


Capabilities
System & data
Encrypted at restabsent
Data is encrypted while the device is locked (FBE on phones, LUKS applied at the workshop on laptops).
− Neither secure element nor storage encryption.
SourceRadio & network
IMEI rotation on SIM swaponsecret workshop
The ekaii fork of blue-merle changes the IMEI on every SIM swap. Changing an IMEI is restricted or illegal in some jurisdictions.
SourceMAC randomization · OUI mimicryonsecret workshop
MAC/BSSID addresses are randomized while mimicking common vendor prefixes (fork PR#74).
SourceLogs in tmpfsonsecret workshop
Client logs live in tmpfs and are wiped at shutdown — nothing persists to flash.
SourceBuilt-in VPN & Torstock (upstream)
WireGuard/OpenVPN · Tor
The GL.iNet firmware ships WireGuard/OpenVPN and a Tor mode for all router traffic.
SourceIMSI-catcher detectionabsent
Heuristic IMSI-catcher detection. Not claimed until verified in our fork.
Workshop & support
Installed, verified at the workshoponsecret workshop
We flash, verify integrity and re-lock every unit. For USB keys we provide the signature-verification procedure — don't take our word for it.
− Flash of the ekaii fork (V2nodep build) + SMS spool purge.
● stock (upstream)◆ onsecret workshop○ option— absent
What this does not protect against
- Does not secure the cellular baseband or the modem firmware. The EM060K-GL is a closed, proprietary stack; a randomized IMEI does not change how the modem talks to the network or stop it from responding to network commands.
- Does not detect or block IMSI-catchers / Stingrays. blue-merle randomizes identifiers on SIM swap; it does not monitor the radio for rogue base stations or downgrade attacks.
- Does not anonymize you at the network or carrier level. The IMSI on your SIM, your location via cell triangulation, and lawful interception by the operator are unaffected; pair with a SIM bought without identity linkage and route traffic over a VPN/Tor.
- Does not defend against device theft, seizure, or coercion. Anyone with physical access can read the live IMEI/MAC, the microSD, and unencrypted config; the password is the only gate.
- Does not erase forensic traces beyond its scope. UBIFS is copy-on-write, so shred only logically removes data; physical flash recovery is out of scope, and GL smstools writes the IMEI/IMSI into the header of every received SMS unless those spools are wiped separately.
- Does not make IMEI changes lawful. In some jurisdictions (e.g. the UK Mobile Telephones (Re-programming) Act 2002) altering an IMEI is a criminal offence; this product is for lawful privacy, not evading lawful interception.
What the workshop does to this device
Our pipeline
- Flash of our maintained ekaii fork of blue-merle (V2nodep build — luci-base dependency removed).
- SMS spool wipe: GL's smstools writes IMEI/IMSI into the header of every received SMS — we purge them.
- Non-destructive check of the SIM-swap flow before shipping.
What you can ask us
- Fork updates on request.
- Flashing help if you go back to stock firmware.
- Support: SimpleX / Signal / PGP.
What we do not do
- No remote access to the router: no agent installed, nothing to revoke.
- No guarantee on the IMSI or carrier side.
- No legal advice on IMEI changing — compliance is on you.
Choose within the range
| GL.iNet Mudi — untouched« Intact — flash it yourself »€350 Monero€500 card | GL.iNet Mudi V2 — blue-merle (ekaii)HERE« Workshop-patched — supported build »€483 Monero€690 card | GL.iNet Mudi 7 — blue-merle (ported)« 5G & Wi-Fi 7 — experimental »€553 Monero€790 card | |
|---|---|---|---|
| Differences | |||
| IMEI rotation on SIM swap | *exp. | ||
| MAC randomization · OUI mimicry | *exp. | ||
| Logs in tmpfs | *exp. | ||
| IMSI-catcher detection | |||
| Installed, verified at the workshop | *exp. |
The intact model costs less because nothing is added — it is yours to flash.
Do it all yourself → stock. Proven blue-merle behaviour → V2. 5G / Wi-Fi 7 and fine with experimental → Mudi 7.
