Thu 06 Aug 2026 / 20:08 ET
Kernel
Internet 3 min read

Kids smartwatch hacking demo exposes shared GPS platform risks

Researchers used a low-cost children’s watch to track, photograph and listen to a reporter, raising fresh questions about shared device backends.

Riley Okafor

By Riley Okafor / Senior AI Reporter

Kids smartwatch hacking demo exposes shared GPS platform risks
img: WIRED

Kids smartwatch hacking was demonstrated in a controlled test reported by WIRED: security researchers Vangelis Stykas and Felipe Solferini used a low-cost CJC children’s watch to follow a reporter, trigger its camera and capture audio without any visible indication on the device.

The demonstration is not evidence of a criminal stalking case. It does show what the researchers could do with the particular watch and the remote platform behind it, and it points to a larger white-label GPS-device business where different product brands may use the same underlying systems.

WIRED identified the tested device as a CJC watch made by YiQingTeng Electronics. When the watch’s GPS was not working properly, Stykas used identifiers it transmitted from nearby Wi-Fi networks to infer the reporter’s location. Later, the researchers remotely captured photographs as the reporter entered an elevator and sat at a desk, then accessed audio from the microphone.

How broad is the kids smartwatch hacking risk?

Stykas and Solferini told WIRED they examined more than 70 GPS-enabled watches and car accessories. They found more than 30 devices using technology and backend servers associated with YiQingTeng, Wonlex, Shenzhen 3G Electronics or the SETracker app. They also identified another 30-plus brands using a separate Shenzhen-based platform called NewGPS2012.

The researchers said those two ecosystems, together with SinoTrack, account for tens of millions of GPS tracker devices. That is their assessment, rather than an independently verified product list, and the reporting does not establish that every brand or device on those platforms remains vulnerable.

According to the researchers’ findings, flaws in the platforms could allow tracking, location disabling or spoofing, interception or alteration of text and audio messages, replacement of emergency contacts, silent audio capture, and photo or video capture on watches equipped with cameras. They also reported potential location tracking and message spoofing risks in some car accessories. They did not test whether those vehicle-related messages could unlock or disable real cars.

What did the platform operators say?

  • SETracker: A representative told WIRED the reported issues had been fixed. After WIRED provided evidence from the researchers’ test, Stykas and Solferini said their technique stopped working hours before their planned Black Hat presentation. They said they could not determine whether every flaw had been fixed.

  • NewGPS2012 and SinoTrack: WIRED reported that neither responded to its requests for comment. The researchers said their techniques still appeared to work against both platforms.

The reported test adds to separate 2026 research from KTH Royal Institute of Technology. KTH said student Gustaf Blomqvist found an internet-accessible insecure service on a different children’s smartwatch and was able to access its camera, microphone, speakers and messaging. That assessment did not identify the CJC watch or tie its findings to SETracker, NewGPS2012 or SinoTrack.

The important distinction is fairly mundane and easily lost in a pile of colorful watch straps: WIRED observed a working demonstration on one device, while the extent of exposure across the broader shared supply chains remains a claim by the researchers and not a confirmed inventory of affected products.

This story draws on original reporting from WIRED.

More Internet/

view all ↗