Hackers hijacked a kids' smartwatch to stalk a reporter before Black Hat talk
> cd .. / HUB_EDITORIALE
News

Hackers hijacked a kids' smartwatch to stalk a reporter before Black Hat talk

[2026-08-07] Author: Meteora Web Redazione
> share
Zenithby Meteora Web The operating system for your business. Social, clients, bookings and invoices in one platform. Gyms, barbers, professionals. Discover Zenith Free demo · no card

A WIRED reporter experienced firsthand just how insecure kids' smartwatches can be. During a security test, two researchers managed to track him, take photos of him, and even listen in on his conversations through a device that costs less than $30. All without any visible sign of intrusion on the wearable. This experiment, presented at the Black Hat conference, reveals systemic vulnerabilities affecting tens of millions of devices worldwide.

A silent attack starting in Brooklyn

Everything began when researcher Paul Stykas messaged the reporter to reveal his exact location. Stykas had been monitoring his movements through the watch's GPS, which, despite malfunctioning, transmitted identifiers of nearby Wi-Fi networks to a remote server. This allowed precise tracking along a Brooklyn street. Half an hour later, upon arrival at WIRED's Manhattan headquarters, Stykas exploited a feature to silently snap a photo from the watch's camera, capturing the moment the reporter stepped into an elevator. Shortly after, another shot showed him at his desk. Then, using the microphone, he enabled audio and a second researcher, Felipe Solferini, listened as a coworker described a weekend visit to an art exhibition. No visible indicator alerted the user that the device was under control.

Sponsored Protocol

An insecure supply chain

The device is sold by an obscure company called CJC and manufactured by YiQingTeng Electronics in Shenzhen, China. More troubling, the platform it relies on, named SETracker, is used by dozens of other brands. The researchers analyzed over 70 GPS-enabled devices and found that more than 30 of them share the same infrastructure by YiQingTeng, also known as Wonlex or Shenzhen 3G Electronics. Another 30-plus brands of car and kids' trackers run on the NewGPS2012 platform. Together with a third system, SinoTrack, these three supply chains feed tens of millions of devices.

Sponsored Protocol

Critical vulnerabilities and real risks

The security flaws discovered are extremely severe. In some cases, authentication is completely missing, allowing anyone to access any device. This means a malicious actor could track a child, disable location, intercept or alter messages, replace emergency contacts, eavesdrop on conversations, and even activate camera and microphone. For car devices, researchers found vulnerabilities that could potentially unlock or disable vehicles. Additionally, server-side issues exposed user data or allowed arbitrary code execution. Stykas emphasized the gravity: "Millions of kids are exposed and vulnerable to exploitation. It's catastrophic. It's really low-hanging fruit for a lot of bad actors."

Sponsored Protocol

The white-label problem

The diversity of brands on the market is illusory. Many seemingly different products share the same vulnerable backend. A parent buying a 'SafeKid' watch in Sweden and another buying a 'SaveFamily' watch in Spain are both sending their child's location data to the same myaqsh.com backend on Alibaba Cloud in mainland China. A single vulnerability in one backend affects dozens of consumer brands simultaneously, and consumers have no way to know which platform their product uses. This white-label model greatly amplifies the impact of any single flaw.

Company response and current status

The researchers have been warning the involved companies for months. A SETracker representative initially claimed that the issues had been resolved long before, but researchers demonstrated that hacking a device was still possible that same week. Only hours before the Black Hat presentation, their attacks against SETracker stopped working, but it remains unclear if all flaws have been fixed. SinoTrack and NewGPS2012 did not respond to requests for comment, and researchers say their attacks against these systems still work. They also found evidence of a previous compromise of NewGPS2012 systems.

Sponsored Protocol

This case highlights the need for greater awareness and regulation for IoT devices. Parents should check manufacturers' security policies before buying a smartwatch for their kids. For more on similar topics, see the article on AWS IoT Core vs Azure IoT Hub and Web3.js vs Ethers.js, which discuss security in emerging technologies. Additionally, for broader context on wearable vulnerabilities, you can consult Wikipedia.

Source: https://www.wired.com/story/hackers-stalked-me-by-hijacking-a-smartwatch-for-kids

> share
Meteora Web Redazione

> AUTHOR_EXTRACTED

Meteora Web Redazione

La redazione di Meteora Web Agency: ingegneri informatici e professionisti del digitale che pubblicano ogni giorno news e approfondimenti su tecnologia, software, marketing e innovazione.
[ Read Full Dossier ]

> METEORA_WEB // DIGITAL AGENCY

We build the digital presence your business deserves.

Websites, social media, online advertising, e-commerce and high-performance hosting, engineered with method by computer engineers in Sciacca, for all of Italy.

> MW_JOURNAL

> READ_ALL()