Kids' Smartwatch Hijacked to Stalk WIRED Reporter
Original: Hackers Stalked Me by Hijacking a Smartwatch for Kids
Why This Matters
Shared backend vulnerabilities across 60+ GPS tracking brands expose millions of child and vehicle devices to stalking risks.
Security researchers Vangelis Stykas and Felipe Solferini demonstrated at Black Hat 2026 how they tracked, photographed, and eavesdropped on a WIRED reporter using a sub-$30 children's smartwatch. Vulnerabilities in its backend platform affect 30+ brands of GPS devices sharing the same infrastructure.
At the Black Hat cybersecurity conference, researchers Vangelis Stykas and Solferini presented findings from analyzing 70+ GPS-enabled watches and car accessories. Using a $30 children's smartwatch made by YiQingTeng Electronics (Shenzhen) and sold under the brand CJC, the researchers tracked a WIRED reporter's location via Wi-Fi network identifiers when GPS malfunctioned, silently captured photos from the watch's camera—including shots inside the WIRED New York office elevator and at his desk—and activated its microphone to eavesdrop on a colleague's conversation. The watch displayed no indication of compromise at any point. The researchers found that 30+ GPS device brands share YiQingTeng's backend (also known as Wonlex, Shenzhen 3G Electronics, or the SETracker app), and another 30+ car and child tracking brands run on a separate Shenzhen platform called NewGPS2012. A third major platform, SinoTrack, compounds the scope. The vulnerabilities stem from a deeply insecure GPS device supply chain, where multiple brands depend on shared, inadequately secured backend infrastructure, leaving potentially millions of devices exposed to similar stalking and surveillance attacks.