Researchers can make headphones leak audio through a wall, but the 30-meter claim has a few caveats
HKUST (Guangzhou) and HK PolyU researchers' InjectEave beams a radio carrier at devices so their own circuits leak analog audio The leaked audio has already been decrypted by the device itself, making encryption offer no protection against such an approach The 30m headline needed a pricey amplifier pushing output to 10 W, while standard ranges of 1 to 6m were measured by detecting a test tone Researchers at the Hong Kong University of Science and Technology and the Hong Kong Polytechnic University have shown that everyday headphones, a desk phone, and a handful of smart-home gadgets can broadcast what they are doing simply by using a radio signal.
The technique, called InjectEave , was presented at USENIX Security 2026 in Baltimore, and multiple outlets have since covered the researcher's claim that the attack "can recover headphone audio from up to 30 meters away, including through walls".
The claim may be accurate, but it has limitations, including the need for specialized equipment that is often very noticeable in most settings.
An impressive technical show with plenty of limitations in tow Conventional electromagnetic eavesdropping waits for a device to leak.
That works poorly for audio, because speech sits below 20 kHz while a device's wiring radiates efficiently only at megahertz or gigahertz frequencies.
InjectEave chooses to close the gap by transmitting a carrier signal at the target.
According to the paper , nonlinear components such as amplifiers, analog-to-digital converters, switching MOSFETs, and power converters mix the secret signal onto that carrier, and the device's own traces and cables radiate the result back to a receiver.
Because the leak happens in the analog path, after audio has been decoded, the project page states that "InjectEave is immune to digital defenses such as encryption, masking, and randomization." Encryption in any form on a wireless headset is irrelevant, since the attack directly targets the signal driving the speaker, not the radio link.
The team demonstrating this used a USRP B210 software-defined radio, two antennas, a Siglent spectrum analyzer, and a laptop to set up their proof of concept, which could, as they noted, "eavesdrop on the majority of these devices from over 2m away and through walls, with a maximum distance of 30m for recovering intelligible headphone audio".
This isn't the first time the technique has been used, even as the researchers have built on it considerably; the idea originates from "The Thing ," a Soviet bug given as a gift to the US ambassador in Moscow in 1945, which was passively powered remotely as a listening device.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.techradar.com — the content belongs to TechRadar.