HMD Fuse Sales Paused After 'Child-Safe' Phone Exposes Live GPS And Kill-Switch Bugs

Security researcher Paul Moore says flaws in the HMD Fuse and HarmBlock+ platform let anyone remotely track a child's live GPS, toggle apps, read messages and disable every protection — including SafeToNet's AI filter.

HMD Fuse Sales Paused After 'Child-Safe' Phone Exposes Live GPS And Kill-Switch Bugs

HMD Global has paused sales of the HMD Fuse, its self-styled "world's safest" smartphone for children, after security researcher Paul Moore published a disclosure showing that anyone can track a Fuse user's live GPS location, enable or disable apps, read or send their messages, and switch off every protection layer on the device — including the SafeToNet-powered HarmBlock+ AI content filter that the phone is built around.

Seven months of disclosures, no full fix

Moore, a UK-based independent security consultant, said the vulnerabilities were disclosed privately to HMD, SafeToNet and Xplora Technologies over the past seven months. The flaws are not, in his words, complex "hacks"; they sit in the parental-control stack that binds the three vendors together, which he says allows unauthenticated remote access to child accounts. The device continued to ship in the UK and Europe while the research team escalated. HMD and its partners paused sales this week while they investigate the reported chain of bugs, according to the Financial Times report on the incident, echoed in a Tech Startups roundup on Friday.

The pitch that just collapsed

The HMD Fuse launched with a marketing message that made child safety the entire product: on-device HarmBlock+ AI would detect and block nude imagery and other harmful media before it could be captured, sent or received; parents would get live location, contact allow-lists, and app kill-switches through an Xplora-powered companion. UK regulators had cited the design as a promising alternative to app-store gating. The bugs invert every one of those promises — location, messages and controls become accessible to an attacker instead of protecting the child.

HMD Fuse child-safe smartphone HarmBlock+ AI SafeToNet Xplora security

Why one weak link matters more when the product is safety

The episode illustrates a lesson the safety-tech industry keeps re-learning: an AI content filter, however capable, cannot make a device "safe" if any other component in the software stack — authentication, cloud API, MDM channel, third-party companion app — leaks. Users experience the phone as one product, so the security posture is only as strong as the weakest vendor. The Fuse combines HMD's Android build, SafeToNet's AI, and Xplora's parental controls, and Moore's disclosure points at the seams between them.

Policy fallout looks likely

The story lands as UK, EU and Australian regulators are pushing operating-system-level child-safety enforcement onto device makers. If a phone marketed as the safest option ships with GPS and kill-switch bugs for seven months, the same regulators may harden pre-shipment audit and disclosure duties on hardware vendors that market to families. It also raises questions for enterprises rolling out age-assurance and youth-mode features, from Meta's smart-glasses recording loophole to Apple's Communication Safety toggles, and mirrors the 100-company open letter on AI-driven cyber threats published this week.

Reporting based on coverage from the Financial Times, Paul Moore's disclosure notes and Tech Startups.

Category: Cyber Security

Tags: AI Cybersecurity Supply Chain Zero-Day

Related Articles