Imagine your keys are tracking you. Not just your location, but your every move — and the company that made them is selling that data to the highest bidder. That’s not a dystopian fantasy. That’s exactly what’s happening with every Tile tracker you own.
You probably bought a Tile to find your wallet. Life360 bought Tile to find you.
Tile’s most dangerous feature isn’t a bug. It’s a business model.
Last year, researchers published a paper (arXiv:2510.00350) showing that Tile’s security is so bad, it’s practically a gift for stalkers. The Bluetooth-based tracking system has a fundamental flaw: it’s designed to be findable by anyone, anywhere. That’s great when you lose your keys. It’s terrifying when someone wants to track your movements without consent.
But here’s the kicker — the company has known about this for years. And they’ve done nothing. Why? Because the vulnerability isn’t a mistake. It’s the engine of their revenue.
Tile was acquired by Life360 in 2021. Life360 started as a family location-sharing app. Now it’s a data brokerage. Their entire business model depends on hoovering up location data and selling it to advertisers. The more devices that ping the network, the more data they collect. The more data they collect, the more money they make.
One commenter on the original Adafruit article nailed it: “This explains why I’m seeing commercials for Life360 now for the first time ever: They’ve developed a new revenue stream by selling everybody’s location to advertisers.” That commenter deleted the app from their family’s phones. You should too.
The company doesn’t want to fix the security flaw. They want to sell it.
Let’s be clear: this isn’t a case of incompetence. It’s a deliberate design choice. By keeping the network open and the tracking protocol weak, Life360 ensures that every Tile device becomes a beacon that feeds their location database. They’re not just tracking your keys. They’re tracking every phone that comes near your keys.
Think about that. Every time you walk past a Tile, you’re being logged. Every time someone walks past your Tile, they’re being logged. It’s a surveillance mesh network, and you paid for the privilege of being part of it.
Apple’s AirTag has similar stalking concerns, but Apple at least made noise about fixing them. Tile? Crickets. Because Apple’s business is hardware. Life360’s business is you.
So what can you do? First, delete the Tile app. Second, remove the battery from any Tile devices you own. Third, if you really need a tracker, use something that doesn’t double as a data pipe. MyGrid.app is one option, though development has been slow. At least their website claims they support degoogled Android — a step in the right direction.
But the real question is: how many other products are built on the same model? How many ‘smart’ devices are actually just Trojan horses for data collection?
You thought you bought a tool. They thought you bought a product.
This isn’t a warning. It’s a call to action. The next time you see a Life360 commercial, remember: they’re not advertising a service. They’re advertising their inventory. And you’re the merchandise.
FAQ
Q: Is the Tile vulnerability really that bad?
A: Yes. The research shows that Tile's Bluetooth tracking can be used to locate any Tile device with high precision, and the network is open to anyone. There's no consent mechanism, no authentication. It's a stalker's dream.
Q: What should I do if I own a Tile?
A: Remove the battery and delete the app. If you need a tracker, look for alternatives that prioritize security over data collection. MyGrid is one option, but do your own research.
Q: Isn't this just a typical security trade-off?
A: No. The typical trade-off is between convenience and security. Here, the 'vulnerability' is actually a feature that generates revenue for Life360. They're not trying to fix it because it's their business model. That's a different category of risk.