ConceptioArchivearXiv CS
arXiv CSopen access

A Relay a Day Keeps the AirTag Away: Practical Relay Attacks on Apple's AirTags

Unknown · 2026 · arxiv_cs
arXiv CS · Papers · License: Open Access · 2026
Open Source ↗Direct PDF ↓
cryptography, security, privacy, cybersecurity

A Relay a Day Keeps the AirTag Away: Practical Relay Attacks on Apple’s AirTags Gabriel K. Gegenhuber1 , Sebastian Strobl2 , Leonid Liadveikin1 , and Florian Holzbauer1

arXiv:2604.10138v1 [cs.CR] 11 Apr 2026

1

University of Vienna, Faculty of Computer Science, 2 SBA Research

Abstract— Apple AirTags use Apple’s Find My network: when nearby iDevices detect a lost tag, they anonymously forward an encrypted location report to Apple, which the tag’s owner can then fetch to locate the item. That encryption protects privacy —neither the finder nor Apple learns the owner’s identity— but it also prevents Apple from validating the correctness of received reports. We show that this design weakness can be exploited: using a relay attack, we can inject manipulated location reports so the Find My service reports a false position for a lost AirTag. The same technique can be used to deny recovery of a targeted tag (a focused DoS), since the owner is misled about its whereabouts. Index Terms—AirTag; location tracker; relay attack

I. I NTRODUCTION With Apple’s Find My infrastructure [1], users can locate lost iDevices and —since the 2021 introduction of AirTags [2], [3]— everyday objects as well. AirTags’ small form factor and long battery life (up to one year on a coin cell) make them convenient for tagging keys, bags, or bicycles [3], but they also enable covert misuse: AirTags can be concealed on a person or in personal belongings and used to track individuals without their consent [5], [9], [11]. While both Apple and Android provide countermeasures to reduce unwanted tracking, studies reveal that these protections can suffer from substantial delays or outright failures, during which victims may unknowingly leak sensitive location information [6], [11]. The Find My network relies on hundreds of millions of participating iDevices to observe nearby lost items and forward encrypted geolocation reports to Apple; the item’s owner can then retrieve these reports to determine its location [1], [8]. While this design preserves privacy (the finder and owner remain anonymous), the encryption also prevents Apple from validating the integrity of submitted reports. In this paper, we exploit that gap: using a practical relay technique, we capture and rebroadcast an AirTag’s Bluetooth Low Energy (BLE) signal at a different place, causing nearby iDevices to generate and upload falsified location reports. As a result, the Find My app may display an incorrect position for the lost tag, effectively producing a targeted Denial-of-Service (DoS) against recovery. We validate the attack under realistic conditions and perform empirical characterization of AirTag behavior —including advertisement rotation and the usable lifetime of captured signals for replay/relay— to quantify the attack surface and limits. Our results expose a fundamental trade-off between privacy and integrity in the Find My design and motivate

countermeasures that preserve user privacy while ensuring the authenticity of location reports. II. M ETHODOLOGY AND I MPLEMENTATION We divided our study into three stages: (i) passive observation, (ii) emulation and relaying, and (iii) exploitation. Each stage built on the previous one to progressively characterize AirTag behavior and validate the relay attack under realistic conditions. All experiments were performed using our own devices and infrastructure and in accordance with applicable institutional research and ethics guidelines. A. Passive Observation and Beacon Collection To isolate signals from our test AirTag and minimize environmental noise, we conducted experiments in a controlled environment and continuously captured BLE advertisements. Using established open-source tooling (AirGuard [7], OpenHaystack [4]), we developed lightweight BLE collector scripts for Android, Linux, and ESP32 platforms to record raw advertisements, timestamps, RSSI, and relevant advertisement fields. From these captures, we identified the packets belonging to our device, observed state transitions between connected Location A

Lost AirTag

BLE Advertisement (1)

Bluetooth Beacon Collector (2)

Location = B (6) Apple's Servers

Relay Server (3)

Bluetooth Beacon Emitter

Location = B

AirTag Owner

(5)

BLE Advertisement (4)

Location B

Nearby Apple Devices

Fig. 1. Relaying an AirTag’s BLE advertisments over the Internet injects false location reports into the Find My system.

(paired to the owner’s phone) and lost modes, and confirmed regular key rotation behavior (for AirTags, once every 24h) reported in prior work [8], [10]. B. Emulation and Relay Second, we implemented the ability to emulate and rebroadcast captured beacons. After collecting advertisements from our test AirTag, we removed the battery from the original tracker device and used custom (non-official) hard- and software to retransmit the recorded packets. AirTags embed parts of their public key material in the BLE MAC address; because changing the BLE MAC on unrooted Android devices is not possible, we implemented BLE emitter code for Linux and ESP32 targets that permit MAC manipulation. We validated successful emulation by observing that the owner’s Find My client retrieved location reports corresponding to the emulated broadcasts. To demonstrate remote relaying, we rebroadcast the captured beacon at a remote location (i.e., a Raspberry Pi located at a research institute in another country); iDevices near that site generated and uploaded geolocation reports for the emulated tag, which our owner device was able to fetch, confirming that relayed signals can produce falsified location reports. C. Testing Corner Cases and Exploitation Finally, we evaluated the practical limits and abuse potential of captured and retransmitted beacons. Our goal was to determine the usable lifetime of a captured advertisement before it can no longer be used to create false reports. To facilitate our experiments, we implemented a relay server that ingests reports from collector devices, timestamps first occurrence, stores raw advertisements, and provides controlled replay scheduling to emitter nodes. Figure 1 shows our experimental setup. III. R ESULTS Our findings show, that the Find My app differentiates between two data sources: Cloud Reports: Location reports that come from the Find My cloud are only considered when they use the most-recent public key. Thus, key rotations on the AirTag invalidate all previous keys. When an AirTag’s current BLE beacons were continuously relayed to a remote location, the Find My app alternated between the legitimate and relayed positions, causing jumps between the two competing locations. • Local BLE Beacons: When the AirTag appears within the BLE range of the owner device, the Find My app assumes that it is close and therefore ignores any data that is reported via the cloud. Overriding cloud reports with local advertisements also worked with previously recorded i.e., historic beacons. •

The Find My app also differentiates between recent and outdated reports, as show in Figure 2.

last seen: Now

last seen: Day 7

Days 1 to 7

Days 8 and ongoing

Fig. 2. While, key rotations on the AirTag invalidate previous keys (for cloud reports), historic beacons can still be used to mislead the tag owner via local BLE advertisments. When surpressing key rotations on the AirTag (e.g., by removing the battery), captured BLE beacons can be replayed for seven days before the Find My app flags them as outdated.

IV. C ONCLUSION AND F UTURE W ORK Our results demonstrate that the design of Apple’s Find My protocol is vulnerable to practical relay attacks. Beyond highlighting this attack vector to the security community, future work will examine whether relaying could be repurposed as an active countermeasure against stalking by obfuscating or disrupting unwanted tracking. Therefore, we aim to investigate which algorithms (e.g., averaging) are used to reconcile multiple recent location reports. Finally, we plan to broaden our study to include additional tracker ecosystems (e.g., Chipolo, Samsung SmartTag, Tile) to assess whether similar weaknesses exist across competing platforms. R EFERENCES [1] Apple. Find My, 2019. https://www.apple.com/icloud/find-my/. [2] Apple. Apple introduces AirTag, 2021. https://www.apple.com/ newsroom/2021/04/apple-introduces-airtag/. [3] Apple. AirTag, 2022. https://www.apple.com/at/airtag/. [4] Lukas Burg, Max Granzow, Alexander Heinrich, and Matthias Hollick. Openhaystack mobile-tracking custom find my accessories on smartphones. In Proceedings of the 15th ACM Conference on Security and Privacy in Wireless and Mobile Networks, pages 277–279, 2022. [5] Dañiel Gerhardt, Matthias Fassl, Carolyn Guthoff, Adrian Dabrowski, and Katharina Krombholz. AirTag-Facilitated Stalking Protection: Evaluating Unwanted Tracking Notifications and Tracker Locating Features. 2025. [6] Alexander Heinrich, Niklas Bittner, and Matthias Hollick. AirGuard – Protecting Android Users From Stalking Attacks By Apple Find My Devices, 2022. [7] Alexander Heinrich, Niklas Bittner, and Matthias Hollick. Airguardprotecting android users from stalking attacks by apple find my devices. In Proceedings of the 15th ACM Conference on Security and Privacy in Wireless and Mobile Networks, pages 26–38, 2022. [8] Alexander Heinrich, Milan Stute, Tim Kornhuber, and Matthias Hollick. Who Can Find My Devices? Security and Privacy of Apple’s CrowdSourced Bluetooth Location Tracking System. PETs, 2021. [9] Alexander Heinrich, Leon Würsching, and Matthias Hollick. Please Unstalk Me: Understanding Stalking with Bluetooth Trackers and Democratizing Anti-Stalking Protection. PETs, 2024. [10] Travis Mayberry, Ellis Fenske, Dane Brown, Jeremy Martin, Christine Fossaceca, Erik C. Rye, Sam Teplov, and Lucas Foppe. Who Tracks the Trackers? Circumventing Apple’s Anti-Tracking Alerts in the Find My Network. In Proceedings of the 20th Workshop on Workshop on Privacy in the Electronic Society, WPES ’21, page 181–186, New York, NY, USA, 2021. Association for Computing Machinery. [11] Kieron Ivy Turk, Alice Hutchings, and Alastair R. Beresford. Can’t keep them away: The failures of anti-stalking protocols in personal item tracking devices. 2023.

