Apple AirTag Hacked, Says Security Researcher Who Found Loopholes to Modify Firmware

German security researcher Thomas Roth who goes by the name “stacksmashing” on Twitter has been able to “break into” the microcontroller of the AirTag.

Advertisement
By Jagmeet Singh | Updated: 10 May 2021 11:45 IST
Highlights
  • Apple AirTag has been hacked by Thomas Roth
  • The researcher posted details about the hack on Twitter
  • Apple AirTag’s Lost Mode could be tweaked once it’s hacked

Apple AirTag is claimed to be designed with privacy and security at its core

Photo Credit: Apple

Apple AirTag, the Bluetooth tracker that was unveiled last month to let people find their lost items, is claimed to have some security loopholes that could allow hackers to modify its firmware. A security researcher has demonstrated the loopholes by hacking the AirTag using reverse engineering. The researcher claimed on Twitter that he was able to modify the default NFC link available through the tracker by reflashing its microcontroller. This appears to be the first successful “jailbreak” attempt on the AirTag, which Apple claims to be designed with privacy and security at its core.

German security researcher Thomas Roth who goes by the name “stacksmashing” on social media tweeted on Sunday that he was able to successfully hack the Apple AirTag by “breaking into” its microcontroller. He claimed that after gaining access to the microcontroller, he reprogrammed the AirTag and modified its firmware.

The changes made by the security researcher allowed him to tweak the functionality of the AirTag and put a custom NFC link when it is in the Lost Mode, as shown in a video posted on Twitter.

Advertisement

 

Normally, when the AirTag is in the Lost Mode, it shows a notification when scanned by an NFC-capable smartphone, such as an iPhone or an Android smartphone, with a link to the found.apple.com website (part of the Find My network) to display information about the owner.

Advertisement

The hackers could be able to leverage the loopholes showcased on Twitter to target those who found the lost AirTag to malicious websites, instead of displaying information about the user. However, Roth did mention in his tweets that it took hours for him to bring modifications. He also said that he bricked a couple of AirTags before reaching success.

Apple claimed privacy and security as the core features of the AirTag at the time of its official announcement last month. However, the tweets posted by Roth suggest that the Cupertino company may need to bring an update to block firmware-level modification.

Advertisement

Gadgets 360 has reached out to Apple for a comment and will update this space when the company responds.


We dive into all things Apple — iPad Pro, iMac, Apple TV 4K, and AirTag — this week on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Apple AirTag, AirTag, Apple
Advertisement

Related Stories

Popular Mobile Brands
  1. Top OTT Releases of the Week: Kantara Chapter 1, Lokah Chapter 1, Idli Kadai, and More
  2. iQOO 15 Indian Variant Allegedly Surfaces on Geekbench Ahead of Launch
  3. Apple CEO Confirms Partnership Plans for AI Services Beyond OpenAI
  4. Realme GT 8 Pro India Launch Date Leaked: Here's When It Might Arrive
  1. SpaceX Revises Artemis III Moon Mission with Simplified Starship Design
  2. Rare ‘Second-Generation’ Black Holes Detected, Proving Einstein Right Again
  3. Starlink Hiring for Payments, Tax and Accounting Roles in Bengaluru as Firm Prepares for Launch in India
  4. Google's 'Min Mode' for Always-on Display Mode Spotted in Development on Android 17: Report
  5. OpenAI Upgrades Sora App With Character Cameos, Video Stitching and Leaderboard
  6. Samsung's AI-Powered Priority Notifications Spotted in New One UI 8.5 Leak
  7. Samsung Galaxy S26 Series Could Feature Model Slimmer Than Galaxy S25 Edge With New Name
  8. iQOO 15 Colour Options Confirmed Ahead of November 26 India Launch: Here’s What We Know So Far
  9. Vivo X300 to Be Available in India-Exclusive Red Colourway, Tipster Claims
  10. OpenAI Introduces Aardvark, an Agentic Security Researcher That Can Find and Fix Vulnerabilities
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.