Bluetooth tracker security: can a tag be cloned?
Bluetooth tracker security is a fair thing to ask about before you attach one to a bike or a toolbox, because the tag is doing something that sounds alarming when you say it out loud: broadcasting, constantly, to anyone within range. This article defines what is actually being sent, answers the cloning question directly, and separates the attacks that work from the ones that do not.
What is Bluetooth tracker security?
Bluetooth tracker security is the problem of letting a tag be found by strangers' phones while revealing nothing about its owner to those strangers. Every finding tag has to advertise, or no passing device could ever hear it and no position could ever be relayed. The design question is therefore not how to hide the broadcast, which is impossible, but how to make the broadcast useless to everyone except the one account entitled to read the result. That is done in two places: the identifier the tag sends, and the encryption on the position a passing device reports.
How does a tag hide who owns it?
It advertises an anonymous identifier that changes regularly and carries no name, no account and no serial number a stranger could look up. What leaves the tag is a short packet that says, in effect, "a Find My accessory is here". It does not say whose, and because the identifier rotates, two sightings hours apart cannot be reliably strung together by an observer into a trail belonging to one person.
The second half happens on the finder's side. When an Apple device hears the tag, it reports the position in encrypted form, and that report can be decrypted only by the Apple Account the tag is registered to. The phone that helped does not learn what it found, and neither does the manufacturer, the shop that sold it or Apple.
Can a Bluetooth tracker be cloned?
Someone can copy the packet a tag is currently broadcasting, but a copy is not a key: it grants no access to the owner's map, no location history and no control over the real tag. This is the part worth being precise about, because "cloned" suggests a duplicate that works, and it is not that.
A clone can do exactly one thing: cause an extra device to appear where the copied advertisement is heard. It cannot ring the original. It cannot see where the original has been. It cannot register itself to your Apple Account or unregister the tag from it. And because the broadcast identifier rotates, a copied one goes stale on its own. Compare that with the effort involved and the attack does not pay, which is why the plausible threats to your bike are all physical.
Can someone scan for my tag with an app?
A general Bluetooth scanner app will show that some accessory is advertising nearby, and nothing further. These apps list signal strength and a device type, and people sometimes use them when hunting for a tag they have been warned about. The listing does not name an owner, does not open a location history and cannot be used to claim the tag.
Signal strength is a poor ruler as well, for the reasons set out in our explainer on what RSSI is and why it misleads: a strong reading means a clear path, not necessarily a short one. If you have been warned by your iPhone that an accessory is travelling with you, the built in flow is more use than any scanner, because it can make the thing sound.
Which risks are real?
The realistic threats are physical or social rather than cryptographic. Ranked by how often they actually matter:
| Risk | How real | What helps |
|---|---|---|
| A thief finds the tag and pulls the cell | Very real | Hide it well and tag the case as well as the contents |
| Somebody plants a tag on you | Real, and alerted | Apple's unwanted tracking warnings on your iPhone |
| A stranger scans and identifies your tag | Not a practical concern | Nothing needed |
| A cloned advertisement reveals your history | Not how it works | Nothing needed |
| Buying a used tag still bound to another account | Real and annoying | Buy new or insist it is removed before purchase |
The first line is the one to spend your attention on, and it is covered in full in can a thief disable a Bluetooth tracker. No amount of encryption survives a hand and a fingernail.
How is BlueTag secured, and what are its numbers?
BlueTag uses an MFi certified chip on Apple Find My, so the rotating identifier and the end to end encrypted location reports described above are how it works rather than an option. The full specification, exactly as published:
| Item | Figure |
|---|---|
| Platform | Apple Find My on iPhone or iPad, iOS 14.5 or later, no Android |
| Bluetooth link | Up to 60 m / 200 ft before the network takes over |
| Buzzer | 80 to 100 dB |
| Cell | CR2032, user replaceable, up to two years |
| Sealing | IP67 |
| Size and mass | 36.3 × 36.3 × 9 mm, about 10 g |
| Silicon | MFi certified, location data encrypted end to end |
| In the box | Two tags, two key rings, a setup sheet |
There is no Ultra Wideband in it, so there is no precision arrow for the final few paces, and no second app or account of ours holding anything about you. What the tag knows, it broadcasts anonymously; what your phone knows stays in Apple's system under your own sign in.
Two tags in a box, posted free anywhere in the UK, with a 30 day return window if it is not what you expected. Read the specification in full before you buy.
From the desk of Bluetooth Tracker Last revised
Related notes
How it works5 min readBluetooth tracker Android support: the honest answer
Bluetooth tracker Android compatibility, explained without the fudge. Why Find My tags refuse to pair, what Google Find Hub is, and what to buy instead.
How it works5 min readUnwanted tracker alerts: the Apple and Google standard
An unwanted tracker alert means a tag is moving with you. What the joint Apple and Google specification does, how to find the tag, and what to do next.
How it works5 min readBluetooth tracker for keys: the complete UK guide
A Bluetooth tracker for keys only earns its place if it survives a keyring. Attachment, loudness, battery, and where keys are actually lost.