Why Opsilux exists
Opsilux reads technology without its maker’s help, so that no nation and no company has to depend on technology it cannot verify. This document says why, what we have found so far, and how we read.
1Why we exist
A country runs on devices it did not build. Routers, base stations, solar inverters, industrial controllers: each arrives as a sealed box with compiled software inside, written by someone else and updated from somewhere else. What that software does is taken on trust, because reading it has been slow work for a few specialists.
Trust is not a security property. On the first morning of the war in Ukraine, an attack on one satellite network reached tens of thousands of modems across Europe1. 1 24 February 2022. Malicious commands overwrote data in the flash memory of KA-SAT modems and cut them off the network. In Germany, 5,800 Enercon wind turbines lost remote monitoring and control. Viasat, KA-SAT network cyber attack overview, 30 March 2022; Reuters, 28 February 2022.
A nation, and every company that runs equipment others depend on, should be able to check what is inside it without asking the maker. That is what Opsilux is for.
2What we found
We started with cryptography, because it is the part with a deadline. A large enough quantum computer would break the public-key algorithms that protect updates, connections and access in almost every device shipped today2. 2 RSA, elliptic curves (ECDSA, ECDH, Ed25519, X25519) and Diffie–Hellman fall to Shor’s algorithm. Hashes such as SHA-256 and 256-bit keys hold.
In October 2026 we read 82 firmware images from the binary alone: the makers’ own firmware from AVM, MikroTik, Turris and Teltonika, and OpenWrt for routers, switches and boards. 192,604 files, on six families of processor3. 3 MIPS, ARM, AArch64, PowerPC, RISC-V and x86. One more image, for an ixp4xx board, could not be opened and is not counted.
Every one of the 82 contains cryptography a quantum computer would break4. The change has started all the same: 59 already ship post-quantum algorithms, and the newest FRITZ!OS carries ML-KEM and ML-DSA where the release before it carries none5. 4 1,350 files in all, counting each file whose cryptography pqscan classes as quantum-vulnerable at medium confidence or above. 5 FRITZ!OS 8.50, FRITZ!Box 7690: /usr/lib/libcrypto.so.3 holds the ML-KEM NTT table of FIPS 203 and the ML-DSA roots; libssl.so.3 offers X25519MLKEM768. FRITZ!OS 8.25 on five other FRITZ!Box models: none found.
3How we read
Our tool, pqscan, reads a firmware image the way the device does. It unpacks the image in memory and examines every file inside. It needs no source code and no help from the maker, and nothing leaves the machine it runs on.
Most of what it finds is in plain sight: constants, keys, certificates and names. Some is not. Compilers split constants across machine instructions on MIPS, ARM, PowerPC and RISC-V, and pqscan puts them back together6. Every finding records what it was read from, and where. 6 On nine OpenWrt images, 57 findings came only from machine instructions. The open-source signature rules of findcrypt and EMBA saw one of them.
What comes out is an inventory that a laboratory can check: a report, a CycloneDX bill of materials, and every algorithm judged against the EU’s Agreed Cryptographic Mechanisms7. 7 ECCG Agreed Cryptographic Mechanisms, version 2.0, 2025: the cryptography EU cybersecurity certification accepts. The Cyber Resilience Act asks for state-of-the-art cryptography but names no algorithm; we judge against this catalogue.
4Where we are
Opsilux is independent and based in England. It is young: this is the first revision of this document, and the next ones will say what we read next. It is built for device makers, test laboratories and the operators who buy their equipment, in Europe first.
If you ship firmware, or depend on someone who does, send us one image. The first report is free.
Opsilux, 5 October 2026
hello@opsilux.com