On September 11, 2025, roughly 500 GB of internal material from Geedge Networks and the MESA Lab at the Chinese Academy of Sciences’ Institute of Information Engineering surfaced online, posted by the collective Enlace Hacktivista, the same group previously tied to the Cellebrite leak. Some analysts put the cache closer to 600 GB.
It held source code, RPM build packages, technical manuals, internal email, and work logs: the operational guts of the systems that filter China’s internet. GFW Report, the watchdog that has tracked the Great Firewall for years, called it the largest exposure in the system’s history.
Geedge is not a state agency. It was founded in 2018 in Hainan, with Fang Binxing, the engineer widely credited as the architect of the original firewall, serving as chief scientist alongside CTO Zheng Chao. That detail reframes the whole story.
The firewall reads less like a shadowy government monolith and more like a procurement relationship between agencies and a private vendor with a product catalog and a support contract.
Most users assume a VPN dies in China because the firewall decrypts it. It doesn’t, and it doesn’t have to. The leaked code shows detection working on metadata and behavior instead. Deep packet inspection classifies traffic by shape and signature where plaintext exists.
Where it doesn’t, the system falls back to active probing: after flagging a suspicious connection, the firewall fires its own crafted packets at the destination server to watch how it answers. A circumvention endpoint tends to respond in ways an ordinary web server never would, and that single reply is enough to fingerprint and blacklist it.
This lines up with research that predates the leak. A 2023 USENIX Security paper documented how the firewall started catching “fully encrypted” traffic, meaning connections with no recognizable protocol header, by measuring the randomness of the bytes themselves.
High entropy with zero plaintext fields is itself the giveaway. The Geedge trove supplies the missing half: the same heuristics, written down in a vendor’s repository, with the thresholds and the tuning attached.
The practical consequence is unforgiving. A protocol that slips through this month can be cataloged the next, and the only honest guide is recent on-the-ground testing rather than vendor marketing. Gizmodo keeps a running comparison of the services that still hold up from inside China, the kind of reference that ages out fast and has to be rechecked precisely because the detection side keeps shipping updates.
Geedge packages this commercially under the name Tiangou Secure Gateway. The documents describe DPI content inspection, dedicated VPN and circumvention-tool detection, real-time user tracking, content injection, and modules able to degrade or drop connections on command.
Bitdefender researchers reviewing the dump flagged the same capability set, including the ability to inject malware into traffic and to mount denial-of-service against targeted endpoints.
A separate investigation drove the export angle home. Researchers at InterSecLab, working with Amnesty International, Justice for Myanmar, and the Tor Project, spent close to a year combing through roughly 100,000 documents.
Their conclusion: the identical stack has been sold abroad. Deployments or contracts turned up for Kazakhstan, Ethiopia, Myanmar, Pakistan, and at least one unnamed state, several financed under Belt and Road framing. In Pakistan the system can reportedly tie tracking to individual SIM cards. In Kazakhstan it shipped with TLS man-in-the-middle interception.
In Ethiopia, monitoring hardware landed in regional data centers. Provincial builds also run inside China in Xinjiang, Jiangsu, and Fujian, separate from the national apparatus.
One wrinkle says a lot about the supply chain. Investigators found Geedge using Sentinel HASP, a licensing product from a Thales subsidiary, to time-limit client access to its own software.
Thales responded that Sentinel has no role in the surveillance functions and does not contribute to how the system performs. The detail still shows how ordinary Western tooling drifts into a censorship build through nothing more exotic than a licensing dependency.
For anyone watching circumvention from the defense side, the leak closes an old debate. Bill Xia, who runs Dynamic Internet Technology and built Freegate, has argued for years that most consumer VPNs cannot durably beat the firewall because their protocols are too easy to single out.
The code backs him. Shadowsocks, plain OpenVPN, and bare WireGuard all carry signatures or timing behaviors the detection modules already recognize.
What lasts is obfuscation stacked on top: transports engineered to imitate ordinary TLS, or to stonewall the firewall’s probes the way a genuine HTTPS server would. Those hold until the catalog updates.
Reality, domain fronting, and the current crop of mimicry protocols are this round of the fight, and none of them should be treated as permanent. A working configuration is a snapshot, not a guarantee, which is why “which VPN works in China” is a question with a different answer every quarter.
Read one way, the leak is a repression dossier. Read another, every detection method baked into Tiangou is a free test case for anyone building or auditing privacy tools. Security teams can run their own traffic against the documented active-probing and entropy checks before a government does it for them.
Threat hunters get a worked example of how legally-sanctioned infrastructure performs DPI, injection, and interception at carrier scale, which happens to be exactly what a capable adversary would want sitting on a compromised backbone.
The harder part is the sales sheet. A system sharpened against one country’s population is now a SKU with reference customers, and the buyers are governments that could never have engineered it themselves. The Great Firewall stopped being a wall the day it became something with a pricing tier.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…