Back to news

Direct-to-Cell Satellites Inherit the Phone Network's Weaknesses

Share:
Direct-to-Cell Satellites Inherit the Phone Network's Weaknesses

AST SpaceMobile launched three more BlueBird satellites on August 5, 2026, expanding a low Earth orbit fleet built to connect ordinary smartphones with no dish and no firmware change. SpaceX's Starlink does the same through an onboard eNodeB modem it calls a "cellular base station in space." Each of these satellites is, in effect, an LTE tower a few hundred kilometers overhead, and it carries the mobile network's known signaling weaknesses up with it.

The satellite is an LTE base station

Direct-to-cell works by reusing a mobile operator's existing spectrum, so the handset treats the satellite as one more cell and roams onto it like a distant mast. The radio protocol is therefore ordinary LTE, and increasingly 5G, the same stack security researchers have probed on the ground for more than a decade. A 2024 paper at the IEEE Symposium on Security and Privacy, The Dark Side of Scale, studied direct-to-cell mega-constellations directly. It found that their scale and constant motion, the features that let them shrug off many attacks, can be turned around to amplify signaling vulnerabilities inherited from LTE and 5G and to obscure attacks inside traffic that looks normal.

What the ground already taught us

On terrestrial networks, the persistent weak point is the small set of messages a phone and a tower exchange before they mutually authenticate. Those messages travel unencrypted, which is what lets a rogue base station, the device also known as an IMSI catcher, pose as a legitimate tower long enough to harvest a subscriber's identity or force the handset down to a weaker protocol. Breaking encryption is never required; the attack lives in the moment before encryption begins. Satellite cell selection leans on the same unauthenticated bootstrapping, so a phone reaching for a real satellite can still be pulled onto a fake cell on the ground, and a single satellite beam covering hundreds of kilometers widens how far one manipulated signal travels, including signaling crafted to deny service.

Privacy erodes in a subtler way. A 2025 study at the same conference, Mind the Location Leakage in LEO Direct-to-Cell Satellite Networks, showed that how these systems decide which satellite serves which user can expose a subscriber's location, which matters most when the user is an aid worker or a reporter in a place where nothing else reaches them.

Why orbit makes it harder

Two things separate the orbital version from its ground twin. Patching a tower is a maintenance visit; patching a base station in low Earth orbit means pushing software to a spacecraft within limited contact windows and with the caution that comes from touching a live satellite. The security boundary also now runs between two companies, the mobile operator that owns the spectrum and the customer relationship, and the satellite operator that owns the base station overhead. Detecting a spoofed cell and hardening the signaling layer falls across that seam, and AST alone expects to need roughly 45 to 60 BlueBird satellites for continuous coverage in its first markets, each one a base station to secure and keep current.

Juniper Research projects monthly active direct-to-cell users climbing from 17.4 million in 2026 to 133 million by 2031, with Ookla measuring connections up nearly 25 percent between July 2025 and March 2026. The Dark Side of Scale authors argue that targeted changes to authentication and signaling would close much of the gap they found, and none of those changes is yet required of an operator flying the service today.

AST SpaceMobile launch first reported by Telecoms Tech News; security findings drawn from IEEE Symposium on Security and Privacy research.