VES-JL-2026-001: JieLi Technology Bluetooth SoC — Supply Chain Threat Intelligence Published: 2026-01-15 Severity: Critical Author: Nirmal Liyon, VertexElite Security Research Complete infrastructure mapping of JieLi Technology Bluetooth SoC supply chain — 10B+ chips, full Alibaba Cloud estate, OTA firmware upload PoC Q: What is JieLi Technology? A: JieLi Technology (JieLi Keji) is a Zhuhai, China-based semiconductor company that manufactures Bluetooth audio SoC chips embedded in over 10 billion consumer devices worldwide, including products from Anker/Soundcore and other major audio brands. Q: Why is the Alibaba Cloud hosting significant? A: JieLi's entire development infrastructure — GitLab source control, firmware distribution servers, SDK repositories, health telemetry (wearheart.cn), and IP camera backends — is hosted on Alibaba Cloud, which was designated a Chinese military entity by the Pentagon on June 8, 2026. Q: What was the OTA firmware upload PoC? A: VertexElite demonstrated arbitrary firmware upload capability to JieLi SoC devices via the OTA update pathway, exploiting weak or absent cryptographic signature verification in the firmware update path. Full advisory: https://research.vertexelite.org/advisories/VES-JL-2026-001