The smartwatch on your child’s wrist might be watching them back
The smartwatch on your child’s wrist might be watching them back
A new investigation by security researchers has demonstrated just how easily a cheap GPS smartwatch marketed for children can be turned into a stalking tool.
WIRED’s Andy Greenberg strapped on a lavender-and-pink child’s smartwatch – sold by an obscure brand called CJC for under $30, made by Shenzhen manufacturer YiQingTeng Electronics, and shipped to him via Amazon by security researcher Vangelis Stykas.
From the moment Greenberg left his Brooklyn apartment, Stykas was watching. The watch’s GPS was actually malfunctioning, but it made no difference: the device was quietly transmitting the identifiers of every nearby Wi-Fi network to a distant server, letting Stykas pinpoint the exact block Greenberg was walking down.
When Greenberg reached WIRED’s Manhattan office, Stykas silently triggered the watch’s camera, photographing him stepping into the lift and again at his desk. He then activated the microphone, piping live audio to fellow researcher Felipe Solferini, who listened in as a colleague described a weekend trip to an art exhibition.
At no point did the watch display any sign it was tracking, photographing, or listening. And all Stykas had needed to target the device was the email address it was registered to – nothing more.
The research behind the experiment – presented at the Black Hat security conference, matters more than the experiment itself. Stykas and Solferini had analysed the supply chains and security of more than 70 GPS-enabled watches and car accessories, and found that tens of millions of tracking devices trace back to just three Shenzhen-based platforms: YiQingTeng (also known as Wonlex, with its SETracker app), NewGPS2012, and SinoTrack. More than 30 smartwatch brands sit on the first platform alone, and 30-plus more on the second.
All three had significant security flaws – in some cases as basic as a complete absence of authentication, meaning anyone could send commands to any device.
Depending on the device this flaw opens the door to your child’s smartwatch tracking their location, disabling or spoofing it, intercepting and faking text and voice messages, silently eavesdropping, capturing photos and video, and even replacing a watch’s emergency contacts with numbers of a hacker’s choosing.
As the researchers put it, a parent in Sweden buying a “SafeKid” watch and a parent in Spain buying a “SaveFamily” watch are unknowingly sending their children’s location data to the same vulnerable backend on a cloud server in mainland China. The apparent choice between dozens of brands is an illusion; a single flaw in one backend exposes them all and consumers have no way of telling which backend their product uses.
None of this is new information. Stykas himself, with researcher Michael Gruhn, disclosed a sweeping collection of GPS-device vulnerabilities dubbed “Trackmageddon” back in 2018. Pen Test Partners and Norwegian authorities issued warnings about hackable children’s watches in 2017 and 2018; the BBC reported in 2018 that MiSafes child-tracking watches transmitted data with no encryption at all, allowing spoofed calls to a child that appeared to come from a parent; and a 2020 study at Münster University of Applied Sciences found serious vulnerabilities in five of the six children’s smartwatches it tested. Germany’s telecoms regulator went as far as banning children’s smartwatches with listening functions in 2017. But after nearly a decade of warnings when Stykas tested a newly purchased watch this year, his surveillance techniques worked as well as ever.
The researchers say they spent months warning all three platforms. One, SETracker, insisted the issues had been “resolved long before” – even as researchers were actively hacking a watch on its platform that same week – and only stopped being exploitable hours before the Black Hat talk. The other two platforms didn’t respond to WIRED at all, and the researchers say their techniques against them still work. “Millions of kids are being exposed and vulnerable to exploitation. It’s just catastrophic,” Stykas told WIRED.
The deeper lesson for parents is that surveillance is not the same as safety. A device that continuously broadcasts your child’s location and can be made to listen and watch on command is a surveillance device – and its safety value depends entirely on how secure it is. When security is lax (and on many of the cheapest devices it is). You’ve bought your child a tracking beacon that a stranger can commandeer with an email address.
So what should parents do? First, ask whether a young child needs a connected wearable at all; for many families, a simple watch will do.
If GPS tracking is genuinely right for your family, buy on security rather than price: choose established brands that publish a vulnerability disclosure policy, issue updates, and state how long the product will be supported – and treat ultra-cheap, unbranded devices from online marketplaces as unsafe by default.
In the UK, the Product Security and Telecommunications Infrastructure Act (2024) legally requires connectable products sold here to meet baseline security standards, but marketplace imports routinely slip through.
Whatever you buy, set it up with the minimum data – a nickname, no photo, no saved school address – use a strong unique password, and disable any remote-listening or camera feature you don’t genuinely need. If a device you own runs on SETracker, NewGPS2012 or SinoTrack, or is named above, stop using it now rather than waiting for a fix that history suggests may never come.
Schools have a role too. Wearables now walk through the gates on hundreds of small wrists, and a compromised device in a classroom is potentially a live microphone in that classroom. Connected wearables belong in school device policies; schools should be willing to ask parents to disable or remove devices with remote-listening functions and apply the same scrutiny to any tracking technology they procure themselves.
Schools can also help educate children and parents the underlying lesson that “smart” is not a synonym for “safe”, and that every camera, microphone and location chip strapped to a child is a safety promise someone else has to keep.