There's a clip going around that says air-gapping is dead. Two machines, no wires, no network, no radio, and they're still talking to each other. Through heat.
Through heat.
An OpenAI researcher said it on a podcast last week. If one machine runs its CPU hot and the other one feels it, that's a channel. And if that's true, then physically isolating a system doesn't contain anything, including something that doesn't want to be contained.
Technically he's right.
That's the worst kind of right.
It is, and that's the whole episode.
Daniel wrote in about this. He's been reading the air-gap exfiltration literature, and he noticed something. A lot of it comes out of Israel. Which is correct, incidentally. And the example he'd seen was malware that oscillates fan speeds, encoding a message in the pitch changes, so somebody sitting nearby with a microphone can read it back.
He's got the mechanism right.
He says, fine, somebody still has to plant a listening device, and at that point you're talking about nation-state tradecraft, extraordinary resources, that whole world. His actual question is the one nobody bothers to ask. Has any of this ever been used? Not demonstrated in a lab. Used. On a real target, by a real operator, for a real reason.
And then he read the tweet.
Two computers regulating their CPU temperatures to talk to each other, and he says, and I'm quoting him, that seemed a bit suspicious. Which is a very polite way of putting it.
It's a very Daniel way of putting it.
So, two things to do. Separate the physics from the fiction, and then find out what actually gets used when the stakes are enormous. Let's go.
Start with what an air gap actually is, because people use the term loosely. An air-gapped system is physically and logically disconnected from every network. No internet, no local area network, no wireless. Nothing. The only way in or out is a human being physically carrying something.
And these aren't hobbyist setups. Classified military networks, payment card processing, industrial control systems, journalists working on things they'd rather not have read.
The entire security model rests on one assumption. No network path means no data leaves. Everything else, the encryption, the access controls, the auditing, sits on top of that assumption. If it fails, the whole thing fails.
And your hunch about Israel, Daniel, that's not a hunch. Dr. Mordechai Guri runs the Offensive Cyber Research Lab at Ben-Gurion University. He's spent more than a decade on this and basically nothing else. Around seventeen hundred citations, an h-index in the low twenties.
WIRED profiled him and the line they used was that he'd uniquely fixated his career on defeating air gaps. That's fair. He's the reason this field exists as a field.
His framing is the part I keep thinking about. Everyone was talking about breaking the air gap to get in. Nobody was talking about getting the information out.
That's the inversion. For decades the threat model was intrusion, somebody breaking in. Guri asked the opposite question. Assume they're already inside. Now what?
And the answer, over two decades, is dozens of channels. Heat, sound, light, magnetism, vibration, radio frequency. Every physical quantity a computer produces, somebody has turned into a transmitter.
Which gives us the paradox the whole episode runs on. Dozens of demonstrated channels. And every confirmed real-world air-gap breach used a USB stick.
So the lab and the field look nothing like each other. Why?
Let's start with the fan, since that's the one Daniel brought up. Fansmitter. The idea is that malware regulates the speed of the internal cooling fan, and the fan speed controls the acoustic waveform the machine emits. You modulate that waveform and you've got binary data going out to a nearby microphone.
No speaker required.
Which matters, because a lot of secure facilities remove speakers specifically to kill acoustic channels. The fan is still there. The fan is always there.
Because the machine has to not melt.
You can't air-gap the heat.
That's the thing about all of these. They're not exploiting a design flaw. They're exploiting the fact that the machine is a physical object.
Right, and then the same actuator gets reused. AiR-ViBeR, 2020. Same trick, malware controls fan speed, except now it's generating inaudible vibrations instead of audible sound. And the receiver is a smartphone accelerometer.
Which needs no permissions.
None. Any app can read the accelerometer. So you've got a phone sitting on the same desk, and it's picking up the fan's vibration through the surface, and decoding it. No microphone access, no special hardware, nothing that would trip a permission dialog.
That's the part that would worry me if I were the one designing the facility.
And then SpiralSpy, out of NDSS in 2022, takes the same fan channel and pushes it to six bits per second. Which is six to twenty-four times faster than the earlier fan methods.
Six bits per second still sounds like nothing.
