Qiui Cellmate: what the security research actually documented
In 2020 the UK security firm Pen Test Partners published research on the Qiui Cellmate, an app-controlled chastity cage. The research described an unauthenticated API, a six digit friend code that could return user data including location and phone number, and a way for an attacker to stop the lock from opening. Because the device as sold had no physical emergency override, a software fault became a physical problem. We have not tested the product and cannot confirm its current state.
What it is: An app-controlled chastity cage: a moulded plastic shell with an electronically driven latch that opens on a command from a paired phone rather than with a key.
What the public record shows
- The Cellmate is a connected chastity cage. Release is handled by an electronic latch and a phone app, not by a keyway.
- In 2020 the UK security firm Pen Test Partners published security research on the product.
- That research described an application programming interface reachable without authentication, meaning requests were not checked against the identity of whoever sent them.
- The system used a six digit friend code to link accounts. The research showed those codes could be stepped through to return account information, and the data described included location and a phone number.
- The research also described a scenario in which an attacker could remotely stop the lock from opening.
- The device as sold had no physical emergency release, so a locked user had no straightforward mechanical way out.
- The firm's published disclosure timeline records first contact with the company in April 2020 and a substantive response the following month.
- In the period after publication, incidents were reported in which users' devices were locked remotely and a small bitcoin ransom was demanded.
Documented concerns
- A lock with no mechanical override turns any software fault into a physical problem for the person wearing it.
- Emergency removal of a rigid shell clamped to genitals is a cutting job, which is not a sensible thing to improvise at home.
- Account linking by short numeric code is a small search space, and small search spaces get walked by software.
- Location and contact data attached to an intimate product is a different class of exposure from a leaked shopping list.
- A fix shipped in a new app version does nothing for someone still running an old one.
- We have not tested this device and cannot verify what the current hardware, firmware or app do.
Our editorial reading, not a test result: the software faults are the headline, but the design decision is the lesson. A connected lock on a human body that ships without a mechanical override leaves the wearer with no exit when the software misbehaves, and no patch fixes an absent keyway. Anyone shopping for a connected cage should treat a documented physical release as the entry requirement rather than a bonus feature.
Most chastity gear fails in ways you can see coming. A hinge wears, a padlock seizes, a ring turns out to be the wrong diameter. The Cellmate introduced a different kind of failure, because the thing holding it shut was software, and software fails in ways a padlock never does.
This page is not a review. We have not tested this device, so there is no score here and there never will be. What follows is the documented public record and our reading of it.
What the device is
The Cellmate is an app-controlled chastity cage. Instead of a key, it uses an electronically driven latch inside a moulded plastic shell, and that latch releases when the paired phone app tells it to. The keyholder can be in the next room or on another continent. That is the entire selling point, and for a couple running control at a distance it’s a genuinely appealing one. Our guide to long-distance orgasm control covers why that reach matters to people.
The trade is structural. A mechanical lock has one interface, the keyway, and one adversary, whoever holds the key. A connected lock has a phone, an app, an account, a wireless link and a server behind it. Every one of those is either a way in or a way to fail.
What the 2020 research documented
In 2020 the UK security firm Pen Test Partners published research on the product. Three findings from that work still matter to anyone deciding whether to buy a connected lock.
The first: the interface the app talked to was reachable without authentication. Nothing checked that a request came from the account it claimed to belong to. That is the sort of flaw that turns every other detail of a system into a problem, because once the front door is open, everything behind it is reachable.
The second followed directly. The service used a six digit friend code so users could link to each other. The research showed those codes could be stepped through, returning information about the account behind each one, and the data described included location and a phone number. Six digits is a million possibilities. A computer walks a million possibilities before you finish your coffee.
The third finding is the one that changed the category of the problem. An attacker could stop the lock from opening. Not open it, which would be embarrassing. Keep it shut, which is something else entirely.
Why the absent override was the real problem
Here is the part that makes this a case study rather than a news cycle. The device as sold had no physical emergency release. No key, no accessible screw, no fallback. If the app would not open it, it stayed closed.
Consider what that leaves a person. Cutting through a rigid shell clamped around genitals, with a tool strong enough to get through it, is not something to improvise at home, and it does not make for a relaxed conversation in an emergency department either. Every software fault in this story is fixable. Vendors patch things constantly. The missing override was a design decision, and it is the reason a bug could put somebody in a position with no good exit.
Our chastity cage safety guide makes the same argument for ordinary cages, where the answer is a spare key kept somewhere you can actually reach at three in the morning. A device with no keyway removes that option from the table.
What happened after the disclosure
The firm published a disclosure timeline alongside the research. It records first contact with the company in April 2020 and a substantive response the following month. That is the normal shape of coordinated disclosure: researchers tell the maker, the maker gets time to fix things, the details become public afterwards.
Then came the part nobody wants in a product story. After the findings were public, people reported that their devices had been locked remotely and a small ransom demanded in bitcoin. Those are reported incidents. We are not in a position to confirm them individually, and we are not going to guess at how many people were affected.
What we can and cannot say about it today
We have not tested a Cellmate. That is exactly why these pages carry no score. A number here would be an invention, and an invented number about a device that locks around somebody’s body is a worse lie than usual.
The record above is documented and public. What we can’t tell you is what the product does now. Companies do fix things. Apps get rewritten, firmware gets replaced, hardware gets revised, and whatever is in a box today is not the thing that was examined in 2020. Patches also reach people unevenly, since a fix in a new app release does nothing at all for someone still running a version from two years ago.
So read this as history with a lesson attached rather than as a live assessment of a current product. If you are considering this device, or any connected cage, ask the seller directly whether the exact model in front of you has a mechanical release, and treat a vague answer as a no.
The lesson that outlives the product
An internet-connected lock on a human body needs a mechanical override. That is the whole thing. Not a nicer app, not stronger encryption, not a longer friend code. A way out that does not depend on electricity, radio, a phone battery, or a company staying in business and keeping its servers on.
That principle applies to the whole category, which is why we treat it separately in what the record says about smart chastity devices. If you are weighing an app layer against a physical setup, remote control chastity apps covers what software actually buys you, and what it quietly takes away.
Questions people ask
Was the Qiui Cellmate hacked?
Security research published in 2020 documented serious flaws, including an interface that did not check who was making a request and a way to keep the lock shut remotely. In the period afterwards, incidents were reported in which people's devices were locked and a small bitcoin ransom demanded. Those are reported incidents rather than something we can independently confirm, and we have not tested the product ourselves.
Did the Cellmate have an emergency release?
The version examined in that research did not have a physical override. That is the detail that made the software problems dangerous rather than merely embarrassing, because a wearer whose app would not open the lock had no simple mechanical way out. If you are looking at any connected cage today, ask the seller directly whether the exact model has a manual release and treat an unclear answer as a no.
Is the Qiui Cellmate safe to buy now?
We cannot tell you that, and we will not pretend otherwise. Companies do patch things, apps get rewritten and firmware changes, so the product on sale today is not the product that was examined in 2020. What we can say is that the durable requirement has not changed: a lock on your body should have a mechanical release you can operate yourself, whatever the app is doing.
Ask someone who owns one
A public record tells you how a product is documented. People who have lived with it will tell you the rest, including the parts no spec sheet mentions.
Find people who own it →