Bluetooth Tracker
Buy a pack

Bluetooth tracker security: can a tag be cloned?

How it worksPublished 4 min read
A small black disc on a slate surface beside a laptop showing a plain dark screen in a quiet room

Bluetooth tracker security is a fair thing to ask about before you attach one to a bike or a toolbox, because the tag is doing something that sounds alarming when you say it out loud: broadcasting, constantly, to anyone within range. This article defines what is actually being sent, answers the cloning question directly, and separates the attacks that work from the ones that do not.

What is Bluetooth tracker security?

Bluetooth tracker security is the problem of letting a tag be found by strangers' phones while revealing nothing about its owner to those strangers. Every finding tag has to advertise, or no passing device could ever hear it and no position could ever be relayed. The design question is therefore not how to hide the broadcast, which is impossible, but how to make the broadcast useless to everyone except the one account entitled to read the result. That is done in two places: the identifier the tag sends, and the encryption on the position a passing device reports.

How does a tag hide who owns it?

It advertises an anonymous identifier that changes regularly and carries no name, no account and no serial number a stranger could look up. What leaves the tag is a short packet that says, in effect, "a Find My accessory is here". It does not say whose, and because the identifier rotates, two sightings hours apart cannot be reliably strung together by an observer into a trail belonging to one person.

The second half happens on the finder's side. When an Apple device hears the tag, it reports the position in encrypted form, and that report can be decrypted only by the Apple Account the tag is registered to. The phone that helped does not learn what it found, and neither does the manufacturer, the shop that sold it or Apple.

Can a Bluetooth tracker be cloned?

Someone can copy the packet a tag is currently broadcasting, but a copy is not a key: it grants no access to the owner's map, no location history and no control over the real tag. This is the part worth being precise about, because "cloned" suggests a duplicate that works, and it is not that.

A clone can do exactly one thing: cause an extra device to appear where the copied advertisement is heard. It cannot ring the original. It cannot see where the original has been. It cannot register itself to your Apple Account or unregister the tag from it. And because the broadcast identifier rotates, a copied one goes stale on its own. Compare that with the effort involved and the attack does not pay, which is why the plausible threats to your bike are all physical.

Can someone scan for my tag with an app?

A general Bluetooth scanner app will show that some accessory is advertising nearby, and nothing further. These apps list signal strength and a device type, and people sometimes use them when hunting for a tag they have been warned about. The listing does not name an owner, does not open a location history and cannot be used to claim the tag.

Signal strength is a poor ruler as well, for the reasons set out in our explainer on what RSSI is and why it misleads: a strong reading means a clear path, not necessarily a short one. If you have been warned by your iPhone that an accessory is travelling with you, the built in flow is more use than any scanner, because it can make the thing sound.

Which risks are real?

The realistic threats are physical or social rather than cryptographic. Ranked by how often they actually matter:

RiskHow realWhat helps
A thief finds the tag and pulls the cellVery realHide it well and tag the case as well as the contents
Somebody plants a tag on youReal, and alertedApple's unwanted tracking warnings on your iPhone
A stranger scans and identifies your tagNot a practical concernNothing needed
A cloned advertisement reveals your historyNot how it worksNothing needed
Buying a used tag still bound to another accountReal and annoyingBuy new or insist it is removed before purchase

The first line is the one to spend your attention on, and it is covered in full in can a thief disable a Bluetooth tracker. No amount of encryption survives a hand and a fingernail.

How is BlueTag secured, and what are its numbers?

BlueTag uses an MFi certified chip on Apple Find My, so the rotating identifier and the end to end encrypted location reports described above are how it works rather than an option. The full specification, exactly as published:

ItemFigure
PlatformApple Find My on iPhone or iPad, iOS 14.5 or later, no Android
Bluetooth linkUp to 60 m / 200 ft before the network takes over
Buzzer80 to 100 dB
CellCR2032, user replaceable, up to two years
SealingIP67
Size and mass36.3 × 36.3 × 9 mm, about 10 g
SiliconMFi certified, location data encrypted end to end
In the boxTwo tags, two key rings, a setup sheet

There is no Ultra Wideband in it, so there is no precision arrow for the final few paces, and no second app or account of ours holding anything about you. What the tag knows, it broadcasts anonymously; what your phone knows stays in Apple's system under your own sign in.

Two tags in a box, posted free anywhere in the UK, with a 30 day return window if it is not what you expected. Read the specification in full before you buy.

From the desk of Bluetooth Tracker Last revised

All workbench notes