The Plastic Trap: Why Your Kid's 'Safety' Watch is a Stalker's Dream

AI-generated image · US National Wire
Security researchers have exposed a catastrophic failure in the supply chain of GPS-enabled gadgets, proving that cheap hardware is often a gateway for remote surveillance.
I've always said that if you trust a spec sheet for a $30 piece of plastic, you're asking for trouble. As Wired first reported, the latest findings confirm my worst fears: these 'safety' gadgets aren't protecting children; they are essentially open invitations for anyone with a malicious mind.
In a recent test conducted by security researchers, a Wired reporter wore a lavender and pink child's smartwatch—sold by a company called CJC and manufactured by YiQingTeng Electronics in Shenzhen, China. The results were chilling. Vangelis Stykas, a Greek security researcher, was able to pinpoint the reporter's exact location in Brooklyn by monitoring Wi-Fi network identifiers, even while the watch's GPS was malfunctioning. Once the reporter reached the Wired Manhattan office, Stykas hijacked the device to silently snap photos of the reporter in an elevator and at his desk. He even used the microphone to eavesdrop on a conversation between coworkers, transmitting the audio to researcher Felipe Solferini.
Here is the terrifying part: the watch gave no indication that it was being hacked. No alerts, no flashing lights—just total, silent surveillance.
Opinion: This isn't just a fluke with one obscure brand. This is a systemic failure of a global supply chain. We are treating these devices as security tools when they are actually security liabilities.
According to Wired, Stykas and Solferini analyzed more than 70 GPS-enabled watches and car accessories for a presentation at the Black Hat cybersecurity conference. They discovered that tens of millions of these devices originate from just three primary supply chains. More than 30 devices utilize the technology and backend servers of YiQingTeng (also known as Wonlex), partner firm Shenzhen 3G Electronics, or the SETracker app. Another 30-plus brands rely on a Shenzhen-based platform called NewGPS2012. A third major platform, SinoTrack, also produces car trackers and smartwatches.
The researchers found significant security flaws across all three. In some instances, a total lack of authentication allowed anyone to access any device. This opens the door to a nightmare scenario: hackers can disable or spoof locations, intercept text and audio messages, replace emergency contacts with their own, and engage in silent audio and video capture. Stykas described the situation as "catastrophic," noting that these devices are "low-hanging fruit" for bad actors.
Even more concerning is the corporate response. Wired reports that when contacted, a representative for SETracker initially claimed the issues had been resolved long ago. It was only after Wired provided evidence of a successful hack occurring that week—and hours before the Black Hat presentation—that the researchers found their specific hacking techniques against SETracker had stopped working. However, they remain uncertain if the underlying flaws were actually fixed.
If you're buying a cheap tracker to keep your child safe, you aren't buying security; you're buying a beacon for whoever is listening.