A Relay a Day Keeps the AirTag Away: Practical Relay Attacks on Apple’s AirTags Gabriel K. Gegenhuber, Leonid Liadveikin, Florian Holzbauer (University of Vienna), Sebastian Strobl (SBA Research)

Background & Motivation Apple’s Find My network enables users to locate lost devices and AirTags by crowdsourcing location data from nearby iPhones. ▶ AirTags broadcast Bluetooth Low Energy (BLE) beacons containing their public key. ▶ Nearby iDevices (e.g., iPhones) detect these and upload encrypted location reports to Apple. ▶ Encryption preserves user privacy, but also prevents Apple from verifying whether the data is legitimate. Misuse: AirTags can facilitate unwanted tracking or stalking. ▶ Both Android and iOS implement anti-stalking notifications and detection features. ▶ Existing solutions can suffer from substantial delays or failures. ▶ Victims are often alerted only after their location is exposed.

Research Objective

Methodology

To demonstrate and analyze a practical relay attack that can:

(i) Passive Observation ▶ Capturing BLE advertisements from our own AirTag in a controlled

▶ Inject false locations into Apple’s Find My network. ▶ Mislead owners or deny recovery of a tag (targeted DoS).

environment.

▶ Evaluate whether this behavior could also be leveraged to protect

▶ Observing key roatations (every 24 h) and state transitions (paired vs. lost state).

against unwanted tracking.

(ii) Emulation & Relay ▶ Confirming relay attack: rebroadcasted BLE beacons generate false location reports. ▶ Verified attack over long-distances (between countries).

Experimental Setup Building upon existing open-source tools (AirGuard, OpenHaystack) and custom hardware (Android, Linux, ESP32), we created a flexible relay infrastructure for timestamping, storage, and scheduled replays.

(iii) Controlled Exploitation ▶ Evaluating practical limits and abuse potential of relaying. ▶ Measuring the usable lifetime of captured beacons.

Location A

Lost AirTag

BLE Advertisement (1)

Results & Observations

Bluetooth Beacon Collector

Data Source Handling ▶ Local BLE beacons are preferred over cloud reports, leading to DoS

(2)

Location = B (6) Apple's Servers

Relay Server (3)

Location = B

when owner device is in close proximity. Relay Effects

AirTag Owner

(5)

▶ Continuous relaying to remote location leads to jumping between true and false positions. Beacon Lifetime ▶ Local BLE Reports: Captured beacons remain valid for at least 7 days

Bluetooth Beacon Emitter

before being flagged as outdated.

BLE Advertisement (4)

Location B

Nearby Apple Devices

▶ Cloud Reports: Key rotations on the AirTag invalidate all previous keys.

Figure 1: Relaying an AirTag’s BLE advertisments over the Internet injects false location reports into the Find My system.

Using our tooling for recording and replaying AirTag BLE beacons, we show that Apple’s Find My protocol is highly vulnerable to practical relay

Conclusion & Future Work ▶ Relay attack feasible, attackers can mislead or block item recovery.

attacks. The findings underline a core limitation of Apple’s privacy model:

▶ Relay mechanism can be repurposed as a privacy shield.

encryption protects identities but prevents the server from validating re-

▶ Extend analysis to other trackers: Chipolo, Samsung SmartTag, Tile.

port integrity.

▶ Further explore ethical relay-based anti-stalking defenses.

This work was partially supported by the FFG ASAP project space4energy (911958) and the FFG GigaApp project Q-Crit Austria (917949).

SBA Research (SBA-K1) is a COMET Centre within the framework of COMET – Competence Centers for Excellent Technologies Programme and funded by BMK, BMDW, and the federal state of Vienna. The COMET Programme is managed by FFG.

Record · ID 10297 · SHA-256 dec7c1c6caa4dd7f
Conceptio Open Knowledge Archive — every document is proof-bundled with source, license, and retrieval metadata.