When Allies Stop Trusting Each Other: Denmark's Bluetooth Warning and the Fracturing Western Alliance

· 16 min read · cybersecurity geopolitics
#1 Gray Zone Warfare

On January 19, 2026, Denmark’s military intelligence service, the Forsvarets Efterretningstjeneste (FE), sent an urgent memo to police districts and government agencies across the country. The message was blunt: turn off your Bluetooth. Now.

No more wireless earbuds during sensitive calls. No more AirPods at security briefings. No more wireless speakers in ministerial offices. The directive extended to personal devices—an unusual scope that raised eyebrows across Copenhagen’s corridors of power.

On its face, this was a routine technical advisory. The FE stated it was relaying vulnerability information from the security research site WhisperPair.eu, not issuing an independent threat assessment. But the timing—in the midst of a serious crisis over Greenland with the United States—invited a more charged interpretation.

Danish police sources told local media that the warning stemmed from “a very concrete incident or suspicion,” language that suggests this was more than a standard security bulletin. Whether that suspicion pointed toward Washington, Moscow, Beijing, or somewhere else entirely, the FE has not publicly said.

But context matters. And in January 2026, the context was tense.


Why Denmark’s History Makes This Moment Significant

To understand why this advisory attracted such attention, you need to understand Denmark’s unique position in the Western intelligence world.

From 2012 to 2014, Danish intelligence actively helped the NSA tap into undersea internet cables running through Danish waters to spy on senior European officials—including German Chancellor Angela Merkel, French President François Hollande, and Swedish Prime Minister Stefan Löfven.

That collaboration wasn’t revealed until 2021, when Danish investigative journalists exposed “Operation Dunhammer,” an internal FE investigation that uncovered the scope of Danish complicity in American surveillance of European allies. The fallout was significant: the head of Danish intelligence was fired, the Danish ambassador to Germany was recalled, and European capitals demanded explanations.

Denmark learned then what it means to be caught between powerful friends. Germany was furious. France demanded answers. But the United States faced no real consequences. The asymmetry of power meant Denmark absorbed most of the diplomatic damage.

As analysts at The Conversation explained, Denmark cooperated because as a small country, it depends on security guarantees from larger powers—and through the NSA partnership, Danish intelligence gained access to advanced technology like the XKeyscore program.

This history creates a lens through which many observers—including some within Denmark—interpreted the January 2026 advisory. Danish intelligence officers who received XKeyscore training understand intimately how these surveillance capabilities work. When the FE warns about Bluetooth vulnerabilities during a crisis with Washington, the subtext is hard to miss—even if the FE itself insists it was simply relaying technical information.


The 14-Meter Spy

The technical details in Denmark’s warning are worth understanding, because they reveal just how far surveillance technology has advanced—and why your wireless earbuds might be more dangerous than you think.

The FE’s directive specifically cited two sets of vulnerabilities. The first, CVE-2025-36911, is known in security circles as “WhisperPair.” Discovered by researchers at Belgium’s KU Leuven university, WhisperPair exploits a flaw in Google’s Fast Pair protocol—the system that lets Bluetooth devices quickly connect to your phone. Google classified the issue as critical and awarded the researchers a $15,000 bug bounty.

The attack is elegant in its simplicity. An attacker with a laptop, a Raspberry Pi, or even just a smartphone can force a connection to your wireless earbuds from up to 14 meters away—about the length of a bus. No pairing request pops up on your phone. No notification appears. The whole process takes roughly ten seconds.

Once connected, the attacker can activate the microphone in your earbuds and listen to everything around you. They can also track your location using Google’s Find Hub network. They can blast audio at maximum volume if they want to harass you.

The defenses are limited but not nonexistent. Users can check for firmware updates from their headphone manufacturers, disable Fast Pair features where possible, or simply turn Bluetooth off during sensitive conversations. For the average person, the risk may be low. But for government officials, diplomats, or executives—anyone who might be a worthwhile target—the calculus is different. Denmark concluded its officials fell into that category.

The second vulnerability, affecting Airoha chips found in Sony, Bose, JBL, Marshall, and Jabra headphones, is equally alarming. Disclosed at the 39th Chaos Communication Congress in December 2025, these bugs allow attackers to read and write to the memory of your audio devices, initiate phone calls without your permission, and eavesdrop on your conversations.

