R/8E3

Every air-gap exfiltration channel surveyed requires a receiver the attacker positions

A compilation of demonstrated exfiltration channels from air-gapped computers by physical emanation: electromagnetic, magnetic, acoustic, thermal, and conducted. Published rates, ranges, and receiver requirements are recorded from the primary papers. A separate section records passive eavesdropping results that achieve greater range without an implant, which the headline finding does not cover.

part one

Scope and definitions

An exfiltration channel here means a channel an attacker drives: software running on the air-gapped machine modulates a physical emanation to encode chosen data. This requires prior compromise of the machine and excludes passive interception of emanations the machine produces incidentally. The distinction is load-bearing for the finding below, and results of the second kind are recorded separately in part four.

A receiver requirement is recorded as the reception apparatus the published evaluation used and the distance at which the reported rate was achieved. Where the apparatus is a commodity device carrying attacker software, that is noted, because it changes what an attacker must accomplish beyond compromising the target.

Fourteen channels are compiled. The corpus is dominated by one research group at Ben-Gurion University of the Negev; that concentration is a property of the literature rather than of the selection here, and one published survey and one retrospective are included to bound it.13,14

The compiled channels

table 1
Demonstrated exfiltration channels by physical medium, with published rate, range, and reception apparatus. Figures are as stated in the cited paper; entries marked not stated were not quantified in the source consulted.
ChannelMediumRateRangeReception apparatus
AirHopper (2014)FM radio, display cable104–480 bit/s1–7 minfected mobile phone, FM receiver
BitWhisper (2015)thermal1–8 bit/hour0–40 cmsecond infected computer, onboard sensors
GSMem (2015)EM, cellular band1–2 bit/s1–5.5 m; 30 m+phone with compromised baseband firmware
Fansmitter (2016)acoustic, fan noise0.25 bit/s0–8 mmicrophone
DiskFiltration (2017)acoustic, drive actuator3 bit/s2 mmicrophone
aIR-Jumper (2017)infrared20 bit/s outboundtens of metresthe site’s own surveillance cameras
MAGNETO (2018)magnetic, low frequencyunder 5 bit/s12.5 cmphone magnetometer, attacker app
ODINI (2018)magnetic, low frequency1–40 bit/s10–150 cmplaced magnetometer bug
PowerHammer (2018)conducted, AC power line10–1000 bit/stap point, not distancecurrent tap at outlet or service panel
LANtenna (2021)EM, Ethernet cablenot stated“several metres”software-defined radio
RAMBO (2024)EM, memory bus1000 bit/sup to 7 msoftware-defined radio, antenna
PIXHELL (2024)acoustic, display coil whinenot stated2 mmicrophone
SmartAttack (2025)ultrasonic, 18–22 kHznot statednot statedcompromised smartwatch, worn on site

Rates span roughly five orders of magnitude, from one bit per hour to one kilobit per second, and are inversely related to range within each medium. Magnetic channels achieve the shortest ranges and penetrate Faraday shielding, which electromagnetic channels do not; the MAGNETO evaluation was conducted with the receiving phone inside a shielding bag and in airplane mode.5 Acoustic channels are the only family that degrades with ambient noise rather than with distance alone.

Two entries are structurally distinct from the rest. PowerHammer is conducted rather than radiated, so its receiver is a current tap rather than an antenna, and its phase-level variant taps the building’s electrical service panel rather than a nearby outlet.9 aIR-Jumper uses the target site’s own surveillance cameras as the transmitting and receiving element, so no apparatus is planted by the attacker, though the cameras must be reachable.6

part two

Reception requirements

Every channel in table 1 requires reception apparatus positioned by the attacker, and in eight of the thirteen that apparatus must itself be compromised or attacker-supplied rather than merely present.

