The solution
In January 2015 Samy Kamkar — the hacker behind the 2005 Samy worm that knocked out MySpace — unveiled KeySweeper: a keystroke logger built into a functioning USB wall charger for as little as $10. It continuously sniffs, decrypts, logs and transmits everything typed on a Microsoft wireless keyboard within range, while looking to its victims like just another charger plugged into the wall.
The hardware is off-the-shelf: an Arduino or Teensy, an nRF24L01+ radio chip, optional SPI flash for storage, and an optional Adafruit FONA board with a SIM card for wireless exfiltration. The weakness is Microsoft's own encryption design: keystrokes are XOR-encoded using the keyboard's MAC address as the key, and since the chip can read that address — and every Microsoft keyboard's MAC begins with 0xCD — the decryption alignment never changes. KeySweeper can send the operator an SMS whenever keywords such as 'bankofamerica.com', 'confidential' or 'password' appear in the keystream.
The underlying flaw wasn't new — white-hat researchers Travis Goodspeed, Thorsten Schröder and Max Moser had exposed the lackadaisical XOR encryption years earlier — but their exploits needed larger, power-hungry computers. Kamkar's contribution was shrinking the attack into an inexpensive, always-on object that a janitor, co-worker or visitor can plant within range of a target and walk away from.
Why it worked
The disguise removes every human checkpoint: no phishing, no malware install, no network breach — the device hides in plain sight as furniture.
Microsoft's encryption used the keyboard's own MAC address as the key, a value broadcast in the clear and prefixed by a constant byte.
Earlier research proved the flaw but required bulky equipment; commodity radios and microcontrollers turned it into a $10 always-on appliance.
Keyword-triggered SMS meant the attacker never had to watch logs — the device surfaced valuable keystrokes on its own.
What can be applied
Key material an attacker can read is not key material: encrypting with a device's own broadcast address protects against nobody with a $10 radio and patience.
Aftermath
Kamkar published the hardware specifications and software. Ars Technica noted the tested keyboard was a brand-new retail model, and that Microsoft's own site listed only a single keyboard model with 128-bit AES encryption; Microsoft's statement said Bluetooth keyboards and its 2.4GHz wireless designs from July 2011 onward use AES and are protected. Wired keyboards and Bluetooth keyboards are immune to this class of attack.
FOLLOW THE EVIDENCE