US Gov & Defense

For Federal Agencies & Prime Contractors

Built in America.
Trusted by Americans.

Every cable that leaves our Pompano Beach facility is manufactured by US workers, on US soil, through a transparent and auditable supply chain. For federal buyers, that’s not a marketing claim — it’s a national security requirement.

Section 889 Compliant SDVOSB Certified Made in the USA ISO 9001 · 14001 · 45001 R2v3 / SERI Certified Buy American Act TAA Compliant Section 889 Compliant SDVOSB Certified Made in the USA ISO 9001 · 14001 · 45001 R2v3 / SERI Certified Buy American Act TAA Compliant

It’s not policy.
It’s federal law.

In August 2018, Congress passed and the President signed Section 889 of the John S. McCain National Defense Authorization Act for Fiscal Year 2019. The law prohibits federal agencies from procuring telecommunications and video surveillance equipment from five named Chinese entities — Huawei, ZTE, Hikvision, Hytera, and Dahua — and their subsidiaries and affiliates.[1]

The expanded prohibition, effective August 13, 2020, goes further. It bars federal agencies from contracting with any company that uses covered telecommunications equipment or services anywhere in its organization — even if that use has nothing to do with the federal contract itself.[2]

For the federal supply chain, that established a clear standard: provenance is no longer optional. Buyers and contracting officers now have a legal obligation to know where their equipment comes from, who manufactured it, and what is — and is not — inside.

Hardware implants in cables
are not theoretical.

Concerns about malicious hardware hidden inside ordinary-looking electronics are no longer the domain of intelligence briefings and classified programs. They have been demonstrated publicly, sold commercially, and reported by major news outlets and security researchers for years. Three documented categories illustrate the scope of the problem.

Documented & Commercial

The O.MG Cable

A USB cable visually indistinguishable from a standard charging cable, containing a hidden Wi-Fi-enabled microcontroller concealed entirely within the connector housing. Once plugged in, an attacker within roughly 100 feet can wirelessly inject keystrokes, log every key typed, exfiltrate data, and execute remote commands on the host device.[3] Originally designed as a red-team penetration testing tool, the cable is now commercially available for under $200.[4] What was once an NSA-only capability — cataloged internally as “Cottonmouth-I” with a price tag near $20,000 — is now a commodity.[5]

Reported, Disputed, Studied

The Supermicro Allegations

In October 2018, Bloomberg Businessweek published an extensive investigation alleging that a specialized unit of China’s People’s Liberation Army had directed Chinese subcontractors to secretly implant microchips, no larger than a grain of rice, onto server motherboards manufactured by Supermicro — servers that ultimately reached nearly 30 American companies and US government agencies.[6] Apple, Amazon, and Supermicro firmly denied the report, and parts of it have been contested. The point that remains uncontested across the security community is the threat model itself: hidden hardware-level modifications, introduced anywhere along a foreign supply chain, are technically feasible and extremely difficult to detect after the fact.[7]

Established Threat Model

Supply Chain as the Weak Link

Cryptographer Bruce Schneier and the broader academic security community have warned for more than two decades that the global hardware supply chain represents the most under-defended layer of modern computing. Components pass through dozens of facilities, in multiple countries, before reaching the end user. Each handoff is a potential insertion point. Once a malicious component is embedded in firmware or silicon, conventional anti-virus software cannot see it — and replacing it requires identifying it first.[8] The shortest known defense against this class of threat is a transparent, domestic supply chain.

From $20,000 to under $5.

The cost of a cable-borne hardware implant has collapsed by roughly four orders of magnitude in less than two decades. What was once an NSA-only capability priced at over $20,000 per unit can today be assembled from components a private individual can buy on the open market for less than the cost of lunch. The chips themselves — the working brain of any such implant — are now smaller than the lead of a pencil, roughly the size of a standard SMD capacitor or resistor found on any circuit board. There is more than enough room inside the molded housing of a USB-C connector, a Lightning connector, or an RJ45 Ethernet plug to conceal one with no externally visible difference.

