A Third Explosive Drone Near Leipzig Exposes a Terrifying Hole in NATO’s Air-Cargo Security
German investigators reportedly found a third drone and about 50 grams of suspected RDX near Leipzig/Halle Airport after an earlier explosive drone targeted a Ukrainian Antonov. An antenna, cellular control gear and DNA clues point to planning—but Berlin has not publicly named the state behind it.
German investigators have found a third drone and suspected military explosive near Leipzig/Halle Airport, deepening fears that one of Europe’s most important cargo hubs was targeted by a coordinated sabotage operation.
The latest device was reportedly discovered on August 14 in a field near Kabelsketal, ten days after the first known incident. Forensic teams found traces or approximately 50 grams of suspected hexogen, the explosive commonly called RDX. German Chancellor Friedrich Merz said those behind hybrid attacks would pay and promised that authorities would identify responsibility soon.
They have not publicly done so yet.
The case involves several pieces that are easily collapsed into one super-drone. They should be separated. Reporting on the first device from August 4 says it carried a much larger Semtex charge and flew toward a Ukrainian Antonov cargo aircraft near its fuel-bearing wing. The detonator apparently failed, and the drone or explosive package did not produce the intended blast. Another drone may have collided with a DHL aircraft, forcing a diversion. The third device and suspected RDX were found later outside the airport.
Investigators also located an antenna and electronic components fixed near a tree in Kursdorf. Media reports say the equipment may have boosted control signals into the airport area. The earlier drone reportedly had an extended-life battery, a 5G router and two SIM cards, potentially allowing remote operation over a cellular network rather than requiring a pilot nearby.
That architecture would be alarming but not magical. A cellular link can allow commands from far away if coverage, authentication and latency are adequate. A local repeater can improve the final connection in a difficult radio environment. It can also separate the operator from the attack site, complicating capture and attribution.
“Controlled from virtually anywhere in the world” describes theoretical network reach, not proof that the pilot sat in a particular country. Investigators need carrier records, SIM registration, server logs, device identifiers and traffic analysis. Skilled operators can route commands through compromised infrastructure and false identities.
The DNA clue demands equal care. German media reported biological traces on the earlier drone and at the scene. A match in a European database reportedly pointed toward Lithuania and may overlap with evidence from the 2024 parcel-bomb campaign, which Lithuanian prosecutors say was organized by people linked to Russian military intelligence.
DNA leading to Lithuania does not mean the Lithuanian government attacked Germany. It may identify a person who lived, traveled, was recruited or handled equipment there. Russian services have been accused of using intermediaries and disposable recruits across Europe. A trace can connect cases without proving who ordered the operation.
Leipzig/Halle is an attractive target because it is a major freight hub and supports logistics connected to Ukraine and NATO. Antonov heavy cargo aircraft are scarce and strategically valuable. Destroying one beside fuel or military cargo could create casualties, close runways, disrupt deliveries and generate fear far beyond the physical damage.
Cheap drones change the security equation. Airports are designed to keep unauthorized people and vehicles away from aircraft, but small unmanned systems can cross fences. Jamming may interfere with legitimate navigation or communications. Shooting a drone risks debris and stray fire. Detection must distinguish birds and recreational devices from an explosive platform quickly enough to act.
The apparent failures also matter. The explosive did not detonate as intended. A bus driver reportedly encountered the device before authorities secured it. If accurate, that suggests both attacker incompetence and a severe detection gap. Europe may have avoided mass casualties through malfunction rather than defense.
Russia denies responsibility and calls the accusation anti-Russian provocation. German officials have so far used careful terms such as possible foreign involvement. That caution is appropriate. Public attribution should combine forensic evidence, communications, financing, travel patterns and intelligence—not merely the identity of the state with the clearest motive.
At the same time, waiting for courtroom certainty can leave infrastructure exposed. Germany can harden cargo aprons, expand counter-drone units, improve cellular anomaly detection and coordinate with logistics operators without announcing the culprit. Merz must balance operational secrecy with public confidence.
The story is larger than 50 grams of RDX. Multiple devices, remote-control infrastructure and a high-value target suggest reconnaissance and planning. But the strongest claims—Russian command, Lithuanian connection and exact attack sequence—remain at different levels of confirmation.
Was Leipzig an attempted act of state sabotage, a proxy operation or something else? The pattern points toward an organized hostile mission. The evidence released publicly does not yet name its author beyond reasonable doubt.
### What to watch next
Watch the German federal prosecutor’s attribution, explosive-laboratory results, telecom records, DNA identification, any arrests and security-camera reconstruction. Separate findings from the August 4 and August 14 devices; different explosives and components should not be merged into one claim.