The DEF CON 2026 anti-surveillance gadgets on show in Las Vegas this year ranged from a $10 DIY chip that sniffs out Flock cameras to a free web tool that scans your phone for spyware without tipping off whoever planted it. Here is a proper look at the ones worth knowing about.
Why Flock cameras are the story behind the story
A lot of what landed at DEF CON this year circles back to one piece of infrastructure: Flock Safety’s automated licence plate reading (ALPR) cameras. According to Mother Jones, Flock Safety has more than 80,000 cameras spread throughout the United States, quietly scanning licence plates and firing automatic alerts to law enforcement and federal agencies. The Immigration Policy Tracking Project has reported that ICE officials have had more than 4,000 lookups conducted at their behest for immigration purposes through Flock cameras. Reports have also linked the data to tracking people potentially seeking abortions and, in some cases, surveilling partners and romantic interests.
Pushback is building. Mother Jones reports that throughout 2025, at least 30 municipalities cancelled their Flock contracts. DEF CON 2026 produced a clutch of tools aimed squarely at that same network.
A DIY hardware enthusiast who goes by Colonel Panic built Flock-You, a lightweight firmware you can load onto any ESP32 microcontroller (a chip you can pick up for £10 to £15 equivalent) to listen for wireless signals that indicate a Flock camera nearby. For those who would rather skip the soldering, Colonel Panic sells packaged ESP32 boards with the firmware pre-loaded, sold as OUI-SPY detectors for around $85 apiece. There are limits: the firmware only works on ESP32 hardware, not Arduino or Raspberry Pi boards. Flock cameras are also being updated to evade detection, so it will likely only catch older or unpatched models.
The Biscuit Ultra, built by a hacker known as Hedge, takes things further. This handheld device scans nearby wireless signals for surveillance tech, returning a list of local wifi networks, any Flock or Axon cameras in range, and, most usefully, an alert if the same device keeps appearing wherever you go. That last function is a practical way to spot active tracking by a smartphone, tracker, or GPS unit. The unit costs around $160 from the Biscuit Shop.
The DEF CON 2026 anti-surveillance gadgets tackling phones, browsers and beyond
The Rayhunter, developed by the Electronic Frontier Foundation, targets a different threat: IMSI-catchers, often called Stingrays. These are devices used by law enforcement that impersonate cell towers, pulling phones off genuine networks and onto the catcher, where location and call data can be harvested. Stray data from bystanders’ phones gets swept up too. Rayhunter runs on any off-the-shelf mobile hotspot, which the EFF says can cost as little as $20. Load the free software, and the hotspot lights red if suspicious tower behaviour is detected nearby.
For anyone who needs to communicate without relying on mobile networks at all, Exploitee.rs showed off The Hacker Pager. It looks like a retro handheld with a screen and mechanical keyboard, and it sends texts via radio waves using open-source Meshtastic firmware rather than cell towers or internet connections. The 2026 firmware update added external Bluetooth keyboard support, multichannel communication, and expanded customisation options. Range is up to thirty miles, assuming a clear line of sight.
On the browser security side, cybersecurity researchers Abhinav Khanna and Krishna Chaganti presented L.A.Y.E.R.S., a downloadable package available on GitHub that scans your installed browser extensions locally, without sending data to any third-party platform. Each extension gets a risk score from one to 100, with lower scores flagging higher risk, based on suspicious permission requests, malicious JavaScript or HTML, and risky external endpoint URLs. Fake extensions disguised as ad blockers or coupon finders have repeatedly shown up logging keystrokes or activating webcams without users knowing.
Finally, Anthony Desnos presented IsMyPhonePwned, a free web application that connects to your Android or iOS device over USB from a desktop PC and generates a bug report checking for spyware. The approach sidesteps the need to install anything on the compromised phone itself, which would risk alerting an attacker. A companion tool called droid2web can scan individual Android app packages separately if you suspect a specific app.
Still at prototype stage but worth a mention: Makoto Sugita, known as Mr. Rabbit, showed off Phasmid, an open-source Python app for Raspberry Pi that splits local storage into two slots, one real, one a scrubbed decoy. Hand over the device under pressure and the attacker sees nothing sensitive. A macOS version is currently under development.

