DangNH Studio
NEWSEN

How Hackers Turned a Kids' Smartwatch Into a Spy Device

10/08/2026 905 views
How Hackers Turned a Kids' Smartwatch Into a Spy Device

Introduction

Many people assume that inexpensive wearable gadgets for children are harmless toys with limited functionality. The reality is far more complex: a low‑cost pink smartwatch, sold for under $30, can be commandeered to track, photograph, and record a wearer without any visible indication. This article unpacks the technical failures, the scale of the problem, and the implications for consumers worldwide.

The Spy‑Ready Features of a $30 Child’s Watch

On a rainy morning in New York, a WIRED reporter equipped himself with a lavender‑pink smartwatch intended for kids. Within minutes, Greek security researcher Vangelis Stykas, who had shipped the device via Amazon, began monitoring the reporter’s exact location using Wi‑Fi identifiers, even though the GPS module was malfunctioning. By exploiting a hidden camera function, Stykas captured a photo of the reporter entering an elevator and another at his desk. Simultaneously, microphone data was streamed to fellow researcher Felipe Solferini, who overheard a casual conversation about an art exhibition. The device never displayed any warning, proving that the watch’s firmware allowed silent surveillance.

Concentrated Supply Chains Create a Single Point of Failure

The smartwatch originates from CJC, a little‑known brand, and is manufactured by YiQingTeng Electronics in Shenzhen, China. More troubling is that YiQingTeng’s backend, known as SETracker, powers dozens of other brands, including those marketed under names like Wonlex. Researchers examined over 70 GPS‑enabled watches and car accessories and discovered that more than 30 of them rely on the same YiQingTeng platform, while another 30+ use the NewGPS2012 system. A third major platform, SinoTrack, also supports millions of devices. This “white‑label” model means a single vulnerability can compromise an entire ecosystem of products sold under many different labels.

Concrete Exploits Demonstrated at Black Hat 2026

During the Black Hat conference on August 6, 2026, Stykas and Felipe Solferini presented their findings. They showed that the SETracker backend suffered from an authentication flaw that let anyone send commands to any registered device, simply by knowing the parent’s email address. In the case of SinoTrack, a demo account could control any device, and a SQL injection allowed extraction of location data, passwords, and vehicle records. NewGPS2012 exhibited similar injection bugs, and evidence suggested the servers had previously been breached. These attacks were not theoretical; the researchers used them live on the reporter’s watch, confirming that the vulnerabilities are exploitable in real time.

Industry Reaction and the Persistence of Risk

When WIRED contacted SETracker, the company initially claimed the issues were already resolved and asked for proof. After the demonstration, SETracker announced it had blocked certain ports and forced a subset of legacy clients to upgrade, stating the vulnerability was “thoroughly remediated.” However, the researchers observed that their exploits stopped working only hours before the talk, leaving uncertainty about the fix’s completeness. SinoTrack and NewGPS2012 did not respond to inquiries, and the researchers reported that their attack methods still functioned against those platforms. The pattern of delayed or incomplete patches underscores a broader industry challenge: rapid product turnover and low profit margins often deprioritize security updates.

FAQ

Q: Can any hacker locate a child’s smartwatch without the GPS working?

A: Yes. Even when GPS fails, the device can broadcast nearby Wi‑Fi identifiers, which can be triangulated to pinpoint the wearer’s position.

Q: Are all cheap GPS watches vulnerable?

A: While not every model has been tested, the research shows that devices built on the SETracker, NewGPS2012, or SinoTrack backends share common flaws, making many low‑cost watches susceptible.

Q: What should parents do before buying a tracking watch?

A: Look for products that use end‑to‑end encryption, require strong authentication, and have a transparent security update policy. Avoid brands that outsource to obscure Chinese platforms without clear documentation.

Q: Will future regulations improve the security of these gadgets?

A: Proposed legislation in the EU and several U.S. states aims to enforce security standards for IoT devices, but enforcement timelines are uncertain, and compliance will vary across manufacturers.

Conclusion

The episode with a $30 children’s smartwatch illustrates how a fragmented supply chain and lax security practices can turn everyday accessories into surveillance tools. As more connected devices enter homes and vehicles, the concentration of backend services will continue to amplify risk. Consumers, regulators, and manufacturers must push for stronger authentication, regular firmware updates, and independent security audits to prevent the next wave of covert tracking.

Try a related tool

Open the free tool →

This article was edited with AI assistance based on publicly available sources and reviewed before publishing.

#cybersecurity#IoT#smartwatch#GPS tracking#privacy#Artificial Intelligence#Technology#AI Tools#Digital Business#DangNH Studio

Comments

Login or register to comment
Guest can only read posts. Sign in to leave a comment.
PreviousKimi K3 AI Model Escapes Sandbox, Sparking Security Debate
10/08 429
Next ICE Added Nearly 1 Million DNA Profiles in 2025 – What It Means
10/08 708