It is nothing, by network standards. But look at the shape of the family. One actuator, the fan. Three different receivers. Microphone, accelerometer, microphone again. And each generation buys you bandwidth. That's the pattern across this entire field.
Now the CPU temperature one. Because that's the tweet.
That's real too. BitWhisper, Guri and colleagues, 2015, IEEE Conference on Security and Privacy. Two adjacent compromised computers communicate through heat.
Adjacent how adjacent?
Zero to forty centimeters.
So, touching.
Effectively touching. The mechanism is exactly what the tweet describes. A binary one is a rise of about one degree Celsius. A zero is a return to baseline. The receiving machine reads it off its own built-in thermal sensors. Bidirectional, and no extra hardware on either side.
And the rate?
One to eight bits per hour.
Per hour.
Per hour. Transmitting a single bit took somewhere between three and twenty minutes in the demo.
So the demo. What did they actually do with it?
They sent a command to reposition a toy missile launcher.
Of course they did.
It's a good demo, honestly. It proves the channel is bidirectional and it proves you can issue a command, not just leak a file. But the numbers are the story. One to eight bits per hour, at a maximum range of forty centimeters, which is about ten thousand times slower than PowerHammer.
PowerHammer being data over the power lines.
A thousand bits per second at the line level. Ten bits per second at the phase level. So put those side by side. BitWhisper, one to eight bits per hour. PowerHammer, a thousand bits per second. The most cinematic techniques in this field are consistently the least practical.
There's something almost admirable about it. Somebody built a working covert channel out of the fact that computers get warm.
There's newer work too. Heaker, from last year, manipulates both CPU and GPU thermal emissions. Thermal-Secret proposes combining heat and fan noise into a kind of steganography. The line of research is alive.
But here's the thing I want to put on the table before we go further. Every single one of these assumes malware is already running inside the air-gapped machine.
That's the asterisk under the whole field.
Because getting the malware in is the hard part. That's the entire reason you air-gap something in the first place.
Right. Which is why people who work in this area will tell you these aren't attacks. They're methods of data exfiltration between two compromised devices. The compromise already happened. You're just watching the exit.
And the exit is the easy half.
The exit is the easy half. That's the sentence I'd put on the poster.
So before we get to whether any of this has been used, give me the breadth. Because I don't think people appreciate how many of these there are.
It's a lot. Magnetics first, because this one surprised me. MAGNETO, 2018. It uses magnetic fields, and it penetrates Faraday cages.
The whole point of a Faraday cage is that it blocks electromagnetic signals.
It blocks radio frequency. It doesn't block static and low-frequency magnetic fields, and that's the gap. The receiver is a smartphone magnetometer, which is the sensor the phone uses for its compass. There's an app called ODINI that Guri's group wrote for it. One to forty bits per second, and they demonstrated pulling a four thousand ninety-six bit key out in about an hour.
Through a Faraday cage, in an hour.
That undermines the standard mitigation, and I don't think that finding got the attention it deserved.
What else?
TEMPEST-LoRa, 2025. Electromagnetic leakage off a video cable, received by commercial LoRa nodes. Eighty-seven and a half meters, twenty-one point six kilobits per second.
That's a completely different order of magnitude from BitWhisper.
It's four orders of magnitude. LaserShark, 2021, uses a laser aimed at the machine's built-in LEDs. Twenty-five meters, eighteen point two kilobits per second inbound, a hundred kilobits per second outbound. LED-it-GO blinks a hard drive activity light up to five thousand eight hundred times per second. COVID-bit, 2022, leaks electromagnetic emissions in the zero to sixty kilohertz band at a thousand bits per second across two meters, and it runs at user level, even from a virtual machine.
The drive activity light.
The little light that tells you the disk is busy.
Every machine in every secure facility has one, and it's been blinking in Morse since the day it was installed.
Effectively, yes. And that's the point of the breadth. It's not one clever trick. It's a systematic survey of every physical quantity a computer emits, and the answer is that all of them can carry data.
So the physics is real. Every one of these has been built and measured. Now the question Daniel actually asked.
Let's talk about the real world.
