Skip to content

Everyday privacy · Updated September 2026

Are there spy chips in your phone? What's real, what isn't, and what a privacy phone can't fix

Small changes add up.

Every so often a video does the rounds claiming there are spy chips hidden in your phone, put there by whoever made it. It gets millions of views, because it taps something reasonable: you carry a device you cannot open, made by companies you have never met, out of parts from factories you will never see. Trusting it is a real question.

Here is the honest answer, and it has three parts. Hidden hardware is real, but it has been the work of intelligence agencies against chosen targets. The most famous claim of spy chips in ordinary kit was never proven. And there is a genuine hardware trust problem in every phone, including ours, which is the bit nobody selling you a privacy phone wants to mention.

The short answer

  • Hidden hardware exists: documented in the Snowden files, aimed at specific targets, mostly network equipment rather than consumer phones.
  • Devices can be tampered with before delivery: proven in 2024, in an attack on one organisation's pagers and radios, not on phones bought from a shop.
  • The famous “spy chip” story about servers was denied in detail by every company named and has never been corroborated.
  • The real hardware weak point in your phone is the modem, the part that talks to the mobile network. A de-Googled phone does not remove it.
  • What actually empties people's accounts is phishing, scam calls and app permissions. UK losses ran to £1.28 billion last year.

1. Hidden hardware is real, and it was aimed at targets

In December 2013, Der Spiegel published a leaked 50-page catalogue from an NSA division called ANT, listing tools for getting inside equipment from Cisco, Huawei, Dell and others. One of them, a firewall implant, was designed to survive “across reboots and software upgrades”, which is exactly the property that makes hardware level access worse than a virus.

So the capability is documented, not theoretical. What the same documents also show is the shape of it: expensive, specialised tools, aimed at chosen targets, largely at the routers and firewalls that carry other people's traffic. Nothing in that catalogue suggests a chip quietly added to every handset on a production line. If you are a journalist, an activist or a government supplier, hardware attacks belong on your list. For almost everyone reading this, they do not.

2. Tampering in the supply chain: the 2024 pagers

In September 2024, thousands of pagers and walkie-talkies carried by people in Lebanon and Syria exploded within minutes of each other. The UN human rights chief said the “simultaneous targeting of thousands of individuals”, without knowing who held the devices or where they were, violated international human rights law.

We are not going near the politics of that. The point for this guide is narrow and important: the devices had been tampered with somewhere between the factory and the people carrying them. The security researchers who analysed the attacks treat it as a hardware supply chain problem, and argue that physical inspection has to become part of how we secure devices.

What it does not show is any risk to a phone you buy from a UK shop. Those were devices bought in bulk and handed out to a known set of people, which is what made an attack like that possible in the first place. It is evidence that a supply chain can be poisoned, not evidence that yours has been.

3. The spy chip story that never stood up

In October 2018, Bloomberg Businessweek reported that tiny malicious chips had been found on server boards used by Apple, Amazon and others. It is still the story people mean when they say “spy chips”.

Every company named denied it in unusually direct terms. Apple published a point by point rebuttal saying “Apple has never found malicious chips, ‘hardware manipulations’ or vulnerabilities purposely planted in any server”, that it had investigated each enquiry and found “absolutely no evidence”, and that it had never been contacted by the FBI about such an incident. Amazon and Supermicro denied it too. In the years since, no independent investigation has produced the chips or corroborated the account.

We are not telling you Bloomberg was wrong, because we cannot know that either. We are telling you it is unproven, which is where the evidence sits, and that a claim this big with no artefact behind it should not be repeated as fact. That cuts both ways: it is also why we will not tell you the phones we sell are provably clean at the silicon level. Nobody can tell you that.

4. The real hardware trust problem: the modem

Inside your phone, alongside the operating system you interact with, sits the modem, sometimes called the baseband. It is the part that registers with the mobile network, handles calls and texts, and keeps the phone reachable. It runs its own firmware, written by the chip maker, and you cannot inspect it or update it independently of the manufacturer.

You do not have to take our word for how much trust that deserves. The GrapheneOS developers, who build the operating system on the phones we sell, treat the modem as something to be contained. Their documentation says the baseband is isolated on every officially supported device, that its “memory access is partitioned by the IOMMU and limited to internal memory and memory shared by the driver implementations”, and that there is “a lot of attack surface between the baseband and the kernel/userspace software stack connected to it”. Their features list includes an LTE only mode specifically “to reduce cellular radio attack surface by disabling enormous amounts of both legacy code (2G, 3G) and bleeding edge code (5G)”.

