BTC
$102,787.72
-
1.74%
ETH
$2,458.46
-
4.59%
USDT
$1.0001
+
0.01%
XRP
$2.5012
+
3.27%
BNB
$649.57
-
2.87%
SOL
$172.48
-
2.28%
USDC
$1.0001
+
0.01%
DOGE
$0.2242
-
9.19%
ADA
$0.7910
-
4.86%
TRX
$0.2631
-
1.62%
SUI
$3.9565
-
5.78%
LINK
$16.45
-
6.43%
AVAX
$24.48
-
5.09%
XLM
$0.3055
-
3.09%
SHIB
$0.0₄1536
-
10.69%
HBAR
$0.2073
-
3.99%
HYPE
$24.83
-
2.57%
TON
$3.2901
-
5.89%
PI
$1.1544
-
24.01%
LEO
$8.5762
+
2.12%
Logo
  • News
  • Prices
  • Data
  • Indices
  • Research
  • Consensus
  • Sponsored
  • Sign In
  • Sign Up
Advertisement

Consensus 2025

Consensus 2025

Prices Increase This Friday

17:11:16:53

17

DAY

11

HOUR

16

MIN

53

SEC

Register Now
Tech
Share this article
X iconX (Twitter)LinkedInFacebookEmail

A New Ultrasonic Hack Can Exploit Your Siri

A new hack called a SurfingAttack uses ultrasonic guided waves to communicate with a device through the voice assistant.

By Benjamin Powers
Updated Sep 14, 2021, 8:26 a.m. Published Apr 7, 2020, 8:01 p.m.
Via Shutterstock
Via Shutterstock

Researchers are sounding the alarm about a new type of hack focused on smart digital assistants like the Amazon Alexa or Apple's Siri.

STORY CONTINUES BELOW
Don't miss another story.Subscribe to the The Protocol Newsletter today. See all newsletters
By signing up, you will receive emails about CoinDesk products and you agree to our terms of use and privacy policy.

The hack, called a "SurfingAttack," uses ultrasonic guided waves that are imperceptible to the human ear to communicate with a device through the voice assistant. It could be used to target Ring services with door deadbolts attached or move the temperature dial on your thermostat.

Security researchers who developed the attack say it enables multiple rounds of interactions between a voice-controlled device and attackers over relatively long distances and without the need for the device to be within sight. It could even be conducted through a heavy surface, like a table.

“Humans cannot hear anything, but the voice assistants will interpret these ultrasonic sounds as a voice command, and conduct certain operations because of it,” said Qiben Yan, an assistant professor at Michigan State University’s Secure and Intelligent Things Lab, who was the lead investigator on the project. “Sending the commands to the voice assistance, we can basically control the voice assistant. There's a lot of opportunities for this when people put their phones down on a table and leave them unattended.”

Yan said hackers could launch conversations with a victim's contacts, and depending on how connected their devices are, potentially control home devices, lock or unlock a car or front door, or alter the thermometer. Such attacks could also impact two factor authentication, by reading the security code sent via text back to the hacker.

Using a $5 off-the-shelf PZT transducer, a type of electroacoustic transducer, the researchers were able to successfully compromise the following devices.

Table of phones that researchers compromised.
Table of phones that researchers compromised.

They believe that more devices could be vulnerable, including phones protected by silicone rubber phone cases.

There are steps people can take to prevent such attacks though. Disabling the voice assistance when your phone is locked, or making sure your phone is on a covering such as a tablecloth, can stop the ultrasonic ways from affecting it. Using phone cases of uncommon materials like wood can also help.

hackingPrivacyiPhoneSurfingAttack
Benjamin Powers

Powers is a tech reporter at Grid. Previously, he was privacy reporter at CoinDesk where he focused on data and financial privacy, information security, and digital identity. His work has been featured in the Wall Street Journal, Daily Beast, Rolling Stone, and the New Republic, among others. He owns bitcoin.

Benjamin Powers

Only 1 article remaining this month.

Sign up for free

About

  • About Us
  • Masthead
  • Careers
  • CoinDesk News
  • Crypto API Documentation

Contact

  • Contact Us
  • Accessibility
  • Advertise
  • Sitemap
  • System Status
DISCLOSURE & POLICES
CoinDesk is an award-winning media outlet that covers the cryptocurrency industry. Its journalists abide by a strict set of editorial policies. CoinDesk has adopted a set of principles aimed at ensuring the integrity, editorial independence and freedom from bias of its publications. CoinDesk is part of the Bullish group, which owns and invests in digital asset businesses and digital assets. CoinDesk employees, including journalists, may receive Bullish group equity-based compensation. Bullish was incubated by technology investor Block.one.
EthicsPrivacyTerms of UseCookie SettingsDo Not Sell My Info

© 2025 CoinDesk, Inc.
X icon
Sign Up
  • News
    Back to menu
    News
    • Markets
    • Finance
    • Tech
    • Policy
    • Focus
  • Prices
    Back to menu
    Prices
    • Data
      Back to menu
      Data
      • Trade Data
      • Derivatives
      • Order Book Data
      • On-Chain Data
      • API
      • Research & Insights
      • Data Catalogue
      • AI & Machine Learning
    • Indices
      Back to menu
      Indices
      • Multi-Asset Indices
      • Reference Rates
      • Strategies and Services
      • API
      • Insights & Announcements
      • Documentation & Governance
    • Research
      Back to menu
      Research
      • Consensus
        Back to menu
        Consensus
        • Consensus Toronto
        • Toronto Coverage
      • Sponsored
        Back to menu
        Sponsored
        • Thought Leadership
        • Press Releases
        • CoinW
        • MEXC
        • Phemex
        • Advertise
      • Videos
        Back to menu
        Videos
        • CoinDesk Daily
        • Shorts
        • Editor's Picks
      • Podcasts
        Back to menu
        Podcasts
        • CoinDesk Podcast Network
        • Markets Daily
        • Gen C
        • Unchained with Laura Shin
        • The Mining Pod
      • Newsletters
        Back to menu
        Newsletters
        • The Node
        • Crypto Daybook Americas
        • State of Crypto
        • Crypto Long & Short
        • Crypto for Advisors
      • Webinars & Events
        Back to menu
        Webinars & Events
        • Consensus 2025
        • Policy & Regulation Conference
      Select Language
      English enEspañol esFilipino filFrançais frItaliano itPortuguês pt-brРусский ruУкраїнська uk