GSMem carries the strongest such dependency: reception requires a rootkit implanted in the baseband firmware of a nearby cellular phone, so an uncompromised phone in the same room receives nothing.3 AirHopper and SmartAttack likewise require malware on the receiving device, a phone and a worn smartwatch respectively.1,12 MAGNETO requires an application installed on the receiving phone, though notably one needing neither root nor unusual permissions.5 BitWhisper requires the receiver to be a second compromised computer physically adjacent to the first, making it the only channel in the compilation whose receiver is itself an air-gapped machine.2

The remaining channels use uncompromised commodity apparatus, but apparatus the attacker must place: a software-defined radio for RAMBO and LANtenna, a magnetometer bug for ODINI, a current tap for PowerHammer, a microphone for the acoustic family.7,8,9,10,11

Ranges

Reported ranges fall between 12.5 cm and roughly 30 m. The upper figure belongs to GSMem with dedicated receiving hardware rather than a phone; with a phone the same channel reports 1 to 5.5 m.3 No channel in table 1 reports a demonstrated range beyond tens of metres, and the two entries that reach that upper bound do so with purpose-built or pre-existing on-site apparatus rather than with a device carried past the building.

part three

Passive eavesdropping results, which the finding does not cover

A separate literature demonstrates reconstruction of information from emanations the machine produces without any attacker software on it. These are not exfiltration channels under the definition in part one, because the attacker does not choose what is transmitted, and they are recorded here because they bound the finding above.

Van Eck, in 1985, reported reconstruction of video display unit contents “at several hundreds of meters distance, using only a normal black-and-white TV receiver, a directional antenna and an antenna amplifier.”15 No implant on the target is required, and the range exceeds every entry in table 1 by two orders of magnitude. Kuhn later demonstrated optical reconstruction of CRT contents from diffuse reflection, without line of sight to the screen.16 Deep-TEMPEST applies deep learning to HDMI emanations and reports a character error rate improvement of more than sixty percentage points over prior work, again with no software on the target.17

Two further results narrow the gap from the other direction. Screaming Channels recovers a full AES-128 key at 10 m by having the target device’s own legitimate radio transmitter re-broadcast digital side-channel leakage, extending electromagnetic side-channel range from centimetres to more than ten metres with a commodity receiver.18 EM Eye reconstructs image streams from embedded camera emissions at over 2 m through a wall.19 Retroreflector work moves the receiver further still by illuminating a passive hardware implant, trading a planted receiver for a planted implant.20

Finding

Across the thirteen exfiltration channels compiled in table 1, every one requires reception apparatus the attacker positions, within a range no evaluation reports beyond tens of metres, and in eight cases that apparatus must additionally be compromised. No surveyed exfiltration channel operates at a distance an attacker can reach without physical access to the site or to a device carried into it.

This finding is bounded to the definition in part one. It does not extend to passive interception, where the results in part three demonstrate reconstruction at several hundred metres with no implant of any kind, and it does not address what an adversary with physical access can accomplish.


related
P/2F9
wiregap
Preventing a compromised agent from causing execution beyond its boundary, by capability absence rather than by inspection. Not a confidentiality mechanism.
E/71B
The safe envelope for an AI agent must narrow as its capability grows
Deployment patterns widen an agent’s reach as it improves, assuming capability and trustworthiness rise together. On why that is backwards, and on the containment that buying an agent maximum flexibility actually costs.

sources

Primary papers where available, preprint where the published venue is paywalled. Entries 15 to 20 are the passive eavesdropping literature recorded in part three.

