Reverse Engineering the TabCat V2 RF Protocol

Kit the cat wearing her TabCat tracking beacon
Kit with her TabCat beacon. Unbothered.

My cat Kit roams outside. After losing her one too many times, I bought a TabCat V2. It’s a small RF tag on her collar and a handheld unit that beeps louder as you get closer. Naturally, I had to open it to see how it works.

FCC Filings

The FCC documents (Handset: TUW-PH, Tag: TUW-BT) show both devices operate at 2435 MHz. Since it’s not Wi-Fi or Bluetooth, the FCC classifies it as “low power transmitters using spread spectrum techniques.” This points toward OQPSK DSSS or frequency-hopping rather than simple narrowband FSK.

PCB & The Chip

The board is tiny. The main IC is marked G22 C224HG. Based on the specs and FCC data, this is almost certainly a Silicon Labs EFR32FG22 Series 2 chip.

This hardware makes sense for the application. The EFR32FG22 handles proprietary wireless protocols, supporting GFSK up to 2 Mbps and OQPSK DSSS at 250 kbps. It has no standard BLE or Zigbee stack, meaning Loc8tor runs a custom protocol on Silicon Labs’ RAIL API.

(Note: I can’t find the exact “C224HG” string in any SiLabs ordering guides. Let me know if you know how to read their package markings.)

RF Capture

I used a wideband SDR to capture 2 MHz of bandwidth centered on 2435 MHz. Looking at the spectrogram, the protocol is highly regular. The handset sends a 120ms ping, the tag replies with a quieter 80ms burst, and they wait 500-700ms before repeating.

Annotated spectrogram
Blue = handset pings. Green = tag responses. Yellow = mystery signals.

I wrote a Python script to isolate these bursts, shift them to baseband, and apply FM demodulation to extract the bits. I’m stuck here for now. Without knowing the exact bit rate or packet framing (preamble, sync word, CRC), I can’t read the payload yet.

The Mystery Signals

At the end of my capture, two faint 20-40ms blips showed up right at the noise floor. They look entirely different from the main pings. The EFR32FG22 has an RFSense wake-up mode, so the tag might send low-power heartbeats before the main sequence starts. Or it’s just random 2.4 GHz interference.

Next Steps

Custom 2.4 GHz protocols are tough. Unlike 433 MHz where tools like rtl_433 usually work out of the box, unknown GFSK needs a lot of manual decoding.

Next up: getting a directional antenna, setting up a GNU Radio flowgraph, and digging into the RAIL SDK docs. If you have experience with EFR32 chips or Loc8tor hardware, get in touch on GitHub or LinkedIn.