Headphones Lamps and Fans Leak Your Audio and Your Daily Routine to the InjectEave Radio Attack

Ethical Hacking Complete Course Zero to Expert
Hack like black hat hackers. Penetration testing, Kali Linux, WiFi and web hacking, and the hacker mindset behind it.
→ Take the full courseYour headphones handed your audio to an antenna 30 meters away, and through concrete to the room next door. Sony. Apple. Philips. HP. The owners did nothing wrong. A second tone read their lamp.
Five researchers in Guangzhou and Hong Kong pointed a radio antenna at eleven ordinary devices and took the audio home. Headphones with a cable and without, a desk phone, two smart fans and two smart lamps. They installed nothing and they touched nothing. The work was presented at USENIX Security 26 and the paper went online on 4 September 2026.
Sound in a headphone is a tiny electrical wave that wiggles between 20 and 20,000 times a second, and that is far too slow to leave a wire as a radio signal. Radio starts in the megahertz, millions of wiggles a second. That gap is why listening in on a headphone stayed a dead end for years. Two earlier attacks, MagEar and Periscope, sat and waited for whatever leaked out of the hardware by itself, and both ran out of signal somewhere between half a meter and a meter and a half. You had to stand close enough to read over the person’s shoulder.
InjectEave stops waiting and makes the leak itself. The attacker transmits one clean radio tone at the device, a steady hum at a single frequency with nothing in it, and that hum couples into the wiring. Inside sits a component that does not hand a signal back exactly as it came in. It bends it a little, and once two signals are bent together they mix. The audio and the hum come back out as one new signal that sits right beside the hum, up in the radio range, where the wiring radiates it into the room.
That bending has a name, nonlinearity, and it is printed in the spec sheet of the amplifier in your headset. Engineers treat it as a rounding error, listed as total harmonic distortion, 0.05 percent in one common audio amplifier chip. This attack runs on that rounding error.
They proved it on the workbench before they went near a product. An AD623 instrumentation amplifier got a sweep of tones up to 16 kHz with an 80 MHz hum laid over it, and handed the sweep straight back with its harmonics. An ADS1115 converter did the same, and it kept doing it when the hum ran faster than the chip can sample, so the mixing happens in the analog part at the front, before anything becomes a number.
A motor driver gave up the speed it was running, a mains rectifier gave up the 50 Hz from the wall socket, and a plain resistor in the same position leaked nothing at all. Without a part that bends the signal there is no attack.
The cable does the rest of the work. A headphone cord is a long piece of copper, and at radio frequencies it behaves as an antenna it was never designed to be. It catches the injected hum on the way in, and once the mixing has happened it carries the result back out into the room. First a receiving antenna, then a transmitting one.
Eleven setups, with the distance at which the attack still landed one time in six:
- โ
Sony ZX110APwired, on a Dell G5 laptop, 5 m - โ The same pair, on a MacBook Pro M2, 4 m
- โ
Apple EarPodswired, on an iPhone 15 Pro, 1 m - โ
UGreen MAX2wireless, 6 m, 8 m with better gear, 30 m with an amplifier - โ
Philips TAH2020wireless, 6 m - โ
HP H231Rwireless, 4 m - โ
Flyingvoice P23GWdesk phone, 3 m - โ
OIDIRE ODI-MF10Asmart fan, 6 m, 10 m with better gear - โ
Xiaomi BPLDS10DMsmart fan, 4 m - โ
JINGZAO JDO-06smart lamp, 3 m - โ
Xiaomi 1Ssmart lamp, 3 m, 5 m with better gear
Look at the first two lines of that list. It is one pair of headphones plugged into two different computers, and the leak changes with the machine behind them: 21.7 dB at half a meter on the laptop against 13.9 dB on the MacBook, with the injection frequency shifting along with it. So the table holds eleven rows but only ten products, because that Sony sits in there twice.
The news reports this week turned one of those rows into a headset brand, and they got that straight from the paper, which calls them three wired headphones from Sony, Dell and Apple in the body text while the table lists Dell as a laptop. The same headphones leak differently depending on what they hang off, and that is worth more than the headline.
The fans and the lamps are the half of this paper that got almost no attention, and they have no audio to give away at all. What a fan has is a speed. Its motor driver runs at a fixed beat per setting, 27 times a second on low, 40 on medium and 50 on high, and that beat comes back out on the injected hum the same way speech does. One of the two fans answered at 38.6 dB, the strongest signal in the table, and at half a meter it named its own setting correctly in 30 trials out of 30. Six meters is where that drops to five out of thirty.
The settings are called Sleep, Natural and Standard, and a fan running on that first setting at two in the morning says that somebody is home and in bed.
The lamps leak through their power converter. Turn a lamp up and it draws more current, more current changes the strength of what comes back, and that strength maps onto the fixed brightness steps the manufacturer built into the app. Twenty percent is the one they call reading. From the pavement, through a wall, with nothing installed anywhere in the house, somebody can work out whether you are asleep, awake or sitting up with a book. A burglar wants to know when your light goes out, and that is what the lamp tells him.
Finding the right hum is the actual work. They swept from 70 MHz up to 2 GHz to see where a device answers, and each model answers somewhere else.
Back to what you hear. At half a meter the recovery is clean: the UGreen set came back at 23.1 dB above the noise and the best of the wired sets at 21.7, and both came through in 30 trials out of 30. The profile carries over to other units as well. They tried two more copies of the same model and landed on the identical frequency, 942 MHz, with 23.2 to 24.6 dB, so an attacker who works out one set has the rest of that model for free.
The EarPods are the weakest entry at 5.9 dB and one meter, and even those came through in 29 trials out of 30. So yes, earbuds count, as long as there is a wire in them. True wireless buds that sit loose in your ear were not in the test set, and the paper makes no claim about them.
