Security1 publisher3 min readPublished
The EncroChat "national security secret" was exploit code sitting on GitHub
Computer Weekly says a Czech firm rehacked France's EncroChat implant and found GitHub exploit code for Bad Binder, an Android bug unpatched in 2.5 billion phones. Lawyers expect a stalled UK case to restart.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Computer Weekly reveals for the first time how French cyber spies hacked EncroChat phones, used by organised crime groups, in 2020; the investigation is by Computer Weekly and the Sussex Centre for Law and Technology (SCLT).
- A Czech spyware company, Invasys, rehacked the French hack; its report was obtained by Computer Weekly.
- French malware described as a national security secret had been copied from the popular code-sharing platform GitHub.
- The secret French state hacking group used an Android exploit first spotted in 2017.
- For two years, a fatal security vulnerability known as the Bad Binder bug was left unpatched inside 2.5 billion phones, leaving users at maximum risk.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Computer Weekly, working with the Sussex Centre for Law and Technology, has published the first detailed account of how French state hackers broke into the EncroChat cryptophone network in 2020, based on a report by Czech security company Invasys that rehacked the French hack [1][2]. The finding that matters for every unresolved EncroChat case is this: the French malware, which France has insisted is a national security secret, was built on exploit code copied from the code-sharing site GitHub [2][3].
The vulnerability was Bad Binder, an Android flaw first spotted in 2017 and left unpatched for two years across an estimated 2.5 billion phones [4][5]. It gave an attacker complete control of an infected handset, including the ability to copy or alter a user's data, programs and files [6]. Felix Freiling, a computer forensics professor at Friedrich-Alexander-Universitaet in Germany, told Computer Weekly the bug code uncovered by Invasys "looks like a student project", apparently including exploit code copied from the internet [7]. He also called the Czech work "unique [and] an impressive breakthrough" that "answers a lot of questions" [8].
The report describes an implant that was poorly written, failed repeatedly, and lacked elementary countermeasures against detection [9]. Reverse engineering of the recovered code shows messages being "hooked" inside the targeted handset and copied almost immediately to police investigators [10]. The Czech rehack also produced digital fingerprints matching the French evidence distributed to police forces across Europe, which the investigation treats as proof of how messages were copied [11].
That is the point of legal contact. In Britain, thousands of cases have been judged and sentenced with no explanation of how the data was obtained, because the French authorities stipulated that the method was a matter of national security [12]. The Investigatory Powers Tribunal case testing the legality of the police tactics has been adjourned for more than two years, waiting for a finding on how the hack was actually carried out [13]. British lawyers told Computer Weekly the exposure of the method is likely to restart it [14], and that if the full facts had been available when trials began in 2020, it would be "open to question whether courts were properly informed" [15].
Matthew Ryder KC, lead counsel in the UK's first EncroChat trial, called the investigation a "landmark breakthrough" and said it "is bound to have consequences for the ongoing legal argument and on legal principles relating to interception and computer interference" [16]. The Dutch criminal lawyer Justus Reisinger, part of the European defence team contesting the evidence, said the material is "vital for EncroChat trials and appeals" and that defence teams have been asking for it for six years [17].
One arithmetic detail deserves scrutiny rather than assertion. If Bad Binder was spotted in 2017 and went unpatched for two years, the window of mass exposure closes around 2019, before the 2020 interception [18]. Which handsets in the EncroChat fleet were still carrying the unpatched flaw, and why, is not settled by the material published so far.
Watch whether the tribunal relists the adjourned case and on what disclosure terms, whether Invasys's findings are put before courts in the Netherlands as well as the UK, and whether French authorities maintain the national security stipulation now that the underlying exploit is documented as public code [3][12][13].