Not even emoji are safe from hackers - smiley faces can be hijacked to hide data, study claims

Angry emoji
(Image credit: Shutterstock)

  • Researcher finds a way to add invisible text to emojis
  • It probably can't be used for malware...probably
  • It could be used for watermarking or bypassing human moderation

A security researcher claims to have discovered a way to hide extra information inside emoji.

Paul Butler explained how he experimented with Unicode and came up with a method that exploits variation selectors (special characters designed to modify the appearance of text but which have no visible effect on most characters). By chaining the selectors together, he was able to encode invisible messages inside an emoji (or any other Unicode character).

Here is how it works: Unicode assigns variation selectors (U+FE00–U+FE0F and U+E0100–U+E01EF) to certain characters, usually to adjust stylistic presentation. However, these selectors can be used to store one byte of data each. Since a sequence of these selectors is preserved even when copy-pasting text, a person could embed a secret message inside an emoji without altering its visible appearance.

Smuggling data

It would seem that the method cannot be used to smuggle malware or malicious code, an application extension, or anything of sorts. However, it could be used to bypass human moderation, or watermark sensitive documents. With these invisible watermarks, an author could be able to track their work being copied and pasted throughout the internet, for example.

Discussing potential defensive measures, Butler said that AI could be of use. While some AI models, such as OpenAI's GPT and Google's Gemini, preserve variation selectors, they do not naturally attempt to decode hidden messages.

However, when paired with code interpreters, AI systems have successfully extracted secret messages within seconds. This suggests that automated detection tools could be developed to counteract potential abuse.

All things considered, this could be seen as an interesting quirk of Unicode. At this time, it’s highly unlikely someone could develop a malicious use for it.

You might also like

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Read more
email
Hidden text "salting" is letting hackers craft devious email attacks to evade detection
Trojan
Hackers hide malware into website images to go unnoticed
AI tools.
Not even fairy tales are safe - researchers weaponise bedtime stories to jailbreak AI chatbots and create malware
A digital representation of a lock
Security experts are being targeted with fake malware discoveries
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
SVG files are offering cybercriminals an easy way in with new phishing attacks
Microsoft Teams
Microsoft Teams is making it even easier to add emoji, and I can't wait to see how badly this goes
Latest in Security
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Latest in News
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC
Oura Ring 4
Activity tracking on Oura Ring is about to get a whole lot better, but I've got bad news about your step count
Google Maps on a phone being held in someone's hand
Google Maps is getting two key upgrades, for easier route planning and quicker access to Gemini AI
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Gemini on a smartphone.
Gemini 2.5 is now available for Advanced users and it seriously improves Google’s AI reasoning
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025