HomeSecurityHackers Were Tracking a Child via a Kids' Smartwatch — What Parents Need to Know...

Hackers Tracked Child Through Kids' Smartwatch — What Parents Need to Know

Disturbing investigation: A WIRED journalist was targeted by hackers using a $30 pink plastic children's smartwatch . Security researchers Vangelis Stykas and Michele Solferini tracked his location, took photos without the watch giving any indication, and recorded audio from his surroundings — revealing a structural flaw in tens of millions of devices. The SecNews technical team breaks down what the researchers found, presenting their research at Black Hat 2026, and what parents need to know.

See also: iCloud Private Relay: A passkey request is enough to reveal the real IP

Children's smartwatch breached by hackers

Children's smartwatch: What hackers were able to do

The researchers managed, having access to this particular children's smartwatch, to perform a series of actions without any warning on the device:

  • Real-time location via built-in GPS
  • Silently take photos with the watch camera, without light or sound
  • Recording audio from the microphone and sending it to attackers
  • Location spoofing to make the parent see the wrong location
  • Reading and intercepting messages from parents to children and vice versa
  • Changing emergency contacts so the attacker can impersonate the parent

The watch never gave any indication that it was under control. These functions would be available to anyone who knew about the loophole — without physical access to the device.

The problem is structural, not isolated

The watch WIRED tested is based on the SETracker platform from Chinese company YiQingTeng (Wonlex). The researchers found that more than 30 brands of children's smartwatches rely on the same platform.

Combined with two other Chinese platforms (NewGPS2012 and SinoTrack), Stykas and Solferini estimated that tens of millions of GPS tracking devices — from children’s watches to car parts — came from just three supply chains. All three had serious security flaws, some as simple as a complete lack of authentication.

GPS tracking for children's smartwatch

How did companies react?

SETracker initially told WIRED that “the issues have been resolved for a long time.” But hours before the Black Hat presentation, the researchers found that their attack method suddenly stopped working — and it’s unclear whether the loophole was actually closed. NewGPS2012 did not respond to WIRED’s inquiries, and the attacks against it remain functional, according to the researchers.

Parent examines child's smartwatch

What can parents do today?

  • Avoid cheap no-name smartwatches from AliExpress, Temu or unknown Greek e-shops. If the price is under 40 euros, the chances are high that it runs on a vulnerable platform.
  • Prefer solutions with a clear baseline. The Apple Watch SE and Google/Fitbit Ace LTE have stricter security practices, with an explicit commitment to data minimization.
  • Check the backend. If the watch app is called SETracker, TinitLL, or has an unknown origin, consider the device unsafe.
  • Disable features you don't need: camera, microphone for eavesdropping, remote listening
  • Update the firmware as soon as an update is available — although many Chinese brands don't issue patches
  • Talk to the child: if they spot anything strange (pink light, sudden movement, messages that the parent did not send) to report it

See also: Meta Muse Spark: AI model hacked company in tests

See also: OpenAI is Preparing an AI Smart Speaker for $300-400 — What We Know

The Greek dimension

In the Greek market, cheap children's smartwatches are being sold en masse by Greek e-shops and marketplaces, often without a clear reference to the backend platform. The General Data Protection Regulation (GDPR) treats minors' data as a particularly sensitive category, with enhanced protection and the obligation of explicit parental consent. Any children's watch sold in the EU that exposes minors' data violates multiple articles of the Regulation.

The European Data Protection Authority has repeatedly highlighted the risks of children's IoT, while recent European Commission plans for the Cyber ​​Resilience Act would oblige manufacturers to provide security updates for the entire life cycle of the device. Until then, however, the responsibility falls on parents.

The incident is yet another episode in a decade of warnings about children's smartwatches. Stykas and Solferini's research stands out because it reveals that the problem is not one specific brand but the entire supply chain of 3 Chinese providers. The SecNews editorial team will monitor developments from the Cyber ​​Resilience Act, the Data Protection Authority and any new revelations. Sources: WIRED, Black Hat 2026, Data Protection Authority.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS