Researchers hack a kids' GPS smartwatch to spy on a WIRED reporter

A WIRED reporter agreed to wear a children's GPS smartwatch bought on Amazon so that Greek security researcher Vangelis Stykas could demonstrate how easily it could be hijacked. Stykas tracked the reporter's location from the moment he left his apartment, using Wi-Fi network identifiers the watch kept transmitting even after its GPS malfunctioned. Half an hour later, once the reporter reached WIRED's Manhattan office, Stykas silently triggered the watch's camera to photograph him stepping into an elevator and again at his desk, then switched on its microphone; a second researcher, Felipe Solferini, listened in as a coworker described a weekend art exhibition. The watch gave no sign it was being controlled.
The device, sold under the obscure brand CJC for less than $30 and made by Shenzhen-based YiQingTeng Electronics, runs on the SETracker backend that Stykas and Solferini found powers more than 30 other watch and tracker brands. Ahead of a talk at the Black Hat security conference, the two researchers analyzed more than 70 GPS-enabled watches and car accessories and traced tens of millions of devices to just three Shenzhen supply chains: YiQingTeng (also sold as Wonlex, via partner firm Shenzhen 3G Electronics, or under the SETracker app name), NewGPS2012, and SinoTrack. All three had serious security flaws, in some cases nothing more than a missing authentication check that let anyone command any device on the platform. That exposed users to location tracking and spoofing, disabled or faked GPS, intercepted or forged text and audio messages, hijacked emergency contacts, silent audio eavesdropping, and camera or video capture on capable devices. For GPS-enabled car accessories running the same platforms, the researchers say they could similarly track vehicles or spoof messages that could potentially unlock or disable them, though they did not test this on an actual car.
On SinoTrack, the researchers found a demo account that could send commands to any of the platform's millions of devices, plus a SQL injection bug that exposed the locations, passwords and vehicle records of tens of thousands of devices. On NewGPS2012, a similar SQL injection flaw let them run their own code on the company's servers, and they found signs that someone else had already breached the backend without authorization. Stykas and Solferini are withholding full technical details of all three flaws because, they say, not all of them are fixed even after months of warning the companies. A SETracker representative twice told WIRED by email that the issues "have been resolved long before" and that the company "attaches great importance to the security of Setracker"; only hours before the Black Hat talk did the researchers find their SETracker exploit had stopped working, though they remain unsure whether the underlying flaws are fully patched. SinoTrack and NewGPS2012 did not respond to WIRED's requests for comment, and the researchers say their techniques against those platforms still work.
The researchers' core point is that the apparent variety of GPS-tracker brands is largely an illusion: as they write in a whitepaper shared with WIRED, a parent in Sweden buying a 'SafeKid' watch and a parent in Spain buying a 'SaveFamily' watch are both sending their child's location to the same vulnerable myaqsh.com backend on Alibaba Cloud, without knowing it, because the white-label model means one backend vulnerability hits dozens of consumer brands at once and buyers have no way to tell which backend their product uses. The problem is not new: Stykas and researcher Michael Gruhn documented a similar set of GPS-tracker flaws, dubbed Trackmageddon, back in 2018; Pen Test Partners and the Norwegian government issued their own warnings in 2017 and 2018; and a 2020 study by Germany's Münster University of Applied Sciences found serious vulnerabilities in five of six children's smartwatches it tested.
Key facts
- Researchers Vangelis Stykas and Felipe Solferini remotely tracked, photographed and eavesdropped on a WIRED reporter through a sub-$30 children's smartwatch, with no indication on the device that it was compromised.
- Analyzing more than 70 GPS-enabled watches and car accessories, they traced tens of millions of devices to three Shenzhen backend platforms: YiQingTeng/SETracker (30-plus brands), NewGPS2012 (30-plus brands) and SinoTrack.
- Flaws ranged from missing authentication on SETracker to a SQL injection on SinoTrack exposing locations, passwords and vehicle records for tens of thousands of devices, to a similar injection and signs of prior unauthorized access on NewGPS2012.
- A SETracker representative claimed the reported issues were already fixed, but the researchers' exploit against it only stopped working hours before their Black Hat talk, and they are not certain the flaws are fully patched; SinoTrack and NewGPS2012 did not respond, and their exploits still work.
- The findings echo warnings stretching back to 2017 to 2020, including the researchers' own 2018 Trackmageddon research and a Münster University study that found serious flaws in five of six children's smartwatches tested.
Why it matters
This is not one buggy gadget but a demonstration that the apparent diversity of GPS-tracker brands is largely cosmetic: dozens of brands sold under different names in different countries all route through one of three vulnerable Shenzhen backends, so a single flaw in one backend compromises every brand built on it at once, and buyers have no way to know which backend their product uses.
Who it affects
Parents and children using any of the 60-plus branded watches identified as running on the YiQingTeng/SETracker or NewGPS2012 platforms, drivers using GPS car accessories on the same or the SinoTrack platform, and more broadly the tens of millions of device owners the researchers trace to these three supply chains, since the researchers could not individually confirm every branded product's vulnerability.
How to use it
There is no user-side fix here: the vulnerabilities live in the vendors' backend servers, not in something an owner can patch. SETracker's exploit stopped working for the researchers only hours before their Black Hat talk and its fix status is unconfirmed; SinoTrack and NewGPS2012 have not responded to WIRED and their exploits still work as of publication, so devices on those platforms should be treated as currently exploitable.
How solid is it
The claims come from named, credentialed security researchers who ran the exploit live against a device WIRED itself wore and shipped for testing, and who are presenting the full supply-chain analysis at Black Hat; they withheld full technical detail on the remaining unfixed flaws specifically because disclosure to the vendors did not resolve them.
Risks and caveats
The researchers did not verify every individually branded device that appears to run on the SETracker or NewGPS2012 platforms, and WIRED could not independently confirm each one either, so brand-level exposure is inferred from shared backend infrastructure rather than device-by-device testing. The researchers also did not test whether the car-accessory flaws could actually unlock or disable a real vehicle, and the article does not establish how many real devices or children, beyond the demonstration itself, have been exploited by unauthorized parties.
“Millions of kids are being exposed and vulnerable to exploitation. It's just catastrophic. It's really low-hanging fruit for a lot of bad actors.”
— Vangelis Stykas, security researcher