What makes these vulnerabilities different from traditional phone hacking is their accessibility. You don’t need to be a nation-state to exploit WhisperPair. The research tools are publicly available. A moderately skilled hacker could build a working attack kit in an afternoon. Security researchers have already published proof-of-concept code on GitHub.

This democratization of surveillance capability is changing how espionage works. Intelligence services no longer need to deploy elite technical teams or compromise telecommunications infrastructure. A single operative sitting in a café 40 feet away from a target can silently compromise their audio devices and listen to every confidential conversation for the rest of the day.

Think about what this means for diplomatic security. Every embassy, every ministerial meeting, every sensitive negotiation now takes place in an environment where wireless audio devices are potential surveillance vectors. The FE’s Bluetooth ban makes perfect sense from a security standpoint.

But security concerns alone don’t explain why Denmark chose to make the warning public.


The Greenland Gambit

To understand Denmark’s decision, you have to understand what else was happening in January 2026.

Two weeks before the Bluetooth directive, President Donald Trump stood before reporters and refused to rule out using military force to take Greenland from Denmark. “I can’t assure you on either of those two,” Trump said when asked about military or economic coercion. “But I can say this—we need Greenland for national security purposes.”

It wasn’t an idle threat. According to multiple reports, Trump had already ordered the Joint Special Operations Command to develop plans for what he called a “possible invasion of Greenland.” His administration threatened tariffs on Denmark and seven other European countries that sent troops to reinforce the Danish Arctic territory.

Denmark responded by deploying hundreds of elite combat soldiers to Greenland, including the commanding general of the Royal Danish Army. European allies—France, Germany, the UK—sent their own forces in solidarity. NATO Secretary General Mark Rutte scrambled to prevent the first intra-alliance military confrontation in the organization’s history.

By mid-January, the immediate crisis had subsided. Trump walked back his most explicit threats at the World Economic Forum in Davos. But the damage was done. For the first time in its history, Danish defense intelligence had publicly identified the United States as a potential threat to national security. The December 2025 intelligence outlook stated bluntly: “The United States uses economic power, including threats of high tariffs, to enforce its will, and no longer rules out the use of military force, even against allies.” Jon Rahbek-Clemmensen, associate professor at the Royal Danish Defence College, called it “almost a seismic shift”—noting that previous intelligence assessments had always framed Washington as a stabilizing force.

Into this charged atmosphere came the Bluetooth directive.

The timing invited interpretation. Danish police sources told local media that the warning stemmed from “a very concrete incident or suspicion”—language that suggests detection rather than mere precaution.

It would be overreach to claim Denmark was explicitly accusing the United States of espionage. The FE has not said that. But the confluence of events—the Greenland crisis, the intelligence report naming the U.S. as a potential threat, and a Bluetooth security warning citing vulnerabilities particularly useful for proximity surveillance—created a narrative that many observers found difficult to dismiss as coincidence.

Whether intentional or not, the advisory functioned as a signal: Denmark was taking its security seriously, even if that meant considering uncomfortable possibilities about its allies.


Reading Between the Lines: What Might Denmark Gain?

The following analysis represents interpretation of Denmark’s possible strategic calculus, not confirmed Danish government intentions.

Whether or not Denmark intended the Bluetooth advisory as a message to Washington, analysts can ask: what would a small country gain by publicizing security concerns during a crisis with a superpower?

The conventional answer is: nothing. Going public typically means burning intelligence sources, inflaming diplomatic tensions, and inviting retaliation. Most countries would handle such matters quietly.

But January 2026 was not a conventional moment. Denmark faced a genuinely new situation: a nominal ally that had threatened military force to seize its territory. In that context, even a routine security advisory could carry additional weight.

If we interpret the advisory as carrying strategic intent—and this remains interpretation—several purposes emerge:

First, it established a record. If tensions with the United States continue to escalate—or if surveillance operations become more aggressive—Denmark now has a documented history of raising concerns. The January 19 directive becomes evidence that Denmark acted in good faith to address security threats before any hypothetical future crisis.

Second, it mobilized domestic and European support. A secret diplomatic protest would have remained invisible to Danish citizens and European allies. By making the warning public, Denmark ensured that its concerns became part of the broader European conversation about American reliability as an ally. France, Germany, and other nations already alarmed by the Greenland crisis now had another data point suggesting American untrustworthiness.

