack worked on all of them. The technique does not require physical access to the target device, making it suitable for covert surveillance.

Users should be aware that common privacy measures such as turning off Bluetooth or using encrypted calling apps provide no protection. The electromagnetic injection hijacks the device's own hardware, making it an active beacon for the audio being played.