Researchers Discover a Technique to Eavesdrop on Headphones From 30 Meters Away

A team of researchers in China has pulled off something that sounds like a plot point from a spy thriller: they’ve found a way to listen in on what someone is hearing through their headphones from up to 30 meters away — even through walls — and no amount of encryption can stop it.

The method, dubbed InjectEave, comes from academics at the Hong Kong University of Science and Technology (Guangzhou) and the Hong Kong Polytechnic University. It was detailed in a paper presented at the USENIX Security 2026 conference and targets the analog guts of everyday audio gear rather than any software vulnerability.

Yan Long, an assistant professor at HKUST Guangzhou and one of the lead researchers, put it plainly: “Our new project, InjectEave, shows that RF signals can induce information leakage from everyday headphones, allowing an attacker to recover headphone audio from up to 30 meters away, including through walls. We have verified the new vulnerability on multiple commercial devices including devices from Sony, HP, Philips, etc.”

Here’s how it works.

An attacker beams a low-frequency radio signal (somewhere in the 0–9 MHz range) at the target device. Nonlinear parts inside the headphones or the device driving them — amplifiers, converters, that sort of thing — mix the internal audio with the incoming signal. The mixed signal then radiates back out through the wiring or cable, where the attacker picks it up with standard radio gear and demodulates it. Because the leak happens after the audio has already been decoded into analog form, digital protections like end-to-end encryption simply don’t matter.

The team tested the attack on 11 off-the-shelf products with zero physical access or modifications. Among them: Sony ZX110AP wired headphones, Apple’s classic wired earbuds, wireless models from UGreen, Philips and HP, a VoIP landline phone, and even a few smart home fans and lamps. With basic lab equipment they pulled intelligible audio from most devices at 1 to 6 meters, including through interior walls and a thick concrete barrier. Add a roughly $400 RF amplifier and the range jumps to 30 meters for some of the wireless headphones while still delivering understandable speech.

They didn’t stop at the lab. In hotel-room and meeting-room case studies the researchers recovered spoken bank-card PINs, transfer amounts and business details through walls. In one particularly unsettling demo involving a landline phone, they eavesdropped in real time, synthesized a fake response in the speaker’s own voice, and injected it back into the call — flipping an agreement into a disagreement without either party realizing what had happened.

Smart fans and lamps weren’t spared either. By listening to their control signals or power draw, an attacker can figure out whether someone is home, sleeping, or just dimming the lights for movie night.

The full 30-meter range does require continuous higher-power transmission and isn’t exactly subtle. Real-world performance also depends on the environment and some post-processing to clean up the distorted audio. Still, the core point stands: this is a hardware problem, not a software one. Better shielding and filtering can make the attack harder, but they don’t make it impossible.

For anyone who spends hours a day with headphones on — whether it’s new album deep-dives, private calls, or just zoning out on the commute — the research is a reminder that the devices we trust to keep our listening private can still leak in ways that have nothing to do with the apps or the cloud. The full paper, audio demos and project materials are available online for those who want to hear the recovered samples for themselves.

Latest Posts

[democracy id="16"] [wp-shopify type="products" limit="5"]