Third, it demonstrated capability. By citing specific technical vulnerabilities—CVEs disclosed only weeks earlier by academic researchers—Danish intelligence signaled that it possesses serious counter-intelligence capabilities. This is not a trivial consideration when your adversary is the most powerful intelligence apparatus in history. Denmark was saying: we can see you.

Fourth, it imposed costs. Every public discussion of American surveillance against allies damages American soft power and diplomatic credibility. The Signal chat leak, in which Vice President JD Vance and Defense Secretary Pete Hegseth expressed “contempt” for European allies, had already undermined trust. The Greenland threats made things worse. The surveillance revelations added another layer to the accumulating evidence that America treats its friends as targets rather than partners.

Finally, it aligned Denmark with a broader European counter-intelligence posture. France’s new National Intelligence Strategy, published in 2025, explicitly calls for “European strategic autonomy in intelligence sharing, technology, and counter-espionage.” Denmark’s public stand positions it within this emerging European framework—a potential hedge against American unreliability.

None of these benefits come without costs. Danish-American intelligence cooperation will take a hit. Danish officials may face reduced access to American intelligence products. The bilateral relationship will carry a new layer of tension.

But from Copenhagen’s perspective, the relationship was already damaged. The Greenland threats demonstrated that alliance membership provides no protection against American pressure. The surveillance (if confirmed) showed that alliance membership provides no protection against American espionage. Given these realities, public disclosure at least allows Denmark to shape the narrative rather than remain a passive victim.


The Five Eyes That Couldn’t See Straight

Denmark’s decision doesn’t exist in isolation. It reflects—and accelerates—a broader crisis in Western intelligence cooperation.

The Five Eyes alliance, comprising the United States, United Kingdom, Canada, Australia, and New Zealand, has been the cornerstone of Western signals intelligence since World War II. Harvard historian Calder Walton calls it “the most important intelligence sharing agreement in history.” For seventy-nine years, these nations have shared their most sensitive secrets under a foundational principle: we don’t spy on each other.

That principle is now in tatters.

In July 2025, Director of National Intelligence Tulsi Gabbard issued a directive halting intelligence sharing with Five Eyes partners on matters related to Russia-Ukraine peace talks. The memo classified all related analysis as “NOFORN”—no foreign nationals—effectively cutting America’s closest allies out of a major policy discussion.

Meanwhile, allied intelligence services have been conducting their own quiet reassessments. “There are serious discussions going on about what information can be shared with the United States,” one Western official told NBC News. “The Five Eyes have always worked on the premise that we don’t spy on each other. I don’t think that’s reliable anymore.” Foreign Policy reported that allies have grown particularly concerned about the appointment of Tulsi Gabbard as intelligence director—a figure “viewed with deep distrust by U.S. national security professionals, not least for her close past alignment with the Kremlin’s views.”

The Signal chat leak crystallized these fears. When the editor of The Atlantic was accidentally added to a group chat containing America’s national security leadership—and then witnessed them sharing classified strike plans while mocking European allies—every intelligence service in the Western world took note. If American leaders handle their own secrets this carelessly, what happens to intelligence that allies share with them?

Denmark’s public disclosure is both a symptom of this trust erosion and a catalyst for further deterioration. Other European nations watching Copenhagen’s defiance will draw their own conclusions about what American friendship is worth. The cumulative effect—Greenland threats, surveillance revelations, Signal leaks, Five Eyes restrictions—creates what analysts call a “trust cascade effect” that will take years, perhaps decades, to repair.

As Walton put it bluntly: Putin “could not dream of doing better than having the Five Eyes alliance undermined and sabotaged from within.”


The Arctic Prize

Behind all of this geopolitical maneuvering lies a fundamental reality: Greenland matters.

The world’s largest island sits atop an estimated 90 billion barrels of oil, 30 percent of the world’s undiscovered natural gas reserves, and massive deposits of rare earth minerals essential for everything from smartphones to fighter jets. According to CSIS analysis, Greenland hosts 25 of the 34 minerals deemed critical by the European Commission, and potentially holds the world’s second-largest rare earth reserves after China. Beijing currently controls roughly 90 percent of global rare earth processing; Greenland’s reserves represent one of the few possible paths to Western independence from that monopoly.

Climate change is making these resources accessible for the first time in human history. As Arctic ice retreats, the Northern Sea Route—connecting Asia to Europe through Russian waters—is becoming a viable commercial shipping lane, cutting fifteen days off the traditional Suez Canal route. Whoever controls the Arctic’s chokepoints will exert enormous influence over global trade.

