Cheap Hacking Gadgets: What They Can Actually Do to You
By NorwegianSpark Editorial · Published August 9, 2026 — written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
Search any large marketplace for security hardware and you will find a category that did not exist for consumers fifteen years ago: small, cheap, openly sold devices whose product photos imply they can open, copy, intercept or unlock something of yours. Some of the listings are honest tools sold to people who fix things. Some are toys. A few are exactly what the photo suggests.
The useful question is not "can this be bought" — it plainly can — but "what does it need in order to work on me". That question sorts the whole category quickly, and it sorts it in a way that tells you what to actually do. Almost everything in this class needs one of three things: physical access to a port, physical proximity to a radio, or your cooperation. Where none of those is available, the gadget does nothing at all.
The one thing they all share
Every attack in this article is local. It needs the attacker near you, near your device, or near your door. That is the single most important property of the category, and it is what separates it from the threats that actually empty accounts at scale — phishing, credential stuffing, reused passwords — which need no proximity and no hardware whatsoever.
That is worth holding onto, because the fear is easy to misplace. If you are trying to decide where to spend an hour and some money on your own security, the boring answer beats the cinematic one: a password manager and two-factor authentication will do more for you than any amount of vigilance about strangers in cafés. The hardware threats are real, they are just not the ones most likely to reach you.
With that said, proximity is not rare. You are near strangers on public transport, in hotels, at conferences, in shared offices and in rented flats. So the category deserves a clear-eyed reading rather than a dismissal.
Category one: things that pretend to be a keyboard
A computer trusts its keyboard absolutely. It has to — there is no way for an operating system to ask a keyboard to prove it is one. A device the size of a memory stick can therefore announce itself as a keyboard and begin typing the instant it is plugged in, far faster than a person could. This is the BadUSB class, demonstrated publicly at Black Hat in 2014, and it is the reason "found a USB stick in the car park" is a running joke among security teams.
The condition it needs is a port and an unlocked machine. Both are within your control. The full picture, including the malicious-cable variant and the airport-charging question, is in the USB stick that types.
Category two: things that pretend to be a network
A Wi-Fi network is a name. Nothing stops a nearby device from broadcasting the same name as the café's, and nothing stops your phone from preferring it. That is an evil twin, and the hardware for it is genuinely cheap and genuinely small.
What it gets is much less than it used to, because almost everything now travels encrypted, but it is not nothing — and this is the one category in this article where a product genuinely fixes the problem rather than merely reducing the odds. See what a fake hotspot can and cannot see for the detail, and is public Wi-Fi safe for the shorter practical version.
Category three: things that copy a credential
Contactless cards, office badges, gate fobs and hotel keys all answer a radio. Some of them answer without proving anything at all, which means copying them is a matter of holding a reader nearby. Others perform real cryptography and cannot be copied this way.
The split between those two groups is not obvious from the outside — the plastic looks the same — and it is roughly a generational one. Why old badges copy in seconds and bank cards do not explains which is which, and why the contactless card in your wallet is the safest item on this list.
Category four: things that watch
A tracker the size of a coin and a camera hidden in a plug are both cheap, both legal to sell, and both a genuine problem in rentals, in cars and in abusive relationships. This is the category where the countermeasure has improved most in the last two years, because the phone in your pocket now looks for the trackers on its own. Found moving with you covers what the alerts do and do not catch.
What is mostly theatre
A fair part of the category does not work as advertised, and knowing which part saves you both worry and money.
- "Unlock any car" replay devices. Modern remote keys use a rolling code — the code changes every press, and a captured one is stale by the time it is replayed. The attacks that do work against cars target relay of the *proximity* key from inside your house, which is a different problem with a different fix: a signal-blocking pouch.
- Listings claiming to unlock or read any phone. A modern phone's storage is encrypted with a key tied to hardware and to your passcode. A device that plugs into the port cannot read it. What such listings usually sell is either a repair tool or nothing.
- Anything sold as a signal jammer. Beyond being ineffective at the advertised job, operating one is illegal in most countries, including throughout Europe and the United States, and it is one of the few items here that will attract a regulator rather than a shrug.
- Old Wi-Fi cracking kits. These target WEP and early WPA. Anything set up in the last decade is out of their reach — assuming you are not still running a router from that era, which is a good reason to read the router checklist.
The defence, in the order that matters
The whole category collapses down to four habits, and none of them is exotic.
- Lock your screen and control your ports. Automatic lock on a short timer removes the entire keyboard-impersonation category, because typing into a locked machine achieves nothing.
- Assume every network you do not own is hostile. Not paranoid — just the correct default. Encrypt the hop with a reputable VPN and the local network stops mattering.
- Treat found or borrowed hardware as untrusted. Cables and sticks included. Charge from your own adapter and a wall socket.
- Fix the boring things first. Unique passwords, a manager to hold them, and phishing-resistant sign-in. These stop the attacks that do not require anyone to be anywhere near you.
Where this fits
This series sits alongside the network-side guides — your router, public Wi-Fi and travelling with devices — and the account-side ones, passkeys and two-factor authentication. Hardware is the least likely way you will be attacked and the most memorable, which is precisely why it is worth understanding well enough to stop worrying about the wrong half of it.
Affiliate disclosure
This article contains affiliate links. If you purchase through them, CyberTechVault earns a commission at no extra cost to you. Our assessments are based on vendors' published documentation, independent lab results and security disclosures — not on hands-on testing by us. Affiliate relationships never decide what we recommend.
Full disclosure: /affiliate-disclosure.
Sources
Factual claims above were checked against these primary sources. Verify directly on the source for anything time-sensitive before relying on it.