1
Guri, M., Kedma, G., Kachlon, A. & Elovici, Y. AirHopper: Bridging the Air-Gap between Isolated Networks and Mobile Phones using Radio Frequencies
IEEE MALWARE, 2014 · arxiv.org/abs/1411.0237
2
Guri, M., Monitz, M., Mirsky, Y. & Elovici, Y. BitWhisper: Covert Signaling Channel between Air-Gapped Computers using Thermal Manipulations
IEEE CSF, 2015 · arxiv.org/abs/1503.07919
3
Guri, M., Kachlon, A., Hasson, O., Kedma, G., Mirsky, Y. & Elovici, Y. GSMem: Data Exfiltration from Air-Gapped Computers over GSM Frequencies
4
Guri, M., Solewicz, Y., Daidakulov, A. & Elovici, Y. Fansmitter: Acoustic Data Exfiltration from Speakerless Air-Gapped Computers
Computers & Security 91, 2020 · arxiv.org/abs/1606.05915
5
Guri, M., Daidakulov, A. & Elovici, Y. MAGNETO: Covert Channel between Air-Gapped Systems and Nearby Smartphones via CPU-Generated Magnetic Fields
Future Generation Computer Systems, 2021 · arxiv.org/abs/1802.02317
6
Guri, M., Bykhovsky, D. & Elovici, Y. aIR-Jumper: Covert Air-Gap Exfiltration and Infiltration via Security Cameras and Infrared
Computers & Security, 2019 · arxiv.org/abs/1709.05742
7
Guri, M., Solewicz, Y., Daidakulov, A. & Elovici, Y. DiskFiltration: Acoustic Data Exfiltration from Speakerless Air-Gapped Computers via Covert Hard-Drive Noise
ESORICS, 2017 · arxiv.org/abs/1608.03431
8
Guri, M., Zadov, B., Daidakulov, A. & Elovici, Y. ODINI: Escaping Sensitive Data from Faraday-Caged, Air-Gapped Computers via Magnetic Fields
IEEE Trans. Information Forensics and Security, 2020 · arxiv.org/abs/1802.02700
9
Guri, M., Zadov, B., Bykhovsky, D. & Elovici, Y. PowerHammer: Exfiltrating Data from Air-Gapped Computers through Power Lines
IEEE Trans. Information Forensics and Security, 2020 · arxiv.org/abs/1804.04014
10
Guri, M. LANTENNA: Exfiltrating Data from Air-Gapped Networks via Ethernet Cables
IEEE COMPSAC, 2021 · arxiv.org/abs/2110.00104
11
Guri, M. RAMBO: Leaking Secrets from Air-Gap Computers by Spelling Covert Radio Signals from Computer RAM
preprint, 2024 · arxiv.org/abs/2409.02292
12
Guri, M. SmartAttack: Air-Gap Attack via Smartwatches
IEEE COMPSAC, 2025 · arxiv.org/abs/2506.08866
13
Park, J., Yoo, J., Yu, J., Lee, J. & Song, J. A Survey on Air-Gap Attacks: Fundamentals, Transport Means, Attack Scenarios and Challenges
Sensors 23(6), 2023 · www.mdpi.com/1424-8220/23/6/3215
14
Guri, M. & Elovici, Y. Bridgeware: the air-gap malware
Communications of the ACM 61(4), 2018 · doi.org/10.1145/3177230
15
van Eck, W. Electromagnetic radiation from video display units: An eavesdropping risk?
Computers & Security 4(4), 1985 · www.tscm.com/vaneck85.pdf
16
Kuhn, M. G. Optical Time-Domain Eavesdropping Risks of CRT Displays
IEEE Symposium on Security and Privacy, 2002 · www.cl.cam.ac.uk/research/security/posters/2002-mgk25-optical.pdf
17
Fernández, S., Martínez, E., Varela, G., Musé, P. & Larroca, F. Deep-TEMPEST: Using Deep Learning to Eavesdrop on HDMI from its Unintended Electromagnetic Emanations
preprint, 2024 · arxiv.org/abs/2407.09717
18
Camurati, G., Poeplau, S., Muench, M., Hayes, T. & Francillon, A. Screaming Channels: When Electromagnetic Side Channels Meet Radio Transceivers
19
Long, Y., Jiang, Q. et al. EM Eye: Characterizing Electromagnetic Side-channel Eavesdropping on Embedded Cameras
20
Granier, P., Davy, M., Besnier, P. & Sarrazin, F. Reflecthernet: Exfiltrating 100BASE-TX Ethernet Traffic Using a Retroreflector Hardware Trojan
preprint, 2026 · arxiv.org/abs/2605.02702