Exactly. After reading the whitepaper on how it works, the device that needs to be tracked has to be compromised with their client software. The "lost" device then hashes their Bluetooth id, sends it to the malware server and then broadcasts it out to the Find My network as a lost device. Using the server or another device that has decoded the hash with a GPU, you can then get that information from the network and track that device.