2008
$20,300
NSA COTTONMOUTH-I
USB cable implant
(leaked NSA ANT catalog)[10]
2008
$24,960
NSA COTTONMOUTH-III
Stacked Ethernet + USB plug implant[10]
2015
$20
TURNIPSCHOOL
Hobbyist USB cable implant inspired by COTTONMOUTH[11]
2025
< $5
Off-the-shelf parts
Microcontroller + radio module in bulk[12]
Smallest Today
1.38 mm²

Texas Instruments MSPM0C1104 — the smallest microcontroller currently in commercial production. Smaller than a single grain of black pepper. Contains a 24 MHz processor with 16 KB of flash memory and costs roughly 20 cents per chip when ordered in volume.[12]

Famously Demonstrated
5 mm²

ATmel ATtiny85 — a hobbyist-grade chip used by security researcher Monta Elkins in a 2019 public demonstration. He soldered it onto a Cisco firewall motherboard, proving the entire Bloomberg “Big Hack” scenario was achievable for under $200 in parts.[13]

Plenty of Room
8.4 × 2.6 mm

Interior space of a USB-C connector. A standard RJ45 Ethernet plug is larger still. Modern microcontrollers, RF transceivers, and printed antennas all fit comfortably inside the molded housing of a connector with no externally visible difference to the user.

Publicly documented cable & connector implants

2008
COTTONMOUTH-I NSA Tailored Access Operations
USB plug implant
$20,300
2008
COTTONMOUTH-III NSA Tailored Access Operations
Ethernet + USB plug
$24,960
2008
FIREWALK NSA Tailored Access Operations
Ethernet + USB w/ RF
Classified
2008
RAGEMASTER NSA Tailored Access Operations
Video (VGA) cable
$30
2015
TURNIPSCHOOL Independent researchers
USB cable
~$20
2019
Elkins motherboard demonstration WhiteScope LLC
Soldered onto motherboard
~$200
2019–Present
O.MG Cable Hak5 / MG — commercial
USB-A, USB-C, Lightning
$120–$180

Of the items above, COTTONMOUTH-III and FIREWALK deserve particular attention. Both were NSA implants designed specifically to live inside Ethernet plugs — the standard RJ45 connectors at the ends of network cables. The leaked 2008 NSA ANT catalog establishes that nation-state actors were already deploying network-cable implants in operational use seventeen years ago. The threat is not new. The threat is no longer expensive. And the threat is no longer limited to nation-state actors.

And when no implant is needed: devices that “call home”

Even setting aside hidden hardware, a parallel and well-documented pattern of behavior has been observed for years: Chinese-manufactured network-connected devices that quietly send data back to servers inside the People’s Republic of China without disclosing the practice to the user. Security researcher Brian Krebs reported in 2016 that Chinese-manufactured security cameras, DVRs, and smart plugs were “punching through firewalls” to connect with infrastructure in China.[14] A 2021 industry analysis by Dark Cubed found that every Chinese-made IoT device it evaluated had at least one network connection to a server based in China — without user permission.[15] More recently, the cellular modules used inside doorbells, refrigerators, thermostats, port and logistics equipment, and other “smart” devices — a market segment now controlled approximately fifty percent by two Chinese firms, Quectel and Fibocom — have drawn formal Congressional and Department of Defense concern for the same reason.[16]

For consumer applications, a compromised cable is a concern. For federal, defense, intelligence, and critical infrastructure use, it is unacceptable.
— Our Position

A government, not a people.

We want to be direct, because federal buyers deserve clarity.

The People’s Republic of China, governed by the Chinese Communist Party, is recognized by the United States Department of Defense and the broader US intelligence community as a strategic competitor and adversary. The CCP exercises legal authority over Chinese companies under the 2017 National Intelligence Law, which compels them to “support, assist, and cooperate with national intelligence efforts” whenever asked. That is not an interpretation. It is the written text of PRC law.

The Chinese people are not the threat.
The regime in Beijing is.

We have nothing but respect for individual Chinese workers, engineers, and citizens. We work alongside many of them, and we know them to be talented, hard-working, and deserving of every freedom currently denied to them by their own government. Our objection is to the documented practice, by the Chinese Communist Party, of leveraging its commercial sector — including telecommunications equipment, electronics, and component manufacturing — for intelligence collection against the United States and its allies.

That is why every Spearhead cable is manufactured in the United States, from a transparent and auditable supply chain, by a company you can call, visit, and verify.

Compliance you can verify.

Our credentials are not aspirational. Each item below is currently active, third-party verified, and available for review by federal contracting officers and prime-contractor compliance teams on request.

I

100% United States Manufacturing

Design, materials sourcing, assembly, and quality control at our Pompano Beach, Florida facility. No offshore subcontracting. Full chain of custody available.

II

SDVOSB — Service-Disabled Veteran-Owned Small Business

Kublai Cable LLC holds the SDVOSB designation, qualifying us for veteran set-aside contracts under FAR 19.14 and SBA-administered VetCert programs.

