HMD Global has paused sales of the HMD Fuse, its self-styled "world's safest" smartphone for children, after security researcher Paul Moore published a disclosure showing that anyone can track a Fuse user's live GPS location, enable or disable apps, read or send their messages, and switch off every protection layer on the device — including the SafeToNet-powered HarmBlock+ AI content filter that the phone is built around.
Seven months of disclosures, no full fix
Moore, a UK-based independent security consultant, said the vulnerabilities were disclosed privately to HMD, SafeToNet and Xplora Technologies over the past seven months. The flaws are not, in his words, complex "hacks"; they sit in the parental-control stack that binds the three vendors together, which he says allows unauthenticated remote access to child accounts. The device continued to ship in the UK and Europe while the research team escalated. HMD and its partners paused sales this week while they investigate the reported chain of bugs, according to the Financial Times report on the incident, echoed in a Tech Startups roundup on Friday.
The pitch that just collapsed
The HMD Fuse launched with a marketing message that made child safety the entire product: on-device HarmBlock+ AI would detect and block nude imagery and other harmful media before it could be captured, sent or received; parents would get live location, contact allow-lists, and app kill-switches through an Xplora-powered companion. UK regulators had cited the design as a promising alternative to app-store gating. The bugs invert every one of those promises — location, messages and controls become accessible to an attacker instead of protecting the child.

Why one weak link matters more when the product is safety
The episode illustrates a lesson the safety-tech industry keeps re-learning: an AI content filter, however capable, cannot make a device "safe" if any other component in the software stack — authentication, cloud API, MDM channel, third-party companion app — leaks. Users experience the phone as one product, so the security posture is only as strong as the weakest vendor. The Fuse combines HMD's Android build, SafeToNet's AI, and Xplora's parental controls, and Moore's disclosure points at the seams between them.
Policy fallout looks likely
The story lands as UK, EU and Australian regulators are pushing operating-system-level child-safety enforcement onto device makers. If a phone marketed as the safest option ships with GPS and kill-switch bugs for seven months, the same regulators may harden pre-shipment audit and disclosure duties on hardware vendors that market to families. It also raises questions for enterprises rolling out age-assurance and youth-mode features, from Meta's smart-glasses recording loophole to Apple's Communication Safety toggles, and mirrors the 100-company open letter on AI-driven cyber threats published this week.
Reporting based on coverage from the Financial Times, Paul Moore's disclosure notes and Tech Startups.