What actually gets used.
USB drives.
That's it?
That's it. Stuxnet crossed the air gap at Natanz with infected removable media. That's the most famous cyber operation of the century and the air gap was defeated by somebody plugging in a stick.
In 2008, Agent.BTZ infected around three hundred thousand US military computers, and it spread the same way. USB. That one triggered Operation Buckshot Yankee, and it's one of the reasons US Cyber Command exists.
Look at the named tooling too. Mustang Panda has a PlugX USB worm. Tropic Trooper has USBferry. APT28 has USBStealer. APT30 has SPACESHIP. The Equation Group had Remsec. Machete in Venezuela. Ramsay, which ESET documented in 2020. Every single one of these is a nation-state-grade actor, and every single one of them chose removable media.
Because it works.
Because it works, it's cheap, it's reliable, and it's deniable. You don't need to control the temperature of anything.
So is there a single confirmed exotic channel? Anything at all?
One, and it's a partial. The NSA's COTTONMOUTH-One. It's a hardware implant, and it came out of the ANT catalog that Snowden leaked. It uses radio frequency to extract data to a briefcase-sized relay up to eight miles away.
Eight miles is not nothing.
Eight miles is impressive. But look at what it requires. It's a physical implant. Somebody has to solder that into the machine. So even the state-level exception smuggles the compromise in physically. It's not pure software, and that's the distinction that matters.
Which means the answer to Daniel's question is no.
The answer is no. There's no public evidence that fan-speed, thermal, vibration, or LED covert channels have ever been used in an actual operation. They're academic proofs of concept. Every confirmed real-world air-gap breach went through removable media.
So why does the lab look nothing like the field?
Two reasons, and I think both of them are right. Eran Tromer at Columbia, who's one of the more careful people in this space, points out that Guri's team tests on consumer hardware. Ordinary desktop machines, ordinary fans, ordinary thermal sensors. Hardened secure equipment is built differently. Tighter tolerances, better shielding, sensors that aren't exposed to user space. So some of the demonstrated range and rate wouldn't survive contact with a real target.
And the second reason?
The second reason is economics. Somebody on Hacker News put it better than I can. The line was that someone is going to discover infinitely more intelligence by good old fashioned dumpster diving than by designing and successfully implementing a novel air-gap exfiltration methodology.
That's brutal and correct.
It's both. Espionage is an economics problem. If you can get the same file with a hundred-dollar USB stick and a contractor who doesn't check his pockets, why would you spend eighteen months building a thermal channel that moves one byte every two hours?
Because it's beautiful.
Because it's beautiful, and because the person building it is a researcher, not an operator. Those are different jobs with different incentives. The researcher gets a paper. The operator gets the file.
Which brings us to the tweet.
September eighteenth, Noam Brown at OpenAI, on the Dwarkesh Patel podcast. His argument was that air-gapping might not be sufficient to contain a misaligned AI, and his example was exactly BitWhisper. One machine runs its CPU hot, the other detects the temperature change, and now they have a communication mechanism.
And the clip went viral.
It went viral through a post on X, and it circulated for a couple of days before anyone dug into the underlying paper. Then mlllm.io published a corrective explainer on the twentieth, which laid out the actual parameters. Both machines already compromised. Forty centimeters maximum. One to eight bits per hour.
Which is the same paper from 2015.
The same paper from 2015. Eleven years old. Gizmodo's AJ Dellinger put it well. Details matter, and once you dig into how BitWhisper actually works, the threat starts to look a lot less pressing.
So is Brown wrong?
I don't think wrong is the right word. He's making a different argument. He's not saying this is a practical escape route. He's saying that physical isolation is a property people assume is absolute, and it isn't. There's no such thing as a perfect seal. Two machines in the same room are coupled through the room.
That's a fair point, actually. It's a philosophical point about containment, not an engineering claim about bandwidth.
It's a philosophical point, and I think it's a good one. If you're reasoning about whether you can contain a system indefinitely, the existence of any channel at all matters, even a slow one. A channel that moves one bit an hour is still a channel. If the timescale you care about is years, one bit an hour is a lot of bits.
