Full Breakdown
Security Flaws Turn Kids’ Smartwatches Into Stalking Tools
8/8/2026, 3:57:06 AM
Core Findings from Security Researchers
Security researchers Vangelis Stykas and Felipe Solferini demonstrated that a low-cost GPS-enabled smartwatch marketed for child safety can be hijacked to monitor the wearer, capture photos, record audio, and spoof location data. Using a $30 device sold online, they showed that the watch’s GPS and Wi-Fi signals could be accessed without any visible warning, allowing continuous tracking even when the GPS signal was weak. The researchers also remotely activated the camera and microphone, proving that the device could be turned into a silent surveillance tool.
Supply-Chain Weaknesses Behind the Devices
The compromised watch runs on the SETracker platform built by Shenzhen-based YiQingTeng Electronics, a manufacturer also identified under the brand name Wonlex and partnered with Shenzhen 3G Electronics. Stykas and Solferini’s analysis of more than 70 GPS-enabled watches and car accessories revealed that over 30 of those devices rely on YiQingTeng’s backend, another 30-plus use a separate Shenzhen platform called NewGPS2012, and a third major platform, SinoTrack, powers additional car trackers and smartwatches. All three supply chains exhibit fundamental security flaws, including a lack of authentication that permits anyone to send commands to any connected device.
Scope of the Vulnerability
The researchers concluded that tens of millions of child-focused smartwatches and vehicle trackers are built on just these three supply chains. The insecure design enables attackers to track locations, intercept or replace messages, change emergency contacts, and capture audio or video without the user’s knowledge. Server-side weaknesses also expose consumer information and could allow code execution on the providers’ backend systems; in one instance the researchers observed evidence of prior unauthorized access.
Company Responses
One manufacturer reportedly patched several of the identified flaws shortly before the researchers presented their findings at the Black Hat conference. Other companies that use the same platforms have not publicly responded, leaving many devices on the market still vulnerable.
Implications for Parents and the Market
Because the same software underpins dozens of branded watches, a single security flaw can affect products sold under many names across different countries. Parents purchasing a seemingly distinct brand may unknowingly expose their child to the same tracking and eavesdropping risks. The findings highlight a broader issue with family-facing connected devices, where inadequate security can turn safety-oriented gadgets into tools for covert surveillance.
