A USB condom is a power-only adapter that blocks data lines while still allowing a device to receive electricity. It is used to reduce risk when powering hardware from an untrusted or unknown USB source, especially where data transfer is unnecessary and unwanted.
What a USB condom does
A USB condom is a simple inline adapter that keeps the power pins active while disconnecting the data pins. That makes it useful when you need to charge from a USB port but do not want the device to negotiate data transfer or expose itself to an unknown host.
The key idea is separation: a charger can provide electricity without also becoming a path for file sync, device enumeration, or other USB-level communication. In practice, that reduces the attack surface at the physical connection point and gives the user a way to treat charging as power delivery only.
Where it fits in the USB threat model
The adapter matters because USB is not just a power interface, it is also a trust boundary. When a phone, tablet, badge reader, or other hardware is plugged into an unfamiliar source, the data channel may enable unwanted interaction even if the user only intended to charge the battery. A power-only adapter removes that channel by design.
This is why the term is often discussed alongside the risk of public charging stations, borrowed cables, and unknown peripherals. The device is not “secured” in a broad sense, but the data path is deliberately suppressed so the most common USB abuse path is no longer available.
Common uses and practical limits
People use a USB condom in places where charging is convenient but trust is low, such as airports, conference venues, shared offices, or travel setups. It is also a reasonable choice for equipment that never needs data transfer from the charging source, especially when the user wants a quick, low-friction safeguard.
Its protection is narrow, though. It does not stop compromise through the device itself, malicious charging hardware that manipulates power delivery, or attacks that happen through other interfaces already enabled on the device. It also depends on the adapter being correctly built so the data lines are truly blocked.
How it differs from other charging or privacy accessories
A USB condom is different from a normal cable, a power bank, or a charge-only port on a wall adapter because the security value comes from physically eliminating the data connection. That makes it a hardware control rather than a software setting.
It is also different from broader identity or access controls because it does not verify trust in the source, it simply prevents the data relationship from forming. That makes it especially useful as a portable, defensive default when the user wants power but not interaction. For broader control context, practitioners often pair this kind of physical safeguard with baseline hardening guidance such as the CIS Benchmarks, which address device and platform configuration rather than the cable itself.
Risk and Threat Considerations
USB charging ports can become an entry point for data exposure, unwanted device enumeration, or malicious accessory behavior when users rely on unfamiliar power sources. A power-only adapter reduces that exposure by removing the data path, but it only helps if the adapter is trustworthy and the use case is actually charge-only.
Failure mechanism: If the data lines are not fully isolated, the connected device may still negotiate USB communication, making it vulnerable to malicious hosts, rogue accessories, or accidental data exchange.
Impact: The result can be leakage, unauthorized device interaction, or a wider compromise path through an otherwise ordinary charging action.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 provides the primary governance reference for this term.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-6 — Access Control Management | USB condoms enforce a no-data connection at the physical trust boundary. |
| Recommendation — Use portable power-only adapters to prevent unintended data access from untrusted USB sources. | ||
Practitioner Guidance
What to watch for: Treat the adapter as a convenience control for low-trust charging, not as a universal security solution. It is most appropriate where the user controls the device, needs only power, and wants to eliminate a known interaction path.
Practitioner note: The most important operational question is whether the charging source is trusted enough to permit data at all. If the answer is no, a charge-only adapter is a clean way to enforce that decision at the physical layer.
Related resources from NHI Mgmt Group
- How should security teams control data loss when USB ports are already blocked?
- What breaks when organisations rely only on USB blocking for device security?
- What breaks when USB and application controls are not enforced consistently?
- Why do USB and peripheral controls still matter in modern DLP programmes?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 29, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org