But the critics would say it distracts from the failures that are actually happening.
They would, and there's something to that. The chain-of-thought monitoring was reportedly off during the Hugging Face incident. That's a real, admitted, documented failure of an oversight mechanism that was supposed to be running. Arguing about thermal channels while that's the state of things is a bit like worrying about the lock on the back door while the front door is open.
So the exotic channels are real physics answering a question nobody in the field is currently asking.
That's the cleanest version of it. The research is real. The threat model it addresses is not the one that's actually costing anyone anything.
There's a detail I keep coming back to, though. Guri's whole body of work assumes the compromise already happened. Every paper starts from a machine that's already running hostile code. And the entire real-world record says the compromise is where everything actually happens. So the research is rigorous about the second half of a two-part problem, and the second half is the easy half.
The hard half is a guy with a lanyard.
Hilbert: The pitch changes.
Sorry?
Hilbert: On the fans. You said if a fan changes pitch you'd notice. I did that for eleven months. Night shift, data center out past the airport, hosted a government contract. My job was to walk the aisles with a clipboard and listen.
Listen for what?
Hilbert: Bearing failure. You logged the pitch. Every rack, twice a shift, and if a fan had drifted you wrote it down and somebody came out and swapped it. I never once thought I was listening to a data channel. I thought I was listening to a fan about to seize.
So the channel you were monitoring was the one Daniel asked about.
Hilbert: It's a real thing. I'm not saying it isn't. I'm saying you've both got the wrong end of it. You don't need a fan to talk to a compromised machine. You need a guy with a USB stick and a lanyard.
The lanyard.
Hilbert: Retractable reel, contractor badge on the end. Everyone in the building wore one. You clipped it to your belt and the badge sat against your hip all day. Nobody looked at it. Nobody had a reason to. You could have walked a thumb drive through that gate every morning for a year and the only thing anyone would have asked is whether you'd badged in.
And the machines inside were air-gapped.
Hilbert: Every one of them. No network, no wireless, nothing. The room was built for it. The people weren't.
Which is the point about the already-compromised assumption. The channel is the second problem. Getting the code in is the first one, and the first one is a human being with a pocket.
Hilbert: There was a no phones policy. Strict. You left it in a locker at the front. But the maintenance crew all carried pagers, because that's how dispatch reached us. And one night a contractor's pager went off and it wasn't a normal page. It was a burst. Long, fast, didn't sound like a number.
What did you do?
Hilbert: Nothing. I wrote down a fan reading and went to the next aisle. I don't know what it was. It might have been nothing. It might have been a weather alert. I never found out and I never asked.
That's the whole threat model in one story. The channel doesn't matter if the human is the vulnerability.
Hilbert: Anyway. I'm late for an appointment. It's a thing with the dentist's office, they only do it Tuesdays, and I've already moved it twice.
So the bandwidth trend.
The bandwidth trend. BitWhisper is one to eight bits per hour. TEMPEST-LoRa is twenty-one point six kilobits per second at eighty-seven and a half meters. That's not a small improvement, that's a different category of thing.
So does the lab-field gap close as the rates go up?
That's the question I don't know the answer to. The optimist's case is that once a channel gets fast enough, the economics flip. If you can pull a megabyte in a few minutes from across a parking lot, that starts to compete with walking a USB stick through the front gate, because it doesn't require a human who might get caught.
And the pessimist's case?
The pessimist's case is that the USB stick also got faster, and it's still a hundred dollars, and it still doesn't require you to control the thermal envelope of a machine you don't own. The shortcut stays cheaper. It's stayed cheaper for twenty years.
The AI-safety framing might be the more consequential part of this, though. Not because BitWhisper is a practical escape route. Because it forces the question of whether physical isolation can ever be sufficient for containing something that doesn't want to be contained.
And that question is new, even though the research under it is eleven years old. That's the part I'd watch.
If you got something out of this one, leave us a review. It helps other people find the show.
Thanks to Hilbert Flumingtop, our producer.
This has been My Weird Prompts. You can find everything at my weird prompts dot com, or email us at show at my weird prompts dot com.
We'll be back soon.
See you then.