Airgap Reversed: Commodity Embedded Devices Turned Into RF Receivers at 100 kbps
chaumian · x · 2026-09-18
- Researchers Paul Staat, Daniel Davidovich, and Christof Paar published a paper demonstrating wireless infiltration of air-gapped systems: where prior EM side-channel work exfiltrated data, this attack goes the reverse direction and gives attackers command-and-control.
- The technique exploits parasitic RF sensitivity in PCB traces and on-chip ADCs, turning commodity embedded devices into inadvertent radio receivers — no dedicated sensors (microphones, LEDs, temperature sensors) needed, and it works in non-line-of-sight scenarios.
- They evaluated 12 commercial embedded devices plus 2 custom prototypes; all exhibited reception capabilities in the 300-1000 MHz range. An ordinary microcontroller evaluation board reliably recovered signals from tens of meters at up to 100 kbps.
More from Safety
- Hackers say they took over OpenAI employee ChatGPT accounts in under 72 hours via two bugs — nptacek · 2026-09-18
- A CTF framing via /goal was all it took to bypass Claude Opus's guardrails — xeophon · 2026-09-18
- Halvar Flake: Useful AI Side Channels Face Real Information-Theoretic and Physical Limits — basedjensen · 2026-09-18
- AI safety researcher pushes back on claims that side-channel attacks make air-gapped networks insufficient — BlancheMinerva · 2026-09-18
- Geoffrey Irving: air gaps may matter someday but are laughably far from AI companies' current security — geoffreyirving · 2026-09-18
- Debate: An Exponentially Growing API-Token-Stealing Replicator Swarm May Scare More Than Weight Exfiltration — cis_female · 2026-09-18