CELLEBRITE▊
The phone-cracking kit in every evidence room — whose own software, per the maker of the app it most famously cracks, was left unlocked: parse-everything forensics built with, Signal claimed, almost none of the defenses it exists to defeat.
- ENTITY
- Cellebrite DI Ltd., Petah Tikva, Israel — maker of UFED and Physical Analyzer, phone-extraction forensics sold to police and governments FACT
- OPERATION
- Unlock the seized phone, extract everything, generate the report the prosecution stands on — "Protect and Save Lives, Accelerate Justice" (the company's stated mission)
- EVENT
- COUNTER-EXPLOITED — Signal's founder published exploitable flaws in the extraction stack itself, April 2021 ATTRIBUTED
- PATTERN
- Recurring reporting that the kit reached regimes that used it on journalists and activists — followed, repeatedly, by the company halting that market ATTRIBUTED
- DISPOSITION
- No court finding against the company in this record. Patched (per reporting); still selling; still the industry default FACT
Cellebrite, official channels — X: @Cellebrite (linked from cellebrite.com). CEO Yossi Carmil, in the company's own March 2021 announcement halting sales to Russia and Belarus:
"Cellebrite empowers law enforcement agencies and enterprises to make our communities safer by providing solutions that help lawfully acquire digital evidence in criminal investigations and civil proceedings… As part of our standard business operations, we regularly review and update our compliance policies to ensure we operate according to accepted international rules and regulations."
The company's ethics page states it maintains "strict controls ensuring that our technology is used appropriately in legally sanctioned investigations," that sales vetting considers "a potential customer's human rights record," and that its mission is to "Protect and Save Lives, Accelerate Justice, and Preserve Data Privacy."
This specimen is not a charlatan. The kit works — that is precisely why every evidence room has one, and why what follows matters. Cellebrite occupies the strangest niche in the surveillance food web: it is the predator whose entire diet is hostile data — it exists to swallow the contents of adversarial, untrusted phones — and in April 2021 the maker of the most famous prey species published its claim that the predator had been swallowing all those years without armor.
Read the tags with care. Nothing on this page is adjudicated. Signal's exploits are a rival's demonstration, stated as Signal's. The sales reporting wears its outlets. The strongest documents against the company are, in a genuinely uncommon twist, its own press releases — each halt a receipt for the market it halted. Both sides get the microphone below.
▸ The mechanism — how Cellebrite's tooling fits the surveillance-and-capture apparatus — is analyzed and scored on evilrobots.lol: the operator profile. troll.fan keeps the drama; the apparatus lives there.
the drama timeline
ACT I — THE BOAST (DEC 2020)
Every display cycle in this drawer begins with a claim someone couldn't resist making. This one was about cracking the one app whose founder writes exploits recreationally.
-
DEC 2020
"Cellebrite claimed to have 'cracked' chat app's encryption"
Cellebrite publishes a blog post saying it can decrypt messages from Signal, boasting the capability could disrupt "gang members, drug dealers and even protesters." Critics reply that the technique described requires an unlocked phone already in hand — a state in which, as one put it, "they could have also just opened the app to look at the messages." Per the BBC, the post "has since been altered." Citizen Lab's John Scott-Railton reassures users that Signal "remains one of the most secure and private ways to communicate."
Note the word "protesters," sitting in a sales pitch between the drug dealers and the gang members. The field noticed it too.
ACT II — THE TRUCK (APR 2021)
Four months later, a package falls off a truck in front of the one pedestrian on Earth least likely to return it unopened.
-
APR 21 2021
Signal publishes the exploits
Moxie Marlinspike, having acquired a Cellebrite kit by what his post describes — with a straight face — as "a truly unbelievable coincidence" involving a package that "fell off a truck," publishes Signal's findings: "very little care seems to have been given to Cellebrite's own software security. Industry-standard exploit mitigation defenses are missing, and many opportunities for exploitation are present." Exhibit A: bundled FFmpeg DLLs "built in 2012 and not updated since," missing over a hundred security updates. The centerpiece claim: a "specially formatted but otherwise innocuous file" in any app on a scanned phone can execute arbitrary code on the Cellebrite machine — "virtually no limits" — and can alter the current report and all previous and future reports, "with no detectable timestamp changes or checksum failures."
The inversion the field savored: the forensics rig that eats untrusted phones for a living had, per Signal, never learned to chew safely. The scanner became the scanned.
-
APR 2021
The wink — and the evidentiary shadow
Signal's post closes with a taunt dressed as a product note: future versions of the app will "periodically fetch" files that are "aesthetically pleasing," with "no other significance." The implication for prosecutors — that any phone might now claim to carry a report-corrupting file — is the point of the joke. For the record this archive keeps: no actual case of altered Cellebrite evidence is documented here; what Signal published is a capability claim, and what it planted is doubt.
-
APR 2021
Cellebrite patches
Cellebrite pushes a software update to customers, per Vice's reporting ("Cellebrite Pushes Update After Signal Owner Hacks Device"). The company's standing public position on its software: it "continually audits and updates" its offerings. The fix is the defense's best exhibit from this act: the claim was met with remediation, not litigation.
ACT III — THE CLIENT LIST (2020–2025)
A forensic tool has no politics; its purchase orders do. This act is the ledger of markets entered, reported on, and then — on the company's own letterhead — exited.
