US National WireUS NATIONAL WIRE
TechOpinion

The 'Good Enough' Security Disaster: How Cheap Kids' Watches Become Stalking Tools

Portrait of Jordan Wexler
Jordan Wexlerconsumer tech & gadgetsAug 9AI
The 'Good Enough' Security Disaster: How Cheap Kids' Watches Become Stalking Tools

AI-generated image · US National Wire

Security researchers demonstrate how a $30 smartwatch can be hijacked for silent surveillance, exposing a catastrophic failure in the global GPS gadget supply chain.

I've always said that a spec sheet is just a marketing document, but when it comes to security for children's wearables, 'good enough' is a dangerous gamble. A recent experiment detailed by Wired proves exactly why, as Wired first reported.

In a hands-on demonstration, security researchers Vangelis Stykas and Felipe Solferini targeted a lavender and pink plastic smartwatch sold by a company called CJC. Despite costing less than $30, the device became a comprehensive surveillance tool. Stykas was able to track a Wired reporter's exact location in Brooklyn by monitoring Wi-Fi network identifiers, even while the watch's GPS was malfunctioning. Once the reporter reached the office in Manhattan, the researchers hijacked the hardware to silently snap photos of the wearer in an elevator and at his desk. They further exploited the microphone to eavesdrop on office conversations—all without the watch providing any indication that it was being accessed.

**Opinion:** This isn't just a failure of one cheap brand; it's a systemic collapse of hardware integrity. When a device is designed to protect a child but instead provides a silent backdoor for strangers, the product is fundamentally broken.

According to Wired, this isn't an isolated incident involving one obscure manufacturer. Stykas and Solferini analyzed more than 70 GPS-enabled car accessories and watches for a presentation at the Black Hat cybersecurity conference. They discovered that tens of millions of these devices originate from just three Shenzhen-based supply chains.

Specifically, the researchers identified the following entities as central to these vulnerabilities:

* **YiQingTeng Electronics** (also known as **Wonlex**), which partners with **Shenzhen 3G Electronics** and utilizes the **SETracker** app. More than 30 devices use this backend. * **NewGPS2012**, another Shenzhen-based platform powering over 30 brands of trackers. * **SinoTrack**, a major provider of smartwatches and car trackers.

The researchers found significant security flaws across all three, including a total lack of authentication that could allow anyone to access any device. This opens the door to location spoofing, the interception of audio and text messages, and the ability for hackers to replace emergency contacts. In the case of car accessories, the researchers noted the potential to spoof messages that could unlock or disable vehicles.

Wired reports that the researchers have spent months warning these companies. When contacted, a representative for SETracker initially claimed the issues were resolved long ago. After Wired provided evidence of a successful hack occurring just days prior, the representative maintained the issues were fixed. Stykas and Solferini noted that while their specific hacking techniques against SETracker stopped working shortly before their Black Hat talk, they remain uncertain if the underlying flaws were actually patched.

Sources

More from Jordan Wexler