A new paper, PrivacyShield: Relaying BLE Beacons to Counter Unsolicited Tracking, proposes a way to make hidden Bluetooth trackers less useful to stalkers by causing them to appear in other locations. It presents a working research prototype, tested mainly against Apple’s AirTags and Find My network.

The underlying problem is that these tracking networks enlist nearby phones to report a tag’s location, potentially including the victim’s own phone. The authors argue that existing anti-stalking measures offer insufficient protection. Alerts take time to appear, speakers can be disabled, and modified trackers can evade detection by changing their identifiers or pretending to be another type of device.
PrivacyShield captures nearby tags’ Bluetooth broadcasts and sends them over the internet to relay stations elsewhere. Those stations rebroadcast the signals, prompting nearby phones to report the tag at the relay’s location. This exploits the network’s inability to distinguish an original broadcast from a relayed copy. The prototype uses a modified Android app, a server and inexpensive ESP32 hardware, without requiring Apple’s cooperation or physical access to the hidden tracker.
In experiments with locations roughly four kilometres apart, the researchers made Apple’s Find My app display an AirTag at the relay location. With one reporting phone at each location, rebroadcasting twice per second reliably produced the false location; slower rebroadcasting caused the displayed position to alternate or stop updating. Effectiveness depended on both broadcast frequency and the number of phones reporting each location.
The crucial limitation is that confusing the displayed location does not necessarily erase the real one and genuine location reports can remain available. A sophisticated attacker analysing all reports, or using prior knowledge of the victim’s movements, might distinguish real locations from decoys. The experiments are relatively small, and protection across other tracking networks is proposed rather than demonstrated to the same extent. The system also cannot protect against GPS trackers, can disrupt legitimate lost-item tracking and could be misused to conceal stolen belongings.
The authors therefore present PrivacyShield as a temporary defence while providers improve their systems. They recommend faster alerts, alerts covering all device types and stronger protocol-level protections. The paper’s main contribution is demonstrating that relaying tracker signals can give potential victims a practical means of disrupting surveillance, although it does not establish guaranteed protection against determined stalkers.
The same principle could apply to ordinary, non-proprietary Bluetooth Low Energy beacons where a receiving system treats a broadcast identifier as evidence of location or proximity. Capturing and rebroadcasting that signal elsewhere could create misleading detections, although the effect would depend on how the receiving system validates and processes them. The broader lesson for users and system designers is that detecting a beacon’s signal does not always, by itself, prove that the original device is physically nearby. More security sensitive applications need to do more checks.








