VOIDEXJournal

Salt Typhoon: The Telecom Hack That Made Encryption Official Advice

State hackers inside US phone networks led CISA and the FBI to tell the public to use end-to-end encrypted messaging. What happened and what it means for you.

By · 6 min read ·
Salt Typhoon: The Telecom Hack That Made Encryption Official Advice

For decades the phone network was treated as part of the furniture. You picked up a handset, you sent a text, and you assumed the system in between was run by large, regulated companies that would keep it safe. In 2024 that assumption broke in public. A state-sponsored group known as Salt Typhoon was found inside the networks of major American telecommunications carriers, and the response from the US government was striking: stop relying on the network, and protect the conversation itself.

At VOIDEX we build a platform on exactly that principle. This article explains what Salt Typhoon was, why the official advice changed, and what practical lessons anyone can take from it, whether or not they ever sit in a government office.

What happened

Salt Typhoon is the name given to a hacking group that US officials attribute to the Chinese state. During 2024, investigators disclosed that the group had gained access to the infrastructure of several large US carriers. The intrusion was not a single stolen password or a phishing email to one employee. It was a presence inside the systems that move calls and messages for millions of people.

Access at that level is valuable for a simple reason. Carriers hold call records: who called whom, when and for how long. They route unencrypted text messages. They also operate systems that exist so that lawful interception requests can be carried out. An intruder who sits inside that machinery can collect a great deal without ever touching a single phone.

The full extent of what was taken has been described in stages and parts of it remain unclear in public reporting. What is clear is the category of the damage: large volumes of communication records, and in some cases the communications themselves, for traffic that was never protected end to end.

The advice that changed

In December 2024, officials from CISA and the FBI briefed reporters on the intrusion and offered advice that would have sounded unusual from a government agency a decade earlier. They encouraged people to use end-to-end encrypted messaging and encrypted calling.

CISA then published mobile communications best practice guidance, aimed first at highly targeted individuals in government and politics. Its core recommendations are worth reading in full, but the headline points are straightforward:

  • Use end-to-end encrypted communications for messages and calls, so the content is protected even if the network underneath is not.
  • Move away from SMS for account security codes. Text messages are not end-to-end encrypted, so a one-time code sent by SMS can be exposed on the network. Phishing-resistant methods such as hardware security keys are stronger.
  • Use a password manager and strong, unique passwords.
  • Set a PIN with your mobile carrier to make it harder for someone to take over your number.
  • Keep devices and software updated.

The guidance is written for people most likely to be targeted, but the logic applies to everyone. If the pipe cannot be trusted, protect what travels through it.

Why end-to-end encryption held up

The most important lesson of Salt Typhoon is what did not leak. When a conversation is end-to-end encrypted, the keys that unlock it exist only on the devices of the people talking. The carrier carries sealed data. An attacker who sits inside the carrier sees the same sealed data. Compromising the network does not compromise the content.

That is a very different model from ordinary SMS and traditional phone calls, where the network itself can see and record what passes through. For those services, the security of your words depends on the security of every system between you and the other person. Salt Typhoon showed how large that attack surface is.

We explain the mechanics in end-to-end encryption explained, but the principle fits in one line: the fewer parties that can read a message, the fewer places it can be stolen from.

What encryption did not protect

Salt Typhoon is also a reminder of the limits. End-to-end encryption protects content. It does not remove the fact that a message or call happened. Carriers still keep records of calls made over their networks, and those records were part of what made the intrusion so serious. A list of who spoke to whom, and when, can map a network of relationships without revealing a single word.

This is the subject of our article metadata is the message. The short version: sealing the envelope is essential, but it is not the whole story. A private platform also has to limit how much it knows about the envelope, and refuse to build a business on it.

There is also a longer horizon to consider. Encrypted traffic that is collected today can be stored and attacked later. That strategy is known as harvest now, decrypt later, and it is the reason modern encryption is moving to post-quantum algorithms now rather than waiting for large quantum computers to arrive.

Where VOIDEX fits

VOIDEX was designed on the assumption that the network is hostile. It is an invite-only, end-to-end encrypted platform, owned by CNOTA, with no ads, no third-party trackers and no selling of data.

In VOIDEX Messenger, direct messages use a hybrid post-quantum key agreement that combines X25519 with ML-KEM-768, followed by a double ratchet with post-quantum re-keying. Each message has its own key, so a compromise at one moment does not unlock the past, and the conversation can recover its security afterwards. Identity signatures combine Ed25519 and ML-DSA-65.

Group chats and private channels use MLS, the IETF standard for group messaging published as RFC 9420. Voice and video calls run over WebRTC with DTLS-SRTP, and the call setup is sealed under the conversation key, so the server cannot quietly swap the encryption fingerprint in the middle. Calls are relayed through VOIDEX's own relay rather than a third party's.

Keys are created on members' devices. VOIDEX servers store public keys and ciphertext. Every device key change is appended to a public, append-only transparency log that clients check before trusting a key, and that anyone can audit. We cover that design in key transparency.

What VOIDEX does not claim is equally important. A messaging service has to route messages, so it knows which accounts exist and that a message is being delivered. VOIDEX sets out what it can and cannot read in its public security report, and the cryptographic core is open source so the claims can be checked rather than taken on trust.

Practical steps after Salt Typhoon

You do not need to be a senator to benefit from the same advice. A short list covers most of the risk:

  1. Move sensitive conversations to an end-to-end encrypted service. Treat ordinary SMS and carrier calls as readable by the network.
  2. Replace SMS codes on important accounts. Use an authenticator app or, better, a hardware security key for email, banking and anything that can reset other accounts.
  3. Add a carrier PIN or port-out lock. It raises the cost of someone taking over your phone number.
  4. Update your phone promptly. Many serious attacks rely on flaws that are already fixed.
  5. Think about metadata as well as content. Prefer services that collect less and do not run on advertising.
  6. Verify the people you talk to. On platforms that support it, check that the keys you are using belong to the person you think.

None of these steps is dramatic. Together they move you from trusting every system in the chain to trusting only the devices at each end.

The larger shift

Salt Typhoon will be remembered as a security incident. It should also be remembered as a moment when the official position on private communication changed. For years, strong encryption was treated in some policy circles as an obstacle. After an intrusion into national telecom infrastructure, government agencies were telling the public to use it.

That shift matters because it reflects a simple truth about modern networks. They are too large, too complex and too valuable to be assumed safe. The durable protection is the one that does not depend on them: encryption that begins and ends on the devices of the people speaking.

VOIDEX is built for that world. It is invite-only: request access, or read exactly what the VOIDEX server can and cannot see first.

Sources

  • CISA, Mobile Communications Best Practice Guidance: https://www.cisa.gov/resources-tools/resources/mobile-communications-best-practice-guidance
  • IETF, RFC 9420: The Messaging Layer Security (MLS) Protocol: https://www.rfc-editor.org/rfc/rfc9420
  • NIST, Post-Quantum Cryptography Standardization: https://csrc.nist.gov/projects/post-quantum-cryptography/post-quantum-cryptography-standardization

Enter VOIDEX

VOIDEX is invite-only and free, with no ads and no trackers. Messages are protected by hybrid post-quantum encryption (X25519 with ML-KEM-768) and checked against a public key transparency log. VOIDEX runs in your browser and as apps for Windows and Mac, with iPhone and Android on the way.

Request access   Get the VOIDEX apps