Tile trackers used by millions contain a serious privacy flaw that could let tech-savvy stalkers, and potentially the company itself, follow users’ movements, according to researchers.

Security experts at Georgia Tech found Life360’s Tile tags broadcast an unencrypted MAC address alongside a rotating ID.

Because the MAC address doesn’t change and the rotating ID can be predicted from past broadcasts, a single intercepted message can “fingerprint” a tag for life, the team told Wired.

This flaw makes it alarmingly easy for someone with a phone or a radio-frequency scanner to track a tag’s movements without the owner’s knowledge.

Even worse, the researchers demonstrated replay attacks that can rebroadcast another person’s Tile signals elsewhere – a technique that could be used to falsely implicate someone in stalking.

They also say Tile’s servers receive these identifiers in cleartext, a design choice that would theoretically allow the company to map tag locations despite public assurances to the contrary.

Tile’s anti-stalking controls are another weak link.

Unlike Apple and Google, which use encrypted broadcasts and frequently rotate hardware addresses, Tile’s “Scan and Secure” detection relies on manual checks and can be defeated if a tag is put into Anti-Theft mode – a feature intended to hide devices from thieves.

Critics say that combination leaves victims exposed and makes enforcement of Tile’s US$1 million (A$1.5 million) fine for misuse an uncertain deterrent.

Life360 acquired Tile in 2021. The first new Tile products were launched under Life360 in September 2024, with the full integration of Tile features into the Life360 app becoming available in 2025.

The Georgia Tech team says it disclosed the flaws to Life360 in November, while Wired reports communication stopped in February.

Life360 has told media it has “made a number of improvements” but hasn’t detailed fixes.