Millions of Children’s Smartwatches Are Exposed to Surveillance Due to Critical Security Flaws in Global Supply Chains
On a rainy morning in New York City, a seemingly harmless piece of consumer technology—a lavender and pink plastic smartwatch designed for children—served as a conduit for a sophisticated, real-time surveillance operation. While the device was intended to provide parents with peace of mind through GPS tracking and communication, it became a window into the wearer’s private life. A security researcher, Vangelis Stykas, was able to monitor a WIRED reporter’s movements from thousands of miles away, capture candid photographs without the user’s knowledge, and intercept private audio conversations. This demonstration was not a result of a highly targeted, bespoke cyberattack, but rather the exploitation of systemic, unpatched vulnerabilities inherent in the device’s underlying software platform.
The implications of this breach extend far beyond a single toy-like wearable. Stykas and fellow researcher Felipe Solferini have spent months auditing the supply chains of over 70 different GPS-enabled tracking devices, ranging from children’s watches to aftermarket automotive accessories. Their findings, set to be presented at the Black Hat cybersecurity conference, reveal a precarious reality: the illusion of product diversity in the consumer electronics market masks a highly consolidated, insecure infrastructure. Tens of millions of devices, branded under dozens of different names, share the same three primary backend platforms, all of which exhibit catastrophic security gaps.
The Anatomy of a Compromised Ecosystem
The watch used in the demonstration was manufactured by YiQingTeng Electronics in Shenzhen, China, and retailed by a company called CJC. It is a sub-$30 device that serves as a prime example of the "white-label" business model. In this model, a single original design manufacturer (ODM) creates the hardware and software platform, which is then licensed or sold to numerous resellers who apply their own branding, packaging, and marketing materials.

Because these companies rely on the same centralized backend servers—such as the SETracker platform—a vulnerability discovered in the core infrastructure creates a ripple effect, compromising the security of millions of users simultaneously. When Stykas monitored the reporter’s journey, he did not need to exploit the hardware directly. By leveraging authentication flaws in the SETracker backend, he gained the ability to send commands to the device as if he were the authorized parental account holder. This allowed him to pull real-time location data, remotely activate the microphone, and trigger the camera shutter, all while the device displayed no outward indication of unauthorized activity.
A Chronology of Vulnerability
The security risks associated with cheap GPS wearables are not a new phenomenon; they represent a recurring cycle of discovery, notification, and failure to remediate. The timeline of this issue spans nearly a decade:
- 2015–2016: Early warnings emerge regarding the insecurity of aftermarket automotive OBDII trackers, which could be exploited to track vehicle movement or potentially manipulate vehicle systems.
- 2017–2018: Major security disclosures, such as those from the Norwegian Consumer Council and the "Trackmageddon" findings by Stykas and Michael Gruhn, highlight that children’s smartwatches are frequently shipped with hardcoded passwords and unencrypted data transmissions.
- 2020: A study by researchers at the Münster University of Applied Sciences confirms that despite years of warnings, five out of six tested smartwatches remained fundamentally insecure.
- 2024–2025: Ongoing audits by Stykas and Solferini confirm that the same vulnerabilities persist in current-generation devices running on platforms like SETracker, NewGPS2012, and SinoTrack.
Despite these repeated public warnings, the manufacturers have largely failed to implement robust security updates. In the lead-up to their Black Hat presentation, the researchers contacted the companies behind these platforms. The responses were inconsistent at best. A representative for SETracker initially asserted that security issues had been resolved, yet when presented with evidence of an active, successful exploit conducted by the researchers just days prior, the company struggled to validate its claims, later appearing to patch the specific vector used while leaving broader systemic risks unaddressed.
The Illusion of Consumer Choice
The research underscores a critical lack of transparency in the global supply chain. A parent in Europe or North America might choose between several different brands, believing they are selecting a unique product with distinct security features. In reality, they are often selecting different labels for the exact same vulnerable backend architecture.

The researchers’ whitepaper notes that the myaqsh.com backend, utilized by YiQingTeng, manages data for a vast array of consumer brands. When a backend is compromised, the attacker does not need to identify the specific brand the consumer purchased; they simply need to target the server. This "one-to-many" vulnerability model turns the market’s reliance on third-party cloud services into a massive liability. In the case of the SinoTrack platform, researchers identified an account intended for testing purposes that possessed administrative-level permissions, which could have been used to send commands to any of the millions of connected devices. Furthermore, the discovery of SQL injection vulnerabilities—a classic, well-understood type of security flaw—on these platforms suggests a lack of even the most fundamental secure coding practices.
Broader Implications and Technical Risks
The scope of the exploitation is limited only by the attacker’s intent. For children’s watches, the risks are primarily privacy-focused: real-time tracking of a child’s location, the potential to alter emergency contact information to misdirect concerned parents, and the ability to eavesdrop on home or school environments.
However, for automotive trackers—devices designed to monitor the health and location of vehicles—the stakes shift toward physical safety. The researchers confirmed that these devices could be instructed to relay location data or, theoretically, spoof messages to vehicle systems. While they did not conduct on-road testing of the latter, the capability to send arbitrary commands to a device physically connected to a vehicle’s diagnostic port presents a significant security risk.
Furthermore, the discovery of evidence suggesting that third-party, unauthorized actors may have already accessed these backend systems is deeply concerning. If an unauthorized entity has already gained a foothold in these databases, the sensitive personal information of millions of families—including names, email addresses, and home locations—is likely already circulating on dark-web forums or is being utilized for targeted social engineering and phishing campaigns.

A Persistent Failure of Governance
The ongoing prevalence of these vulnerabilities raises difficult questions about the oversight of the Internet of Things (IoT) market. Regulatory bodies in various jurisdictions have attempted to mandate higher security standards for connected devices, but the speed of manufacturing and the complexity of global supply chains have made enforcement exceptionally difficult.
"Millions of kids are being exposed and vulnerable to exploitation," Stykas stated. "It’s just catastrophic. It’s really low-hanging fruit for a lot of bad actors."
The researchers maintain that their objective is not merely to demonstrate the insecurity of these specific devices, but to advocate for a fundamental shift in how IoT manufacturers prioritize security. Without mandatory security standards, transparency in supply chains, and the ability for consumers to easily verify the security provenance of the products they purchase, these vulnerabilities will likely remain a permanent feature of the low-cost electronics market.
As the industry moves toward an increasingly connected future, the case of the vulnerable smartwatch serves as a stark reminder. When security is treated as an afterthought in the design of consumer hardware, it is the most vulnerable members of society—children—who often bear the greatest cost. For now, the "smart" features that parents rely on to protect their families remain, in many cases, a significant point of failure that can be exploited with little more than a computer and a basic understanding of network protocols. Until manufacturers are held accountable for the security of their backend infrastructure, the burden of risk remains entirely with the consumer.