What it is
What it is
The GL.iNet Mudi V2 (GL-E750V2) is a battery-powered OpenWrt LTE router built around the Quectel EM060K-GL modem. On its own it is a capable travel router with VPN, Tor, and ad-blocking. We ship it with our maintained ekaii fork of [blue-merle](https://github.com/srlabs/blue-merle), the SRLabs research package that reduces the forensic traceability of the Mudi by randomizing the identifiers the device exposes.
What blue-merle actually does
blue-merle addresses four upstream-documented mechanisms: IMEI randomization (random, or deterministic from the inserted SIM's IMSI), MAC address randomization, BSSID randomization, and volatile storage of client connection data (the OUI/client database is moved to a tmpfs mount so it does not persist across reboots). The intended workflow is a *SIM swap*: you toggle the side switch, change the SIM, and the device re-rolls the IMEI so a new SIM is not seen by the network alongside your previous equipment identity. Our ekaii fork adds vendor-OUI MAC mimicry (LA-bit 0, real-looking OUIs per PR #74) and ships a V2nodep build so it installs on current GL firmware where the upstream `luci-base` dependency no longer exists.
Honest positioning
This is an *identifier-hygiene* tool, not anonymity in a box. It changes what the device advertises (IMEI, MAC, BSSID); it does nothing about the SIM (IMSI), your location (cell triangulation), or the operator's lawful visibility into your traffic. The modem baseband remains a closed, trusted-by-default component. Used correctly — fresh non-attributable SIM, IMEI randomized on each swap, traffic over VPN/Tor, SMS spools wiped — it raises the cost of cross-SIM correlation. Used carelessly it provides little. And in several jurisdictions changing an IMEI is a regulated or criminal act: read the legality note before you randomize anything.
Usage guide
Before you start
This guide assumes you understand the legality question first. Upstream states plainly: *"Depending on your jurisdiction, changing your IMEI might violate local regulation or law."* In the UK, the Mobile Telephones (Re-programming) Act 2002 makes altering an IMEI a criminal offence outside narrow manufacturer exceptions. Other countries differ. You are responsible for confirming it is lawful where you operate. blue-merle is a lawful-privacy tool; it is not a way to evade lawful interception or to impersonate a stolen device — never set an IMEI that belongs to another active or stolen handset.
Initial setup
- Charge the unit and connect to its default Wi-Fi / `192.168.8.1`. Set a strong admin password immediately — on this device the password is the only thing protecting the live IMEI, MAC, config, and microSD.
- Update the GL.iNet firmware to a 4.3.x build before doing anything else, then verify blue-merle is the ekaii V2nodep build (the upstream package with a hard `luci-base` dependency will be rejected by current gl-sdk4 firmware).
- Decide your trace policy *now*. Run a read-only check (`analyze` in our toolkit, or read the IMEI via `gl_modem AT 'AT+EGMR=0,7'`) and record the factory IMEI if — and only if — you want the ability to restore it. There is no upstream restore (issue #83); once randomized, the factory IMEI is gone from the modem EFS.
Daily use: the SIM-swap flow
The core operation is swapping SIMs without letting the network see two SIMs behind one equipment identity:
- Use the side switch to enter the blue-merle SIM-swap mode (or run the `blue-merle` CLI / LuCI page).
- Physically change the SIM.
- Confirm; blue-merle generates a new IMEI (random, or deterministic from the new IMSI) and writes it via `AT+EGMR`. On reboot the boot hook re-rolls Wi-Fi MAC/BSSID to plausible vendor OUIs.
Use a SIM that is not linked to your identity. A randomized IMEI behind an attributable SIM gains you nothing — the IMSI still identifies the subscriber.
Hardening
- Wipe the SMS spool after every randomization. GL's `smstools` writes `IMEI:` and `IMSI:` headers into every received SMS under `/etc/spool/sms/...`. A pre-swap SMS therefore still links your old IMEI to that SIM even after the EFS is rewritten. blue-merle does not clean these; wipe them separately (our toolkit's `wipe-sms <old_imei>`).
- Layer the network. Identifier randomization is local-radio hygiene only. Route all traffic through a WireGuard/OpenVPN tunnel or Tor so the carrier and upstream see neither your real IP nor plaintext.
- Treat the microSD as plaintext. It is not encrypted by the router; store nothing sensitive on it unless you encrypt it yourself.
- Power off when crossing a checkpoint. A powered device exposes the live identifiers to anyone who seizes it.
Verifying integrity
- After install, run the non-destructive checks: IMEI generation dry-run, Luhn-checksum validation, and the MAC generator (`imei_generate.py -g -r -v`). These confirm the tooling works without writing to the modem.
- Read back the live IMEI with `gl_modem AT` and confirm it changed (and passes Luhn) after a real swap.
- Confirm MAC/BSSID changed after reboot via `ip link` / the LuCI status page, and that the OUI looks like a real vendor with the locally-administered bit clear.
- Confirm the client/OUI database is on tmpfs (`mount | grep oui-tertf`) so it does not survive a reboot.
Pitfalls
- UBIFS is copy-on-write: `shred` is logical only. Do not assume deleted data is physically unrecoverable from the flash.
- `/tmp` is tmpfs: anything staged there is lost on reboot.
- Duplicate IMEI risk: setting an IMEI already active on the same network (or a stolen one) can cause connectivity problems and is exactly what the law targets.
- No baseband guarantees: the modem firmware is closed; blue-merle changes what it advertises, not how it behaves.
Specifications
| Model | GL.iNet GL-E750V2 (Mudi V2) |
|---|---|
| Cellular modem | Quectel EM060K-GL (LTE Cat-6, global bands) |
| RAM | 128 MB DDR2 |
| Onboard flash | 16 MB NOR + 128 MB NAND |
| Removable storage | microSD up to 1 TB (sold separately) |
| Wi-Fi | 2.4 GHz up to 300 Mbps + 5 GHz up to 433 Mbps |
| Battery | 7000 mAh Li-Po; also acts as USB power bank |
| Firmware / patch | GL.iNet OpenWrt 4.x + blue-merle ekaii fork (V2nodep build, luci-base dependency dropped) |
| Physical controls | OLED screen + side mode switch used to trigger the SIM-swap flow |
After purchase
Your device arrives already prepared — this guide is for redoing everything yourself or checking our work.
Open the full guide
Avant de commencer
Ce guide suppose que vous avez d'abord traité la question de la légalité. L'amont l'indique sans détour : *« Selon votre juridiction, changer votre IMEI peut enfreindre la réglementation ou la loi locale. »* Au Royaume-Uni, le Mobile Telephones (Re-programming) Act 2002 fait de la modification d'un IMEI une infraction pénale hors des rares exceptions réservées au fabricant. D'autres pays diffèrent. Il vous revient de confirmer que c'est licite là où vous opérez. blue-merle est un outil de vie privée licite ; ce n'est pas un moyen de contourner l'interception légale ni d'usurper un appareil volé — ne définissez jamais un IMEI appartenant à un autre combiné actif ou volé.
Configuration initiale
- Chargez l'appareil et connectez-vous à son Wi-Fi par défaut / `192.168.8.1`. Définissez immédiatement un mot de passe admin robuste — sur cet appareil, le mot de passe est la seule chose protégeant l'IMEI en cours, la MAC, la configuration et la microSD.
- Mettez à jour le firmware GL.iNet vers une version 4.3.x avant toute chose, puis vérifiez que blue-merle est bien le build ekaii V2nodep (le paquet amont avec une dépendance dure `luci-base` sera rejeté par les firmwares gl-sdk4 actuels).
- Décidez de votre politique de traces maintenant. Lancez un contrôle en lecture seule (`analyze` dans notre boîte à outils, ou lecture de l'IMEI via `gl_modem AT 'AT+EGMR=0,7'`) et notez l'IMEI d'usine si — et seulement si — vous voulez pouvoir le restaurer. Il n'existe aucune restauration amont (issue #83) ; une fois randomisé, l'IMEI d'usine disparaît de l'EFS du modem.
