In short
FlashCall uses a short or intentionally unanswered phone call as part of user verification instead of, or alongside, an SMS OTP. The application places a call to the user's number and terminates it before answer; the app reads the incoming caller ID as the verification code, so no voice minutes are billed and no SMS is sent.
How the mechanism works
The application requests verification. A platform places a call to the user's number from a number whose last digits are the verification code. The handset receives the call; the application reads the caller ID, extracts the digits, and cancels the call before it is answered.
From the user's perspective verification is instantaneous and requires no action. From the network's perspective, a call was set up and released before answer — generating signaling but no billable minutes and no message.
What it looks like in network data
FlashCall has a distinctive footprint that separates it from ordinary calling:
- Very short or zero duration, with release before answer
- High volume from a small set of originating platforms
- High fan-out — many distinct destinations, each contacted once
- Caller-ID rotation, because the number itself carries the code
- Answer-seizure ratios far below any normal calling pattern
- Timing correlated with app logins rather than with human calling habits
Why it displaces messaging revenue
OTP traffic is typically the most valuable A2P category an operator carries: high volume, latency-sensitive, and priced accordingly. FlashCall moves that verification onto the voice channel at close to zero cost to the enterprise, and close to zero revenue for the operator.
Because the calls are never answered, they generate no billable minutes either, so the displaced revenue does not reappear anywhere. An operator seeing unexplained OTP decline while overall app usage grows should check the voice channel before concluding it lost the customer.
It is not fraud
FlashCall is a legitimate verification method used by major applications, and treating it as fraud leads to poor decisions. It is a commercial and product problem: the operator's product is being substituted by a cheaper alternative that happens to run over its own network.
Guardivia detects and classifies the activity so the commercial team can quantify it. Where an operator chooses to act, enforcement is executed through a voice firewall or session border controller, not by the messaging platform.