III

Section 889 Compliant

No covered telecommunications equipment from Huawei, ZTE, Hikvision, Hytera, Dahua, or their subsidiaries appears anywhere in our supply chain.

IV

Buy American Act & TAA Compliant

Our manufacturing meets the substantial-transformation and US-content thresholds for both the Buy American Act and the Trade Agreements Act.

V

ISO 9001:2015, 14001:2015, 45001:2018

Quality management, environmental management, and occupational health & safety — all certified by Perry Johnson Registrars (PJR) and valid through 2029.

VI

R2v3 / SERI Certified

Responsible Recycling, version 3 — the leading international standard for responsible electronics handling and end-of-life data security. Issued by PJR.

Capability statement, on request.

We are prepared to engage with federal contracting officers, prime contractors, and procurement teams on volume orders. Capability statements, sample units, certification documentation, and facility visits can be arranged on request.

References & Further Reading
  1. Center for the Study of the Presidency & Congress — NDAA Procurement Ban (overview of Section 889). thepresidency.org/ndaa-procurement-ban
  2. Exiger — Everything You Need to Know About Section 889 of the NDAA Compliance Requirements. exiger.com
  3. Bastille Networks — USB O.MG Cable Wireless Security Research. bastille.net/research/omg-cable
  4. Hak5 — O.MG Cable product page and technical specifications. shop.hak5.org/products/omg-cable
  5. Dark Reading — From ‘O.MG’ to NSA: What Hardware Implants Mean for Security. darkreading.com
  6. Bloomberg Businessweek — The Big Hack: How China Used a Tiny Chip to Infiltrate America’s Top Companies (Oct. 2018). bloomberg.com
  7. TechCrunch — Chinese chip spying report shows the supply chain remains the ultimate weakness. techcrunch.com
  8. Schneier on Security — Chinese Supply Chain Hardware Attack (commentary by Bruce Schneier). schneier.com
  9. Big Think — China implanted tiny spy chips in servers used by Amazon, Apple. bigthink.com
  10. Wikipedia / NSA ANT Catalog — Leaked 2008 NSA Tailored Access Operations hardware-implant catalog (Snowden disclosures), including COTTONMOUTH-I, COTTONMOUTH-III, FIREWALK, RAGEMASTER, and unit pricing. en.wikipedia.org/wiki/ANT_catalog · Also Schneier on COTTONMOUTH-I
  11. Ben-Gurion University / arXiv — USBee paper documenting TURNIPSCHOOL as a 2015 hobbyist-built USB cable implant inspired by COTTONMOUTH, built for approximately $20. arxiv.org/pdf/1608.08397
  12. ZME Science — Texas Instruments unveils MSPM0C1104, the world’s smallest microcontroller, at 1.38 mm² and roughly 20 cents per chip in volume. zmescience.com
  13. Medium / The Startup — The in-hardware tiny spy chips you can make for only $200 (documenting Monta Elkins’ 2019 demonstration using an ATtiny85 chip on a Cisco firewall). medium.com
  14. Slashdot / Krebs on Security — IoT devices secretly phoning home to China-based infrastructure (security cameras, DVRs, and smart plugs). news.slashdot.org
  15. PR Newswire / Dark Cubed IoT Security Report — Every IoT device evaluated had supply-chain ties to China; most had at least one unauthorized network connection to a China-based server. prnewswire.com
  16. Benzinga / Congressional report — Chinese cellular modules (Quectel, Fibocom) controlling roughly half of the global market, embedded in doorbells, thermostats, port equipment, and logistics infrastructure — flagged by Congress and DoD for surveillance and remote-shutdown risk. benzinga.com

Source notes: The Section 889 statutory framework is settled federal law. The O.MG cable is a documented, commercially available hardware implant verified by multiple independent security researchers. The leaked NSA ANT catalog (2008 originals, disclosed publicly in 2013–2014 by Der Spiegel and Jacob Appelbaum following the Snowden disclosures) has been confirmed authentic by the broader security community and includes itemized pricing for the cable implants listed above. The 2018 Bloomberg Businessweek report on Supermicro motherboard implants was denied by the named companies and remains contested; we cite it here to illustrate the threat model raised by the broader security community, not as established fact. Documented patterns of Chinese-manufactured IoT devices communicating with infrastructure inside the PRC are drawn from multiple independent industry analyses and Congressional findings.

Scroll to Top