Usage quotidien : le flux de changement de SIM
L'opération centrale consiste à changer de SIM sans laisser le réseau voir deux SIM derrière une même identité matérielle :
- Utilisez l'interrupteur latéral pour entrer dans le mode de changement de SIM de blue-merle (ou lancez la CLI `blue-merle` / la page LuCI).
- Changez physiquement la SIM.
- Confirmez ; blue-merle génère un nouvel IMEI (aléatoire, ou déterministe à partir du nouvel IMSI) et l'écrit via `AT+EGMR`. Au redémarrage, le hook de boot régénère MAC/BSSID Wi-Fi vers des OUI constructeur plausibles.
Utilisez une SIM non liée à votre identité. Un IMEI randomisé derrière une SIM attribuable n'apporte rien — l'IMSI identifie toujours l'abonné.
Durcissement
- Effacez le spool SMS après chaque randomisation. Le `smstools` de GL inscrit les en-têtes `IMEI:` et `IMSI:` dans chaque SMS reçu sous `/etc/spool/sms/...`. Un SMS antérieur au changement relie donc encore votre ancien IMEI à cette SIM même après réécriture de l'EFS. blue-merle ne nettoie pas ces fichiers ; effacez-les à part (le `wipe-sms <old_imei>` de notre boîte à outils).
- Superposez le réseau. La randomisation d'identifiants n'est qu'une hygiène radio locale. Faites passer tout le trafic par un tunnel WireGuard/OpenVPN ou Tor afin que l'opérateur et l'amont ne voient ni votre vraie IP ni du clair.
- Considérez la microSD comme du clair. Elle n'est pas chiffrée par le routeur ; n'y stockez rien de sensible sans la chiffrer vous-même.
- Éteignez l'appareil au passage d'un point de contrôle. Un appareil sous tension expose les identifiants en cours à quiconque le saisit.
Vérifier l'intégrité
- Après l'installation, lancez les contrôles non destructifs : génération d'IMEI à blanc, validation de la somme de contrôle de Luhn, et le générateur de MAC (`imei_generate.py -g -r -v`). Ils confirment que l'outillage fonctionne sans écrire dans le modem.
- Relisez l'IMEI en cours avec `gl_modem AT` et confirmez qu'il a changé (et passe Luhn) après un échange réel.
- Confirmez que MAC/BSSID ont changé après redémarrage via `ip link` / la page d'état LuCI, et que l'OUI ressemble à un vrai constructeur avec le bit localement administré à zéro.
- Confirmez que la base clients/OUI est sur tmpfs (`mount | grep oui-tertf`) pour qu'elle ne survive pas à un redémarrage.
Pièges
- L'UBIFS est en copy-on-write : `shred` n'efface que logiquement. Ne supposez pas que les données supprimées sont physiquement irrécupérables de la flash.
- `/tmp` est en tmpfs : tout ce qui y est posé est perdu au redémarrage.
- Risque d'IMEI en double : définir un IMEI déjà actif sur le même réseau (ou volé) peut causer des problèmes de connectivité et c'est exactement ce que la loi vise.
- Aucune garantie sur le baseband : le firmware du modem est fermé ; blue-merle change ce qu'il annonce, pas son comportement.
Verifiable sources
- blue-merle — source et README amont SRLabs Verified on: 15 June 2026
- Notes de version blue-merle 2.0 (SRLabs Research) Verified on: 15 June 2026
- Installer blue-merle et randomiser l'IMEI sur le Mudi (Wiki Systemli) Verified on: 15 June 2026
- Guide utilisateur officiel GL.iNet GL-E750/GL-E750V2 Verified on: 15 June 2026
- Mobile Telephones (Re-programming) Act 2002 (Royaume-Uni) Verified on: 15 June 2026
- blue-merle issue #83 — pas de restauration de l'IMEI d'usine Verified on: 15 June 2026
- Forum communautaire GL.iNet — blue-merle sur le E750 Verified on: 15 June 2026
- Projet OpenWrt (base du firmware) Verified on: 15 June 2026