Georgia Tech researchers just exposed serious security flaws in Tile's tracking network that could enable mass surveillance of its 88 million users worldwide. The team found that Tile transmits unencrypted location data, MAC addresses, and device IDs - giving stalkers and potentially law enforcement the ability to track users despite the company's privacy claims. This puts Tile users at significantly higher risk than competitors like Apple AirTags.
The tracking device industry just got hit with a bombshell security report that exposes how Tile's popular location tags create a massive surveillance risk for their 88 million users worldwide. Georgia Tech researchers Akshaya Kumar, Anna Raymaker, and Michael Specter spent months reverse-engineering Tile's system and found fundamental design flaws that competitors like Apple, Google, and Samsung specifically avoid.
The core problem is encryption - or rather, the lack of it. While Apple's AirTags and Google's Find My Device network encrypt all broadcast data and location reports, Tile transmits everything in plaintext. Each Tile tag continuously broadcasts its MAC address and unique ID unencrypted, allowing anyone with a Bluetooth antenna or modified Tile app to intercept and track these signals.
"An attacker only needs to record one message from the device to fingerprint it for the rest of its lifetime," Kumar told WIRED. This creates what the researchers call "systemic surveillance" risk for anyone carrying a Tile device or Tile-enabled products from Dell, Bose, and Fitbit.
The surveillance capability extends far beyond individual bad actors. Law enforcement could potentially use this vulnerability to identify anyone in a specific area who carries a Tile device, while the company itself appears to maintain the technical capability to track all users despite privacy policy claims stating "you are the only one with the ability to see your Tile location."
The researchers believe location data gets stored unencrypted on Tile's servers, transforming what should be a simple lost-item finder into what they describe as "Tile's infrastructure into a global tracking network." This stands in stark contrast to competitors who use end-to-end encryption specifically to prevent companies from accessing user location data.
Apple, Google, and Samsung have "designed their system intentionally such that they aren't able to recover your location," researcher Michael Specter explained. "Because they don't want to be in the business of knowing where all people are at all times."
But Tile's security problems go deeper than just encryption. The researchers discovered that Tile's anti-stalking protection - designed to alert users when unknown tracking devices follow them - can be easily circumvented through the company's anti-theft feature. When a Tile owner enables anti-theft mode to hide their tag from potential thieves, it also becomes invisible to anti-stalking scans, effectively allowing stalkers to hide their tracking devices.
This creates a unique vulnerability that other tracking device makers avoid by simply not offering anti-theft modes. "That's a compromise that these companies are willing to make in order to have stronger anti-stalking properties," Kumar noted.
The anti-stalking system itself has significant limitations compared to competitors. While Apple and Google devices continuously scan for unknown trackers and automatically alert users, Tile's "Scan and Secure" feature requires manual activation, runs for only 10 minutes, and must be periodically restarted by users who remember to do so.
Tile attempts to address anti-theft mode abuse by requiring government ID verification and threatening users with a $1 million fine for stalking. But the company's terms contain contradictory statements about sharing user information with law enforcement - sometimes requiring warrants, other times allowing sharing "at our discretion, even without a subpoena."
The researchers also discovered that attackers could frame innocent Tile users for stalking through "replay attacks" - recording a legitimate device's unencrypted broadcasts and retransmitting them near potential victims to make it appear the original owner is stalking them.
These findings take on added significance given that a study published last year found over 40 percent of stalking victims had been tracked using Bluetooth tags hidden in cars, purses, or backpacks. The research team reported their findings to Tile's parent company Life360 in November 2024, but communication stopped in February 2025.
When WIRED contacted Life360 for comment, the company provided only a generic response stating they had "made a number of improvements" without specifying what those improvements were or whether they addressed the fundamental encryption issues.
The Tile vulnerability report highlights a growing divide in the tracking device industry between companies prioritizing user privacy and those maintaining surveillance capabilities. While competitors have moved toward zero-knowledge architectures that prevent even the companies themselves from tracking users, Tile's approach creates systemic risks for millions of people who simply want to find lost keys. For users concerned about privacy and stalking protection, the research suggests switching to encrypted alternatives from Apple, Google, or Samsung until Tile addresses these fundamental design flaws.