Research
We drive innovation in privacy and security for cellular technologies alongside leading research institutions.
- Technical Explainer08.03.26 · The Cape Team
Audit of Disappearing Call Logs
The cybersecurity research firm Trail of Bits conducted an audit of our Disappearing Call Logs feature in May and July of 2026.
- Technical Explainer07.14.26 · The Cape Team
Cape is SOC 2 Type 2 Compliant
Cape has secured SOC 2 Type 2 certification on all five Trust Service Criteria (TSC): Security, Availability, Confidentiality, Processing Integrity, and Privacy. While most SOC 2-compliant companies only cover the Security TSC, only 5% go for the Privacy category, as it’s the rarest and hardest to get.
- Research06.29.26 · Mijin Shin, Wooram Park, Sangwook Bae, CheolJun Park, Seongmin Kim
Accountable Cross-Operator 5G Charging via TEEs
Presented at Wisec 2026. The 5G core network's control plane operates under a trust-based model. While sufficient for single-operator deployments, the model breaks down in cross-operator settings. In this work, we revisit this trust assumption from a charging accountability perspective. We identify key attack surfaces in cross-operator charging workflows by analyzing charging-relevant operations across network functions, where visibility is inherently limited. We derive design goals for accountable charging, outline a Trusted Execution Environment (TEE)-based approach that enables verifiable execution of charging-critical functions, develop a roaming testbed using Open5GS integrated with an online charging system, and conduct a preliminary evaluation of the TEE-based approach by measuring its overhead on charging-critical operations.
- Technical Explainer05.21.26 · Keegan Stoner and Sean Hutchinson
Signaling Attacks and How Cape Protects You
Signaling is also one of the most overlooked attack surfaces in mobile security. Signaling attacks let adversaries track your real-time location, intercept your text messages, redirect your calls, make calls or send messages from your number, block your service, disrupt entire networks, and more.
- Technical Explainer05.21.26 · David Dunn, Chief Architect at Cape
What Happens During a Cellular Connection?
The telecom industry is essentially a massive, private internet. It interconnects globally through private exchanges and fiber connections in ways that are rarely visible or accessible to the public. When you finally peek underneath the hood of these networks, you realize the entire architecture is held together with duct tape and bubble gum. This outdated system relies heavily on implicit trust. This inherent trust makes your mobile connection highly vulnerable to tracking and exploitation, sometimes by design and sometimes by unintended consequences. Here is the technical reality of what happens during your cellular connection.
- Research05.19.26 · Taekkyung Oh, Duckwoo Kim, Hansung Bae, Beomseok Oh, CheolJun Park, Tyler Tucker, Nathaniel Bennett, Sangwook Bae, Byeongdo Hong, Patrick Traynor, Yongdae Kim
Devilray: A Systematic Adversarial Model Revealing Blind Spots in Fake Base Station Detection
Barriers to accessing commercial fake base stations (C-FBS) have limited visibility into real-world operation and forced detection systems to be designed around self-built prototypes. In this paper, we present Devilray, a reconfigurable baseline designed to explore the realistic adversarial space and identify blind spots in current detection. Devilray enables the systematic exploration of 2,592 feasible and realistic FBS instances, capturing a wide range of operational possibilities. Using Devilray, we evaluate seven FBS detectors and uncover coverage gaps across all seven, revealing blind spots rooted in assumption-bound design and evaluation.
- Technical Explainer05.07.26 · Keegan Stoner, Software Engineer at Cape
How IMSI Rotation Defends Against Paging Attacks
Your phone is almost always in your pocket, and even when you're not making a call or browsing the web, it's quietly listening for the network to reach out. This background process, called paging, is how your carrier notifies your device of an incoming call, text, or app notification. It's invisible, automatic, and without proper protections, can be exploited. Paging attacks have been known for years, but in 2019 a team of researchers from Purdue University and the University of Iowa led by Prof. Syed Hussain presented a research paper demonstrating a new family of vulnerabilities. With a few silent phone calls and around $200 of hardware, an attacker in your vicinity can confirm your location with nearly 100% accuracy. For users on a typical carrier, these attacks are serious and largely unaddressed. Cape's IMSI rotation mitigates these attacks, and this post explains how.
- Technical Explainer03.19.26 · Ben Iofel, Software Engineer
Cell Phone Networks are Just Microservices
If you’ve ever wondered how a cell phone carrier works, and looked up a 4G/5G network architecture diagram, you may have found a confusing mess of acronyms and arrows, felt your eyes glaze over, and given up like I did. Here's what I wish someone had told me: ignore the acronyms. It's just microservices.
