A developer went looking for why his Bluetooth headphones kept cutting out and found audio fingerprinting running silently on the AliExpress homepage — a hidden Web Audio graph that plays an inaudible tone through your sound hardware and measures how your specific machine handles it. Matt Callaghan published the findings on his blog on 20 August 2026, and they are unusually well documented for this kind of discovery, because he did not go looking for tracking at all. He went looking for whatever was stealing his music.

AliExpress logo, illustrating the silent audio fingerprinting found running on the AliExpress homepage
Image: AliExpress, via Wikimedia Commons

The symptom was oddly specific. Callaghan’s headphones support multipoint, so they stay paired to his PC and his phone at once, with the PC taking priority. Music from the phone would stop within seconds of an AliExpress page loading in Firefox or Chrome, and start again the moment he closed the tab. Muting the tab did nothing. Muting Firefox did nothing. Muting Windows did nothing. And there was no video, no audio player, and no visible media anywhere on the page.

What audio fingerprinting actually does

Callaghan checked the obvious culprits first — <audio> and <video> elements, calls to HTMLMediaElement.play(), Media Session metadata, embedded frames — and found none of them. So he wrapped the AudioContext constructor in his own logging code before loading the page, and watched what happened.

Two audio contexts appeared, both running, both connected to the system audio output, while the page sat idle. The stack traces pointed at two heavily obfuscated scripts served from an Alibaba media domain under a directory named AWSC: collina.js and fireyejs.js. Both, Callaghan writes, appear to be part of Alibaba’s browser security and anti-abuse tooling.

The audio graph each one builds is short and clever. A sawtooth oscillator generates a known waveform; an analyser node measures the result after the browser’s audio stack has processed it; a script processor reads the frequency data; and a gain node set to zero sits at the end so nothing is audible. The trick is that the chain is still connected to the audio destination, which forces the browser to keep processing it live. That is what kept the PC’s audio path awake and stopped the headphones handing back to the phone — and it is exactly why the mute button was useless.

There is no media element for the browser’s normal tab mute control to stop.

— Matt Callaghan, in his write-up of the findings.

The reason this works as identification is that no two setups process that tone identically. Small differences in browser build, operating system, audio libraries and hardware produce slightly different numbers out the other end. On its own that is not enough to pick you out of a crowd. Combined with everything else the same scripts measure, it gets much closer.

The audio is the small part

Callaghan’s inspection of the bundles found code that also queries or measures canvas rendering and toDataURL(), WebGL renderer information and shader precision, screen and viewport dimensions, device pixel ratio, hardware concurrency and device memory, installed browser plugins, supported audio and video formats, WebRTC behaviour, performance timing, mouse, touch, focus and scroll events, device motion and orientation, and properties commonly associated with browser automation. The results are serialised, encrypted and sent to Alibaba telemetry services via fetch() or sendBeacon().

Brave says it blocks these specific AliExpress scripts by default, with no settings change required, and that it has randomised audio fingerprints by default for more than six years — injecting random data so that each site sees a different fingerprint, which also resets between sessions. Those are Brave’s own claims, made in a thread published on 22 August.

It is worth being fair about the motive. Callaghan is, and says so plainly: a marketplace this size has real problems with account takeovers, fake accounts, scraping, automated purchasing, payment fraud and coupon abuse, and cookies are a poor tool for that because they can be cleared or copied. A fingerprint assembled from dozens of independent measurements is much harder to fake. From AliExpress’s side, this plausibly means fewer CAPTCHAs for genuine customers.

The objection is not that fraud detection exists. It is that this particular implementation runs on the general shopping homepage, before you have done anything sensitive like logging in or paying; that it collects a very broad set of device and behavioural signals; that it is deliberately hard to inspect; and that there is no indication anywhere in the browser UI that a page has started a live audio-processing graph. Nothing visible in the browser tells you it is happening, and the one control that looks like it should stop it — mute — does not. What the data is retained for, how long, and whether it is linked across other Alibaba properties is not something anyone can determine from the browser side.

How to block it

Callaghan tested blocking the two script families with uBlock Origin, and reports the homepage still renders normally with no audio contexts created. If you use uBlock Origin, here is his method.

  1. Open the uBlock Origin dashboard and select My filters.
  2. Add these two lines: ||assets.aliexpress-media.com/g/AWSC/uab/*/collina.js$script,domain=aliexpress.com and ||assets.aliexpress-media.com/g/AWSC/fireyejs/*/fireyejs.js$script,domain=aliexpress.com
  3. Click Apply changes.
  4. Close any AliExpress tabs that are already open, then reopen the site. This step matters: blocking a script does not shut down an audio context it has already created.

Two honest caveats, both from Callaghan. These rules are deliberately narrow — they target only the two observed script paths, only on aliexpress.com — so a version or path change on Alibaba’s side can break them. And because the scripts are tied to anti-fraud systems, blocking them may produce extra CAPTCHAs or trouble at login or checkout; he suggests temporarily disabling the rules if a legitimate login or payment is refused.

Callaghan also noted a Mozilla bug report open on the underlying behaviour, bug 1863193, covering the way a silent Web Audio graph can hold the audio path open.

Why this matters if you have never used AliExpress

AliExpress itself is not the point for most Indian readers — its app was blocked here in the November 2020 tranche of 43 Chinese apps banned under Section 69A of the IT Act. The technique is the point. Web Audio fingerprinting is a general method, it is not unique to Alibaba, and it works on any site that cares to implement it. The defences are general too: a content blocker, a browser that randomises fingerprinting surfaces by default (Brave says it does this by default; Firefox offers a resistFingerprinting mode), and keeping shopping in a separate browser profile from anything you are signed in to.

The uncomfortable part is how this surfaced. It was caught because it broke a pair of headphones. If you are wondering how much of this runs on sites where it does not break anything, that is the right question, and there is no way to answer it from the outside. If you want a related read, we recently covered the 700-plus fake VPN extensions found on the Chrome Web Store — another case where the thing marketed as protecting your privacy was doing the opposite.

Sources: Matt Callaghan (laserphile), via gHacks