Back in January I wrote about the Airoha chips, millions of them, where an open factory protocol let someone within Bluetooth range clone a pair of headphones and reach the phone behind it. The advice at the bottom of that post was that a high value target should use a wired set. That was right for that attack, because the hole sat in the radio chip. It does not help you here. The wired set at the top of this list leaks at five meters and gave the second cleanest signal of the six headphone rows. The way out of one attack is not the way out of the next.
The equipment is nothing special:
- โ an
Ettus USRP B210software radio - โ a log-periodic antenna
- โ a spectrum analyser
- โ a laptop
They run it at 18 dBm, about what a home WiFi router puts out, and that reaches six meters. One amplifier bought on Alibaba for 415 dollars takes the output to 40 dBm, ten watts, roughly a hundred and fifty times more power, and the leak comes back stronger in step with it. That is the difference between six meters and thirty, with a clear line of sight.
Walls barely matter. Glass and wood cost 1 to 2 dB and change nothing about whether it works, while concrete costs 5.8 dB and drops the word recognition by three percent. Through a wall at normal listening volume, 65 dB, about 22 percent of the words come out wrong, with the signal sitting roughly 10 dB above the noise. In a separate test at half a meter with clear line of sight, they ran two minutes of recorded speech through a diffusion model they trained themselves, and it climbed from 7.0 to 16.1 dB with intelligibility going from 0.58 to 0.72. Enough to follow a conversation.
A busy room does not save you either. They ran the attack in an office with ceiling cameras, ceiling microphone arrays, central air conditioning and a pile of WiFi and BLE gear switched on, and that cost them 2.2 dB.
Then they took it out of the lab. A hotel room, someone on a video call with a wireless headset, and the listener sitting in the room next door, more than a meter away with 30 centimeters of concrete in between. What came back through that wall was a sentence about meeting outside 221B Baker Street at six the next day, word for word. They repeated it in a meeting room.
The desk phone is where it turns nasty, because there the attack runs in both directions. The listener stands in the corridor, 50 centimeters from a 20 centimeter office wall, injects at 880 MHz and picks up the voice coming out of the phone’s speaker. That audio feeds a voice cloning model called IndexTTS-2, which now has a sample of the person on the other end of the line. The system waits for a trigger word, something like quote or confirmation, then builds a fresh sentence in that same voice and injects it back into the phone on a 1075 MHz carrier at 40 dBm.
On the scale they use for how understandable speech is, the fake line came within 0.071 of the genuine one. Close enough to pass. The person holding the phone hears a sentence that was never said, in a voice they know, in the middle of a business call.
The attack works on what you say as well. They tried two desktop microphones, a UGreen CM769 and a Razer SEIREN V3 MINI, and both gave up their audio at about 30 centimeters. It stays that close because of the voltages. A microphone capsule puts out somewhere between 1 and 10 millivolts while a headphone driver swings 1 to 2 volts, a gap of 40 to 60 dB. Same mechanism, much smaller signal.
One detail says a lot about how far along this is. The researchers reported their findings to the manufacturers and got no answer, so they blanked the vulnerable injection frequencies out of their own results table and left the injection control logic out of the code they published. The frequency column is scrambled on purpose. The running text is not: 940 MHz for the wireless headphones, 480 MHz for the fan and 100 MHz for the lamp stand in section 4.3, 942 MHz in 4.2.1, and 880 and 1075 MHz in 5.2. Holding something back is harder than it looks.
This did not come out of nowhere. Two of the five authors worked on EM Eye in 2024, the attack that pulled the picture out of a built-in camera by listening to the noise coming off its image sensor. That one was passive: wait, listen and hope there is enough signal. Two years later the same people stopped waiting and started supplying the carrier themselves, and that is the difference between 1.5 meters and 30.
You can listen to it yourself. They put eleven demonstrations online, with the original audio next to what came out of the antenna, before and after the noise was cleaned up. The hotel room is there, the meeting room is there, and so is the landline where they talk back.
The defences are physical. They wired one speaker up both ways and measured it: two conductors running side by side gave 37.6 dB, and the same two twisted around each other dropped to 26.9. The twist makes each wire pick up the hum in opposite phase, so most of it cancels itself out. Shielding and filtering raise the bar further, and none of it is a guarantee. Sound is an analog wave, and you cannot scramble an analog wave the way you scramble a password. Scramble it and there is no sound left.
The attack belongs to electronics with an unshielded nonlinear analog interface, and that covers the amplifier in your headset, the converter in your phone, the driver in your fan and the power supply in your lamp. It is a property of the hardware, not a bug in one brand.
What this is worth to you:
- โ A wire only stops the Bluetooth attacks. This one goes straight through it
- โ Cheap parallel-conductor cables leak the most, twisted pair the least
- โ Anything with a motor or a dimmer broadcasts its state, and its state is your routine
- โ Your microphone leaks too, at arm’s length instead of across the street
- โ For a private conversation, distance from the outside wall is the control you have
- โ A voice on the line is not proof of who said it, and that now holds for the landline
Pulling audio off a cable takes a software radio, but a WiFi adapter in monitor mode shows you tonight what your own house is broadcasting.
My Ethical Hacking Complete Course Zero to Expert takes you there step by step: reconnaissance, scanning, exploitation and traffic analysis, hands-on, from your first day with no Linux or hacking background.
โ Join my complete ethical hacking course
Hacking is not a hobby but a way of life.
Sources:
Injected and Leaked, USENIX Security 26 | InjectEave project page | USENIX Security 26 presentation
Stay updated
Get the latest posts in your inbox every week. Ethical hacking, security news, tutorials, and everything that catches my attention. If that sounds useful, drop your email below.