- Technical Explainer02.02.26 · The Cape Team
Disappearing Call Logs Explained
Call and text logs document every call and text you make or receive, including their duration and your location at the time. Anyone with access to your call logs would be able to identify your closest relationships, locate your home and workplace, and reconstruct your daily routine at a level of detail and specificity that you yourself couldn’t achieve. We run our own mobile core. That means that unlike other mobile virtual network operators, or MVNOs, we produce our own logs. Cape deletes call and text metadata in days instead of years. This post includes a technical deep dive into how the feature works.
- Technical Explainer01.27.26 · The Cape Team
Secure Global Roaming Explained
Our secure global coverage gives you the power of international roaming without exposing your identity or communications. This post details the risks of standard global roaming, and the multiple layers of protections Cape has implemented to protect against these threats while you are roaming abroad.
- Technical Explainer12.17.25 · The Cape Team
Identifier Rotation Explained
Your IMSI is a unique number assigned by your mobile carrier when you sign up for service. It lives on your SIM card and typically never changes. Cape’s Identifier Rotation automatically rotates your IMSI on a daily basis, and also allows you to change your IMSI on-demand within the Cape app. This post details how the feature works, what it can and cannot protect you from, and more.
- Research06.30.25 · Maurice Zhang, Stephen Dowhy, John Doyle, David Dunn, Joel Cornett, Sangwook Bae
When Diameter Firewall Meets User Devices
A Diameter firewall is essential for mobile operators to protect their subscribers, as Diameter networks lack end-to-end authentication and heavily rely on trust among partner operators. This poster introduces a user-interactive Diameter firewall, which incorporates user engagement by allowing subscribers to confirm suspicious attach requests.
- Technical Explainer03.18.25 · The Cape Team
Encrypted Voicemail Explained
Traditional telco often avoid encrypted due to added complexity. Cape encrypts all voicemails at rest, and they can only be decrypted by our subscribers. This post details how our Encrypted Voicemail feature works to encrypt both the content and metadata of your voicemail messages.
- Research02.03.25 · Sangwook Bae
Cell Site Simulators at the DNC: Collaborating with EFF to Improve Detection
Cape worked with The Electronic Frontier Foundation (EFF) on research and advancements in Cell Site Simulator (CSS) detection to develop the EFF's Rayhunter tool. By reanalyzing wireless signal data collected during the event, Rayhunter was able to detect irregular control plane data flow indicative of a CSS.
- Research12.04.24 · Taekkyung Oh, Sangwook Bae, Junho Ahn, Yonghwa Lee, Tuan Dinh Hoang, Min Suk Kang, Nils Ole Tippenhauer, Yongdae Kim
Enabling Physical Localization of Uncooperative Cellular Devices
Presented at Mobicom 2024. Authorities may need to physically locate user devices to track criminals or illegal equipment by monitoring uplink signals with cellular operator assistance. This research introduces the Uncooperative Multiangulation Attack (UMA), which overcomes key challenges in tracking uncooperative cellular devices by forcing continuous transmission, maximizing signal strength, and distinguishing target signals from repeaters.
- Research06.28.23 · Tuan Dinh Hoang, CheolJun Park, Mincheol Son, Taekkyung Oh, Sangwook Bae, Junho Ahn, BeomSeok Oh, Yongdae Kim
LTESniffer: An Open-source LTE Downlink/Uplink Eavesdropper
Presented at Wisec 2023. LTE sniffers are important for security and performance analysis because they can passively capture the wireless traffic of users. However, existing LTE sniffers are limited and cannot decode data traffic. This paper introduces LTESNIFFER, the first open-source LTE sniffer that can passively decode uplink and downlink data traffic. We evaluated the performance of LTESNIFFER on both testbed and commercial network environments, and compared LTESNIFFER with AirScope, a popular commercial LTE sniffer.
- Research04.27.23 · Beomseok Oh, Junho Ahn, Sangwook Bae, Mincheol Son, Yonghwa Lee, Minsuk Kang, Yongdae Kim
Preventing SIM Box Fraud Using Device Model Fingerprinting
Presented at NDSS 2023. SIM boxes play a critical role in international-scale frauds that steal billions of dollars from individuals and MNOs across the globe. In this paper, we propose an access control logic that detects when unauthorized SIM boxes use cellular networks for communication using precise fingerprinting to distinguish device models and types, without relying on IMEI, which can be spoofed easily.
RESEARCH COLLABORATORS

A leading nonprofit defending privacy, free expression, and digital rights in the digital world.
Breakerspace, led by Dave Levin, researches next-gen network and systems security—earning recognition like the Internet Defense Prize.

The Air Force's research arm advances cutting-edge technologies, including cybersecurity and national defense systems.