Your Headphones Can Be Spied On From 30 Meters Away, and Encryption Won’t Help

Researchers exploit analog hardware flaws in 11 consumer devices to capture audio from 30 meters, bypassing all encryption

Al Landes Avatar
Al Landes Avatar

By

Image: Deposit Photos

Key Takeaways

Key Takeaways

  • InjectEave recovers headphone audio through walls from up to 30 meters away.
  • Encryption cannot block InjectEave because leakage occurs on the analog signal path.
  • A $400 RF amplifier extends the attack range, threatening boardrooms and law offices.

Your headphones just became a radio transmitter. Researchers from Hong Kong University of Science and Technology (Guangzhou) and Hong Kong Polytechnic University have demonstrated InjectEave, an attack that recovers audio from consumer headphones at distances up to 30 meters, through walls, using commercially available radio equipment. The work appears at USENIX Security 2026, and the hardware required costs less than a decent pair of noise-canceling headphones.

How a Headphone Amp Becomes a Spy

InjectEave aims a radio-frequency carrier at a target device, and the device’s own analog components do the rest of the work.

The attack exploits nonlinear components inside everyday electronics, including headphone amplifiers, analog-to-digital converters, and power converters, that unintentionally mix an injected RF signal with whatever audio is playing internally. Think of it as accidental AM radio: the device briefly becomes a tiny, unlicensed transmitter. It broadcasts your conversation on a frequency a nearby receiver can tune in and decode. A surveillance app picks up that re-radiated signal and reconstructs the audio.

The Part Where Encryption Becomes Irrelevant

Secure apps and encrypted calls cannot protect audio that must exist in analog form inside the device before you can hear it.

The research team states it plainly in the USENIX paper: “InjectEave is immune to digital defenses such as encryption, masking, and randomization, because the leakage comes from the analog path.” Your Signal call, your encrypted VoIP line, your end-to-end everything: none of that matters once audio has been converted to an electrical signal driving a headphone driver. That analog moment is where InjectEave operates, and encryption has no jurisdiction there. Apps caught secretly tracking users demonstrate how thoroughly digital protections can be bypassed at the hardware and analog layer.

Distances, Devices, and a $400 Amplifier

Entry-level radio gear produced intelligible audio through interior walls at up to 6 meters; a low-cost amplifier pushed that to 30.

The researchers tested 11 products, including the Sony ZX110AP, Apple wired earbuds, UGreen MAX2, Philips TAH2020, HP H231R, the Flyingvoice P23GW VoIP phone, and smart-home devices from Xiaomi, Oidire, and Jingzao. At roughly 18 dBm of transmit power from a USRP B210 software-defined radio, the team recovered intelligible audio at 1 to 6 meters through interior walls. A roughly $400 RF power amplifier boosted output to around 40 dBm, pushing effective range to 30 meters through walls for devices including the UGreen MAX2 and Philips TAH2020.

Who Actually Needs to Pay Attention

Hotel corridors, shared office buildings, and multi-tenant spaces put confidential conversations within practical attack range.

Lead researcher Yan Long told The Register: “Our new project, InjectEave, shows that RF signals can induce information leakage from everyday headphones, allowing an attacker to recover headphone audio from up to 30 meters away, including through walls.” Boardrooms, law offices, and healthcare facilities that depend on encrypted communications remain physically vulnerable if an attacker with suitable RF gear can reach proximity. An adjacent hotel room or a shared building floor is well within that envelope.

Real Constraints, Partial Fixes

Hardware mitigations can reduce risk, but none of them eliminate it entirely.

Executing InjectEave requires RF expertise, device-specific calibration, and physical proximity, which makes it a targeted threat rather than a mass-scale exploit. The researchers identify hardware-level mitigations, including improved EM shielding, RF filtering on signal paths, and twisted-pair wiring for headphone leads, though they caution these measures reduce attack feasibility rather than guarantee protection. Understanding broader USB Charger Risks offers a complementary perspective on how hardware-level RF and signal vulnerabilities can be partially addressed. High-power transmissions also risk running into spectrum regulations depending on jurisdiction.

As software-defined radio platforms get cheaper and more capable, the barrier to sophisticated RF attacks keeps falling. If “encrypted” still reads to you as a complete privacy guarantee, InjectEave is a firm reminder that the analog world was never covered by that promise.

Share this

At Gadget Review, our guides, reviews, and news are driven by thorough human expertise and use our Trust Rating system and the True Score. AI assists in refining our editorial process, ensuring that every article is engaging, clear and succinct. See how we write our content here →