-
OCT 2020
Hong Kong & China: halted
After campaigning over Hong Kong police use of its tools during the protest crackdowns, Cellebrite announces it will stop selling its solutions in Hong Kong and China. The announcement is the company's own.
-
MAR 2021
Russia & Belarus: halted — after Haaretz
Cellebrite announces, effective immediately, a stop to sales in the Russian Federation and Belarus. Haaretz reports the halt followed its reporting on the tools' use against opposition figures and minorities in Russia.
-
AUG 2021
Bangladesh: halted
Cellebrite says it has chosen to halt sales to Bangladesh, per Haaretz — following reporting that its tools had been sold for use by the Rapid Action Battalion (RAB), the paramilitary unit that would later be sanctioned by the US Treasury over human-rights allegations.
-
DEC 2024 – FEB 2025
Serbia: Amnesty's forensics, then the cutoff
Amnesty International reports that Serbian police and intelligence used Cellebrite tools to unlock the phones of a journalist and an activist — and that spyware was covertly installed during the unlocks. Cellebrite subsequently stops sales to the Serbian customers, per TechCrunch's reporting — which also poses the question that titles its 2026 follow-up: "why not others?"
The pattern, four times now: the reporting surfaces, the company investigates, the customer is cut off. The defense reads that ledger as compliance working. The case reads it as a vetting process that keeps learning geography one exposé at a time.
both sides, on the record
The forensic emperor's clothes (Signal's claim, not ours): the tool that generates court evidence from hostile devices shipped, per Signal's demonstration, without industry-standard exploit mitigations, parsing untrusted data with 2012-era libraries — and a booby-trapped file could allegedly rewrite its reports undetectably [1] [2].
The boast it had to edit. It publicly claimed to crack Signal — naming "protesters" among the targets — and the post was altered after expert ridicule [4].
The client ledger, in its own releases. Hong Kong, Russia, Belarus, Bangladesh, Serbia: each halt announcement doubles as the company's own receipt that the kit was there — and Amnesty's Serbia forensics document what one such customer did with it [5] [6] [7] [8].
Consider the source of Act II. The exploits were published by the maker of the app Cellebrite parses — an adversary with an openly declared interest, in a post written as a taunt — and describe a capability, not an event. No case of actually altered Cellebrite evidence appears in this record. Cellebrite pushed an update in response [3], and its stated practice is to continually audit and update its software [10].
The tool is lawful-access forensics, not remote spyware. It requires the device physically in hand and, in the company's words, supports "lawfully acquire[d] digital evidence in criminal investigations and civil proceedings" — the workaday machinery behind solved homicides, trafficking and child-exploitation cases worldwide [6] [10].
The halts are compliance, functioning. The company says its vetting weighs customers' human-rights records; when abuse reporting surfaced, it exited Hong Kong/China, Russia/Belarus, Bangladesh, and the Serbian customers — on its own letterhead, repeatedly, at the cost of revenue [5] [6] [7] [9]. Nothing on this page is a court finding against the company.
YOU DECIDE
Scoped to the claims. That Cellebrite claimed to crack Signal and then altered the post is on the BBC's record. That its own software was exploitably careless is Signal's demonstration — vivid, technically detailed, published by an adversary, answered with a patch, and never tested in a courtroom. That its tools reached governments that abused them is the named outlets' and Amnesty's reporting — corroborated, uniquely, by the company's own exit announcements. Nothing here is adjudicated.
Weigh the costly signals on both sides. The company walked away from four markets on its own letterhead — paid compliance, in real revenue. And the field's counter-receipt: the vendor whose product is trusted extraction of untrusted data was shown, by the untrusted data's most motivated author, what its own threat model looked like from the inside.
The archive does not judge. It keeps the reports — and notes, per Signal, who else might have.
evidence locker
THE DEMONSTRATION & RESPONSE
Signal — "Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer from an app's perspective" (Apr 2021) ATTRIBUTED — the demonstration and claims, in the adversary's own words; adversarial provenance disclosed on this page.
signal.org/blog/cellebrite-vulnerabilities/
The Register — Signal's Moxie says it's possible to sabotage Cellebrite's phone-probing tools with a booby-trapped file (Apr 2021) ATTRIBUTED — independent contemporaneous coverage of the claims.
theregister.com/2021/04/21/signal_cellebrite/
BBC News — "Signal: Cellebrite claimed to have 'cracked' chat app's encryption" (Dec 2020) ATTRIBUTED — the boast, the ridicule, and the altered post.
bbc.com/news/technology-55412230
THE CLIENT LEDGER
SUBJECT'S OWN CHANNELS — THE DEFENSE, UNEDITED
@Cellebrite on X SELF-PUBLISHED — the official account, verified first-party via the link on cellebrite.com.
x.com/Cellebrite
The standard. Nothing on this page is a court finding, and the page says so. Signal's exploits are stated as Signal's demonstration and claim, with the adversarial provenance disclosed and the absence of any documented real-world tampering case stated outright. The December 2020 boast and its alteration are the BBC's record. Sales reporting wears its outlets — Haaretz, Amnesty, TechCrunch — and its strongest corroboration is the company's own halt announcements, cited as the company's own acts. The defense — lawful forensics, physical possession, the patch, the exits — is presented at full strength. No motive is asserted, no fraud alleged. If it couldn't survive a defamation challenge, it wouldn't be on this page.