This is why three great powers are converging on the region. Russia has militarized its Arctic coast, deploying new bases and reactivating Cold War-era installations. China has declared itself a “near-Arctic state” and invested billions in Arctic infrastructure and research. The United States sees Greenland as essential to its own Arctic position—hence the extraordinary pressure on Denmark.

Vice President Vance made the stakes explicit during his visit to Greenland: “Russia and China and other nations are taking an extraordinary interest in Arctic passageways and Arctic naval routes and indeed in the minerals of the Arctic territories. We need to ensure that America is leading in the Arctic.”

This competition isn’t going away. Even if the immediate Greenland question is resolved through diplomacy, the underlying drivers—valuable resources, shipping routes, and strategic position—will persist for decades. Denmark, whether it likes it or not, sits at the nexus of great power competition. Its intelligence about Russian movements, Chinese investments, and Arctic developments is valuable to every major power.

That value is both an asset and a vulnerability. It means Denmark possesses information that powerful nations want—by cooperation if possible, by espionage if necessary.


What This Means for Ordinary People

If you’ve made it this far and you’re wondering whether any of this affects you, here’s the uncomfortable truth: it probably does.

The WhisperPair vulnerability affects an estimated 68 percent of all devices that use Google’s Fast Pair protocol. If you own wireless earbuds or headphones from Sony, Google, JBL, Jabra, OnePlus, Xiaomi, or dozens of other manufacturers, your devices may be vulnerable to the same attack that apparently concerned Danish intelligence enough to issue an emergency directive.

There’s no patch you can install on your phone that will fix this. The vulnerability exists in the firmware of the audio devices themselves, and most manufacturers have been slow to release updates. Some never will. The only reliable protection is to disable Bluetooth entirely when handling sensitive communications—exactly what Denmark told its officials to do.

More broadly, the Denmark case illustrates how the boundaries between state-level surveillance and consumer technology have collapsed. The same Bluetooth protocols that let your earbuds connect seamlessly to your phone also create attack surfaces that intelligence services—and capable criminals—can exploit. Your everyday technology choices have security implications that extend far beyond your personal convenience.


Possible Futures: Scenarios to Watch

The following represents informed speculation, not prediction. Events could unfold differently.

If current trends continue, several developments seem plausible:

Scenario 1: European counter-intelligence coordination. Other EU member states—particularly France, Germany, and the Netherlands, given their own histories with NSA surveillance—may implement similar wireless security guidance. France’s 2025 National Intelligence Strategy already emphasizes European autonomy in counter-espionage.

Scenario 2: Bluetooth exploitation becomes routine. The WhisperPair tools are publicly documented. Security researchers have published proof-of-concept code. It would be surprising if capable attackers—state and non-state alike—did not incorporate these techniques into their operations.

Scenario 3: Intelligence sharing continues to erode. The trend toward a “more conditional, more guarded partnership” predates the Denmark situation. But each additional friction point makes recovery more difficult.

What remains certain: Regardless of how the Greenland question is resolved, the Arctic will remain a zone of great power competition. Denmark will continue to face intelligence pressure from multiple directions—American, Russian, Chinese—and will need to navigate that pressure carefully.


What We Can Learn

Whether Denmark intended its Bluetooth advisory as a strategic signal or simply as prudent security guidance, the episode shows something worth understanding about the current moment.

Alliances are not friendships. They are arrangements of mutual interest that persist only as long as the interests align. When a superpower threatens to use force against a treaty ally over territory, the assumptions that underpin the relationship come under strain.

The facts are these: Denmark issued a Bluetooth security advisory. The FE said it was relaying technical information. Police sources suggested a “concrete” trigger. And all of this occurred during the most serious crisis in Danish-American relations since World War II.

How you interpret the connection between these facts depends on how you assess Danish intentions, American activities, and the nature of alliance politics. Reasonable people can disagree.

What seems harder to dispute is that the old certainties are eroding. The trust that once bound Western intelligence services is fraying. And in an era when your earbuds can become listening devices from 14 meters away, the line between technical security and geopolitical signaling has become hard to see.

G.

All views expressed here are my own and do not represent the opinions or positions of my employer or any organization I am affiliated with.

AIL: 0 1 2 3 4 5

Giulio wrote the core content and analysis. claude-opus-4.6 / Anthropic (primary contributor) and other AI models supported with research, sounding board, refinement, and structural editing.