Researchers found that millions of children's smartwatches and vehicle trackers share insecure backends, allowing hackers to monitor locations, eavesdrop, and capture photos.

Key facts
- •Researchers successfully hijacked a $30 smartwatch to track a reporter, record audio, and take photos remotely.
- •Three major Shenzhen-based platforms—SETracker, NewGPS2012, and SinoTrack—support millions of vulnerable GPS devices.
- •Security flaws include a lack of authentication and SQL injection vulnerabilities that allow unauthorized access to user data.
- •The researchers found evidence that some systems may have already been compromised by other unauthorized users.
- •Many brands use the same backend infrastructure, meaning a single vulnerability can impact dozens of different products.
Security researchers Vangelis Stykas and Felipe Solferini demonstrated that inexpensive GPS-enabled smartwatches for children contain critical security flaws. During a test, the researchers successfully tracked a reporter's location, intercepted audio, and captured photos from a watch without the wearer's knowledge. The findings, which are being presented at the Black Hat cybersecurity conference, highlight systemic vulnerabilities across three major supply chains based in Shenzhen, China.
By the numbers
Systemic Vulnerabilities in GPS Platforms
The researchers analyzed over 70 GPS-enabled devices and found that more than 30 use the technology and backend servers of YiQingTeng, also known as Wonlex or SETracker. Another 30-plus brands operate on a platform called NewGPS2012, while a third major platform, SinoTrack, also supports millions of devices. These platforms share significant security flaws, including a lack of authentication that allows unauthorized access to device data and functions.
Risks to Consumers and Privacy
These vulnerabilities allow hackers to track device locations, intercept messages, spoof audio, and replace emergency contacts. In some instances, researchers found they could execute code on backend servers or access consumer information. The researchers noted that the white-label model means a single vulnerability can affect dozens of different consumer brands simultaneously, often leaving parents unaware that their devices are connected to the same insecure backend.
Industry Response and Patching
Stykas and Solferini stated they have been warning the companies behind these platforms about the vulnerabilities for months. While some hacking techniques against the SETracker platform appeared to stop working shortly before the Black Hat presentation, the researchers remain uncertain if the flaws are fully resolved. SinoTrack and NewGPS2012 did not respond to requests for comment, and researchers report that their hacking techniques against those systems still appear to function.
Advertisement
This article was independently rewritten by ManyPress editorial AI from reporting originally published by Wired.

