09.03.26 · Brian Stoner, Head of Product

iOS Invalid Recovery Phrase Bug

If you signed up for Cape on iOS between July 12 and August 19, 2026, there is a small chance you have an invalid recovery phrase.

What happened?

On July 12, we made changes to the iOS onboarding process (app version 1.505.0) that resulted in a race condition, in which some new customers ended up creating two separate recovery phrases instead of one. The Cape app showed one of those recovery phrases to the customer, but authenticated using the other phrase. As a result, you may have saved a recovery phrase that doesn’t work. To be clear, no recovery phrases were compromised; they simply would not work to authenticate your account.

We discovered the bug on August 13 but struggled to reproduce it. After some late nights of debugging and a few app release iterations, we had a working fix on August 19 with iOS app version 1.507.2 that prevented anyone else from hitting this issue.

Because we don’t store recovery phrases ourselves, we couldn’t identify exactly who was impacted. And because we don’t want customers to give us their recovery phrase, our support team couldn’t manually resolve the issue for anyone. The only way to resolve this in a way that upheld our security model was to build a new flow into the app to allow customers potentially impacted by the bug to validate their recovery phrase and if necessary, regenerate a new phrase. This was released on September 3rd, with iOS app version 1.509.0.

Why a recovery phrase (also known as the 24-word passphrase)?

We keep your account secure using public key cryptography. When you create an account with Cape, a 24-word passphrase is generated on your device and never known by us. You use this passphrase to authorize sensitive account actions, like porting your number out or moving your SIM to a new phone. Read more .

Who was impacted?

Upon discovering the issue, we were able to retroactively identify the errors produced by this race condition in Sentry logs, but because we anonymize those reports, it’s impossible to link those errors to specific customers.

We were able to narrow it down to 551 customers who made their first payment within five minutes of a Sentry error. We expect only a small subset of the 551 have actually hit the bug, as we got fewer than three verified complaints about it via customer support.

How do I fix this?

If you were potentially impacted, you will have received a notification within your Cape app, along with instructions to verify your recovery phrase.

If your recovery phrase generates a valid public key that matches your account, you’re good to go. If your recovery phrase generates a valid public key but that public key is not matched to your account, a new recovery phrase will be generated on your device for you to save.

If you’ve lost your recovery phrase, we cannot grant access to your account, as Cape is secure by design and does not keep a copy of your 24-word phrase. In these cases, we can help you cancel your subscription and create a new account.

How we’ll prevent future bugs

We are rearchitecting the authentication code in our iOS app to make this class of bugs significantly less likely in the future.

Share it

Signup Callout

Switch to Cape,
America's privacy-first mobile carrier.

Protect yourself with premium, secure cell service.

Sign up now