One Bluetooth Glitch Uncovered A Privacy Surprise

Person holding smartphone with Alibaba app on screen
Photo: Jirapong Manustrong / Shutterstock

A Chinese-owned shopping giant used a hidden trick to secretly track American shoppers’ devices, and it only got caught because it broke someone’s Bluetooth headphones.

Story Snapshot

  • AliExpress, owned by Chinese conglomerate Alibaba Group, ran silent audio code that fingerprinted visitors’ devices without their knowledge.
  • A developer discovered the scheme only after the hidden code broke his Bluetooth headphone connection.
  • The audio never played out loud and never used a microphone, but it still let Alibaba build a unique digital ID for each visitor.
  • Two obfuscated scripts tied to Alibaba’s anti-fraud system, called AWSC, were responsible for the tracking.
  • Privacy-focused browsers like Brave and Firefox already block the technique, while Chrome users remain exposed by default.

Hidden Code Turns Browsers Into Silent Trackers

Researchers and the privacy-focused Brave browser found that AliExpress secretly created hidden “Web Audio” processes on its homepage. The code built an audio pathway with the volume set to zero, so shoppers heard nothing. But the browser still processed the silent sound, and that processing became a fingerprint of the device.

This kind of tracking works because every computer’s sound hardware and software process audio slightly differently. By generating a test tone and measuring the tiny differences in how a device handles it, a company can identify a user’s browser without ever asking permission or dropping a cookie.

Bluetooth Failure Exposed the Scheme

Nobody would have noticed this scheme if it hadn’t broken something. A developer investigating why his Bluetooth headphones kept failing to switch between his phone and computer traced the problem back to AliExpress. The site’s silent audio code was holding onto the system’s audio output, jamming the normal Bluetooth handoff process.

That accident led the developer to dig deeper into AliExpress’s website code. He found two heavily disguised scripts buried inside Alibaba’s AWSC anti-fraud toolkit, both quietly building an audio-processing graph in the background of the page. What looked like a security tool for stopping fraud was secretly doing something else: building a permanent profile of the visitor’s device.

Alibaba’s site made a shopper’s computer play a sound nobody could hear, just to measure how it processed that sound and turn the result into a unique ID. No microphone recorded anyone’s voice, and no audio ever reached a speaker. But the company still got what it wanted: a way to recognize the same device again and again, even if the user cleared cookies or used a private browsing window.

Chinese Tech Giant’s Track Record Raises Alarms

This is not some random ad-tech startup cutting corners. Alibaba is one of China’s largest companies, and Chinese law gives Beijing sweeping authority to demand data from firms headquartered there. Any data AliExpress quietly harvests from American shoppers, including hidden device fingerprints, sits inside a corporate structure that answers to the Chinese Communist Party when asked.

Conservatives have spent years warning about apps and platforms with ties to Beijing collecting American data without real transparency or consent. This episode fits that pattern exactly: a foreign-owned company running obfuscated code that most shoppers could never detect, doing far more than the “anti-fraud” label suggested. Limited government types and privacy advocates alike should be asking why a shopping website needs to secretly fingerprint every visitor’s hardware at all.

Browser fingerprinting itself is not new, and it is not limited to AliExpress. A survey from the Electronic Frontier Foundation found the practice on 78 percent of the top 10,000 most-visited websites, a sharp jump from prior years. What sets the AliExpress case apart is the deliberate concealment, the link to a foreign anti-fraud system, and the fact that ordinary Chrome users have no built-in defense against it, unlike Firefox or Brave users who are automatically shielded.

For now, shoppers who want to avoid the hidden tracking have limited options: switch to a privacy-hardened browser, install a content-blocking filter, or simply think twice before handing more data to a platform owned by a company operating under Chinese Communist Party oversight. Until AliExpress or Alibaba publicly explains why the code exists, American consumers are left to assume the worst about what else might be quietly running in the background.

Sources:

zerohedge.com, malwarebytes.com, theregister.com, mallory.ai, spidersweb.pl, zicode.com