
Every air-gap exfiltration channel surveyed requires a receiver the attacker positions
Scope and definitions
An exfiltration channel here means a channel an attacker drives: software running on the air-gapped machine modulates a physical emanation to encode chosen data. This requires prior compromise of the machine and excludes passive interception of emanations the machine produces incidentally. The distinction is load-bearing for the finding below, and results of the second kind are recorded separately in part four.
A receiver requirement is recorded as the reception apparatus the published evaluation used and the distance at which the reported rate was achieved. Where the apparatus is a commodity device carrying attacker software, that is noted, because it changes what an attacker must accomplish beyond compromising the target.
Fourteen channels are compiled. The corpus is dominated by one research group at Ben-Gurion University of the Negev; that concentration is a property of the literature rather than of the selection here, and one published survey and one retrospective are included to bound it.13,14
The compiled channels
| Channel | Medium | Rate | Range | Reception apparatus |
|---|---|---|---|---|
| AirHopper (2014) | FM radio, display cable | 104–480 bit/s | 1–7 m | infected mobile phone, FM receiver |
| BitWhisper (2015) | thermal | 1–8 bit/hour | 0–40 cm | second infected computer, onboard sensors |
| GSMem (2015) | EM, cellular band | 1–2 bit/s | 1–5.5 m; 30 m+ | phone with compromised baseband firmware |
| Fansmitter (2016) | acoustic, fan noise | 0.25 bit/s | 0–8 m | microphone |
| DiskFiltration (2017) | acoustic, drive actuator | 3 bit/s | 2 m | microphone |
| aIR-Jumper (2017) | infrared | 20 bit/s outbound | tens of metres | the site’s own surveillance cameras |
| MAGNETO (2018) | magnetic, low frequency | under 5 bit/s | 12.5 cm | phone magnetometer, attacker app |
| ODINI (2018) | magnetic, low frequency | 1–40 bit/s | 10–150 cm | placed magnetometer bug |
| PowerHammer (2018) | conducted, AC power line | 10–1000 bit/s | tap point, not distance | current tap at outlet or service panel |
| LANtenna (2021) | EM, Ethernet cable | not stated | “several metres” | software-defined radio |
| RAMBO (2024) | EM, memory bus | 1000 bit/s | up to 7 m | software-defined radio, antenna |
| PIXHELL (2024) | acoustic, display coil whine | not stated | 2 m | microphone |
| SmartAttack (2025) | ultrasonic, 18–22 kHz | not stated | not stated | compromised smartwatch, worn on site |
Rates span roughly five orders of magnitude, from one bit per hour to one kilobit per second, and are inversely related to range within each medium. Magnetic channels achieve the shortest ranges and penetrate Faraday shielding, which electromagnetic channels do not; the MAGNETO evaluation was conducted with the receiving phone inside a shielding bag and in airplane mode.5 Acoustic channels are the only family that degrades with ambient noise rather than with distance alone.
Two entries are structurally distinct from the rest. PowerHammer is conducted rather than radiated, so its receiver is a current tap rather than an antenna, and its phase-level variant taps the building’s electrical service panel rather than a nearby outlet.9 aIR-Jumper uses the target site’s own surveillance cameras as the transmitting and receiving element, so no apparatus is planted by the attacker, though the cameras must be reachable.6
Reception requirements
Every channel in table 1 requires reception apparatus positioned by the attacker, and in eight of the thirteen that apparatus must itself be compromised or attacker-supplied rather than merely present.
GSMem carries the strongest such dependency: reception requires a rootkit implanted in the baseband firmware of a nearby cellular phone, so an uncompromised phone in the same room receives nothing.3 AirHopper and SmartAttack likewise require malware on the receiving device, a phone and a worn smartwatch respectively.1,12 MAGNETO requires an application installed on the receiving phone, though notably one needing neither root nor unusual permissions.5 BitWhisper requires the receiver to be a second compromised computer physically adjacent to the first, making it the only channel in the compilation whose receiver is itself an air-gapped machine.2
The remaining channels use uncompromised commodity apparatus, but apparatus the attacker must place: a software-defined radio for RAMBO and LANtenna, a magnetometer bug for ODINI, a current tap for PowerHammer, a microphone for the acoustic family.7,8,9,10,11
Ranges
Reported ranges fall between 12.5 cm and roughly 30 m. The upper figure belongs to GSMem with dedicated receiving hardware rather than a phone; with a phone the same channel reports 1 to 5.5 m.3 No channel in table 1 reports a demonstrated range beyond tens of metres, and the two entries that reach that upper bound do so with purpose-built or pre-existing on-site apparatus rather than with a device carried past the building.
Passive eavesdropping results, which the finding does not cover
A separate literature demonstrates reconstruction of information from emanations the machine produces without any attacker software on it. These are not exfiltration channels under the definition in part one, because the attacker does not choose what is transmitted, and they are recorded here because they bound the finding above.
Van Eck, in 1985, reported reconstruction of video display unit contents “at several hundreds of meters distance, using only a normal black-and-white TV receiver, a directional antenna and an antenna amplifier.”15 No implant on the target is required, and the range exceeds every entry in table 1 by two orders of magnitude. Kuhn later demonstrated optical reconstruction of CRT contents from diffuse reflection, without line of sight to the screen.16 Deep-TEMPEST applies deep learning to HDMI emanations and reports a character error rate improvement of more than sixty percentage points over prior work, again with no software on the target.17
Two further results narrow the gap from the other direction. Screaming Channels recovers a full AES-128 key at 10 m by having the target device’s own legitimate radio transmitter re-broadcast digital side-channel leakage, extending electromagnetic side-channel range from centimetres to more than ten metres with a commodity receiver.18 EM Eye reconstructs image streams from embedded camera emissions at over 2 m through a wall.19 Retroreflector work moves the receiver further still by illuminating a passive hardware implant, trading a planted receiver for a planted implant.20
Finding
Across the thirteen exfiltration channels compiled in table 1, every one requires reception apparatus the attacker positions, within a range no evaluation reports beyond tens of metres, and in eight cases that apparatus must additionally be compromised. No surveyed exfiltration channel operates at a distance an attacker can reach without physical access to the site or to a device carried into it.
This finding is bounded to the definition in part one. It does not extend to passive interception, where the results in part three demonstrate reconstruction at several hundred metres with no implant of any kind, and it does not address what an adversary with physical access can accomplish.
Primary papers where available, preprint where the published venue is paywalled. Entries 15 to 20 are the passive eavesdropping literature recorded in part three.