That is the honest state of things: the risky component is walled off and watched, rather than trusted or removed. And the plainest limitation of all is not secret at all. Connecting to a mobile network means identifying yourself to it, as GrapheneOS puts it, so your network knows which mast your phone is near, whatever operating system you run. Flight mode genuinely stops that, because it turns the radio off.

5. What a de-Googled phone fixes, and what it cannot

This is the part we would rather you heard from us than found out later.

  • It does fix: Google's own collection from the operating system and its apps, the advertising identifier, and the constant background check-ins that come with stock Android. Our free guide walks through doing it yourself.
  • It does not remove the modem, the SIM, or your network's records of where your phone has been.
  • It does not exempt you from ID or age checks. See what happened to digital ID and the Online Safety Act.
  • It does not stop you installing something that tracks you. Apps you choose, and permissions you grant, are still yours to manage.

Anyone selling a phone on the promise that it makes you invisible is selling you a story. That is the whole reason this site exists.

6. The hardware you can actually check

Hardware trust is not all or nothing. Some of it is verifiable, and some of it you can switch off yourself.

  • Verified boot. Android's published design “strives to ensure all executed code comes from a trusted source”, checking each stage of startup before the next one runs. On a Pixel running GrapheneOS you can confirm the phone is running the software it claims to be running.
  • An independently tested security chip. Google publishes the certifications for the Titan M2 secure microcontroller in Pixels, including a Common Criteria certificate from TrustCB (reference CC-2300073-01). Published evaluation is not proof of perfection, but it is the opposite of “trust us”.
  • Port control. GrapheneOS can disable the USB data lines in hardware when the phone is locked, its default being “charging-only when locked”.
  • A sensors switch. It can also block apps from the accelerometer, gyroscope, compass and barometer, feeding them “zeroed data” instead, which stock Android does not offer.
  • Physical answers for physical worries. A pouch for car keys, a cover over a laptop camera, and flight mode when it matters. Our guide to gadgets that physically block tracking sorts the useful from the gimmicks, and the ones we rate are on our everyday kit page.

7. Meanwhile, what is actually happening to people

UK Finance reported in June 2026 that criminals stole £1.28 billion through payment fraud in 2025, of which £576.4 million was authorised push payment scams, where someone is talked into sending the money themselves. Most of those cases, 66 per cent, started online, and another 17 per cent came through phone networks.

None of that needed a chip in anybody's phone. It needed a convincing email, a call that sounded like the bank, or a cheap shop that never posts anything. Which is why the boring list beats the exciting one.

What to do, in order

  1. Install updates. The single biggest difference, and free. If your phone has stopped getting them, that is the real end of its life: see how long a phone gets updates.
  2. Protect your accounts. Different passwords and 2-step verification on email and banking, because email is the key to everything else.
  3. Learn the two scam patterns that get most people: fake emails and calls pretending to be your bank.
  4. Check app permissions, especially location and microphone, and delete the apps you never open.
  5. Get yourself off the data broker lists, which is tedious and free: how to do it.
  6. Then, if you want to, de-Google the phone. It removes a genuine and constant source of collection, and you can do the whole thing yourself for nothing.
  7. Hardware bits last. Pouch, port blocker, camera cover. Cheap, narrow, fine to own.

The test we would apply to any claim

When someone tells you there is a spy chip in your phone, ask three things. Who documented it, and can you read that document? Does the claim describe a targeted operation or something done to everyone? And what exactly are they selling you on the back of it?

Applied to us, the answers are: the sources above, mostly targeted operations, and a refurbished Pixel with the Google software taken off it, which we will happily tell you how to do yourself for free.

Blink saysYou don't have to do it all today. Change one setting from this guide and you're already better off.

Get the scam alert free, monthly.

Once a month: the scams going round the UK, what they look like and what to do. Checked against official sources. Plus our free de-Google guide.

We hate spam, and we'd never sell your data. That would be a bit rich, wouldn't it?

Want off Google without the faff?

You can do it yourself for free. Our free guide shows you how. Or we'll set up a de-Googled Pixel and send it to you, ready to use. No fear-selling, and one flat fee for the work.