Crowdsourced location networks turn billions of consumer devices into a global sensor grid for locating lost items, but the same reach enables two systemic abuses: (i) location tracking via beacons that masquerade as “lost tags,” and (ii) data exfiltration by embedding short secrets in Bluetooth Low Energy (BLE) advertisements that are relayed forward without inspection. Using Apple’s Find My as a case study, we show that covert beacons reliably reach the cloud and then the attacker within minutes due to relay density. We also find that basic single-layer countermeasures such as packet dropping, TCP ACK/RST injection, fixed-delay insertion, or traffic flooding fail under realistic operational conditions. We contribute the first end-to-end experimental evaluation of deployable mitigations that require no vendor changes. Our defense-in-depth design combines: endpoint controls that correlate OS location-service access with immediate BLE advertising and enforce per-process advertising limits; a hybrid perimeter detector that correlates on-host BLE advertisement counts with outbound traffic to crowd-location backends; and physical controls for high-security areas, including exclusion zones of 35 m indoors and 200 m outdoors (line of sight), optionally supported by selective, low-duty RF jamming. For the longer term, we outline protocol changes that vendors can adopt, such as basic beacon admission control and authentication, shorter helper-retention timers, and helper-side quotas. While evaluated on Find My, these findings generalize to crowdsourced location systems built under similar design assumptions.