Disturbing investigation: A WIRED journalist was targeted by hackers using a $30 pink plastic children's smartwatch . Security researchers Vangelis Stykas and Michele Solferini tracked his location, took photos without the watch giving any indication, and recorded audio from his surroundings — revealing a structural flaw in tens of millions of devices. The SecNews technical team breaks down what the researchers found, presenting their research at Black Hat 2026, and what parents need to know.
See also: iCloud Private Relay: A passkey request is enough to reveal the real IP

Children's smartwatch: What hackers were able to do
The researchers managed, having access to this particular children's smartwatch, to perform a series of actions without any warning on the device:
- Real-time location via built-in GPS
- Silently take photos with the watch camera, without light or sound
- Recording audio from the microphone and sending it to attackers
- Location spoofing to make the parent see the wrong location
- Reading and intercepting messages from parents to children and vice versa
- Changing emergency contacts so the attacker can impersonate the parent
The watch never gave any indication that it was under control. These functions would be available to anyone who knew about the loophole — without physical access to the device.
The problem is structural, not isolated
The watch WIRED tested is based on the SETracker platform from Chinese company YiQingTeng (Wonlex). The researchers found that more than 30 brands of children's smartwatches rely on the same platform.
Combined with two other Chinese platforms (NewGPS2012 and SinoTrack), Stykas and Solferini estimated that tens of millions of GPS tracking devices — from children’s watches to car parts — came from just three supply chains. All three had serious security flaws, some as simple as a complete lack of authentication.

How did companies react?
SETracker initially told WIRED that “the issues have been resolved for a long time.” But hours before the Black Hat presentation, the researchers found that their attack method suddenly stopped working — and it’s unclear whether the loophole was actually closed. NewGPS2012 did not respond to WIRED’s inquiries, and the attacks against it remain functional, according to the researchers.

What can parents do today?
- Avoid cheap no-name smartwatches from AliExpress, Temu or unknown Greek e-shops. If the price is under 40 euros, the chances are high that it runs on a vulnerable platform.
- Prefer solutions with a clear baseline. The Apple Watch SE and Google/Fitbit Ace LTE have stricter security practices, with an explicit commitment to data minimization.
- Check the backend. If the watch app is called SETracker, TinitLL, or has an unknown origin, consider the device unsafe.
- Disable features you don't need: camera, microphone for eavesdropping, remote listening
- Update the firmware as soon as an update is available — although many Chinese brands don't issue patches
- Talk to the child: if they spot anything strange (pink light, sudden movement, messages that the parent did not send) to report it
See also: Meta Muse Spark: AI model hacked company in tests
See also: OpenAI is Preparing an AI Smart Speaker for $300-400 — What We Know
The Greek dimension
In the Greek market, cheap children's smartwatches are being sold en masse by Greek e-shops and marketplaces, often without a clear reference to the backend platform. The General Data Protection Regulation (GDPR) treats minors' data as a particularly sensitive category, with enhanced protection and the obligation of explicit parental consent. Any children's watch sold in the EU that exposes minors' data violates multiple articles of the Regulation.
The European Data Protection Authority has repeatedly highlighted the risks of children's IoT, while recent European Commission plans for the Cyber Resilience Act would oblige manufacturers to provide security updates for the entire life cycle of the device. Until then, however, the responsibility falls on parents.
The incident is yet another episode in a decade of warnings about children's smartwatches. Stykas and Solferini's research stands out because it reveals that the problem is not one specific brand but the entire supply chain of 3 Chinese providers. The SecNews editorial team will monitor developments from the Cyber Resilience Act, the Data Protection Authority and any new revelations. Sources: WIRED, Black Hat 2026, Data Protection Authority.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
