Researchers find all popular voice assistants, like Siri or Alexa, can be controlled via verbal commands emitted on ultrasonic frequencies using ~$3 hardware
How JPMorgan Banks Detroit's ‘Unbankable’ James Vincent / The Verge : Inaudible ultrasound commands can be used to secretly control Siri, Alexa, and Google Now Carl Velasco / Tech Times : Alexa, Siri, Google Assistant, And Cortana Can Be Hacked Using Sound Frequencies Humans Can't Hear Aman Jain / ValueWalk : Siri, Alexa, Google Now Can Be Hacked Using Inaudible Commands John Adams / PaymentsSource : 9.7.17: Your morning briefing Dave Neal / Inquirer : DolphinAttack: Alexa, Siri and more are vulnerable to ‘silent’ hacking JC Torres / SlashGear : Alexa, Siri are easily hacked, you won't even hear it coming Tyler Lee / Ubergizmo : Researchers Demonstrate ‘Dolphin Attack’ That Targets Digital Voice Assistants Bret Kinsella / Voicebot : Siri, Google Assistant and Alexa Hacked with High Frequency Dolphin Attack Usman / iPhone in Canada Blog : Simple Design Flaw Makes Siri and Alexa Vulnerable to Hacks Steve Dent / Engadget : Alexa and Siri are vulnerable to ‘silent,’ nefarious commands YouTube : DolphinAttack: Inaudible Voice Command Tweets: Dr. Drang / @drdrang : iPhone users won't believe Siri is vulnerable to this attack. We know Siri never does what you tell it. http://www.fastcodesign.com/ ... Craig Saila / @saila : Seems being able to talk to our computers might have opened a surprisingly easy way to hack them, too http://www.fastcodesign.com/ ... Mark Wilson / @ctrlzee : Apple, Google, Amazon, Microsoft have all made the same, terrible mistake http://www.fastcodesign.com/ ... @ia : Hackers can take control of the most popular voice assistants by whispering to them in frequencies humans can't hear http://www.fastcodesign.com/ ...
Context & Ripple Effects
This 2017 finding — dubbed DolphinAttack — showed that Siri, Alexa, Google Now, and Cortana obey ultrasonic commands humans cannot hear, built from roughly $3 of parts. It matters because it attacked the core assumption of every always-listening assistant: that a valid command implies a human spoke it.
The result opened a research thread rather than closing one. Researchers later showed commands hidden inside music and speech that humans can't detect, and then demonstrated laser-based command injection against smart speakers, tablets, and phones from far away — each escalation reusing the same broken trust model this paper first exposed.
First-order effects
- Amazon, Apple, and Google's always-on microphone pipeline accepts commands their users never hear, so any Siri, Alexa, or Google Now device within ultrasonic range becomes controllable by an attacker with commodity hardware.
- The wake-word trust model breaks immediately: microphones are revealed as an untrusted input channel, forcing the named vendors to treat acoustic hardware, not just software, as an attack surface.
Second-order effects
- Rather than fading, the attack class escalated — researchers went on to hide commands in ordinary audio and to hit devices with lasers, keeping sustained pressure on Amazon and Google whose platforms were already criticized for lax vetting of malicious voice apps.
- Every assistant feature that executes consequential actions (purchases, door locks, messages) now carries a hidden-command risk premium, pushing vendors toward confirming intent through channels a speaker cannot spoof.
Third-order effects
- If physical-layer injection keeps outpacing patches, voice interfaces converge on source verification — liveness detection and authenticated command paths — the same problem that surfaced when an AI clone defeated a bank's voice biometrics.
- Smart speakers in high-stakes settings (payments, access control, vehicles) would need hardware-level defenses, restructuring how Amazon, Apple, and Google design microphone pipelines and how regulators treat voice-device certification.
The trend: Voice assistant security is shifting from software exploits to physical-channel attacks — ultrasound, hidden audio, lasers — that firmware updates alone cannot close.