Hackers Stalked Me by Hijacking a Smartwatch for Kids

Staff
By Staff 6 Min Read

Here is a summary and humanization of the report, expanded to explore the broader implications of the findings.

The convenience of modern technology often blinds us to the silent risks hidden beneath the plastic casings of our everyday gadgets. A recent investigation presented at the Black Hat cybersecurity conference by researchers Stykas and Solferini has pulled back the curtain on a deeply unsettling reality: tens of millions of GPS-enabled smartwatches and car trackers, marketed largely as tools for parental peace of mind, are essentially wide-open backdoors for malicious actors. While we might expect cheap, $30 gadgets from obscure manufacturers to lack high-end encryption, the scope of this problem is not limited to a single bargain-bin brand. Instead, it stems from a centralized, alarmingly insecure supply chain. These devices aren’t just poorly made; they are built on a foundational architecture that treats privacy and security as an afterthought, if it considers them at all.

When you look at the industry, the names on the boxes—CJC, YiQingTeng, or any of the dozens of rebranding companies—are largely irrelevant. The real concern is the invisible platform powering them. The researchers discovered that more than 70 different devices, marketed for everything from tracking children to monitoring personal vehicles, all rely on a handful of massive, insecure backend platforms like Wonlex, SETracker, and NewGPS2012. By consolidating these massive user bases onto just three primary supply chains, the industry has inadvertently created a “single point of failure” for millions of people. If a hacker manages to compromise one of these central servers, they don’t just get access to a single watch; they gain the keys to a vast network of unsuspecting users, turning a supposed safety device into a potent tool for digital stalking and exploitation.

The vulnerabilities identified are, frankly, terrifying in their simplicity. In many instances, the researchers found a complete lack of authentication, meaning that anyone with basic technical knowledge could access a device without a password. Once inside, the potential for abuse is limited only by the imagination of the attacker. A hacker could track a child’s real-time location, disable or spoof GPS data, intercept private text and audio messages, or even change emergency contact information to their own. Beyond these intrusions, the devices could be manipulated to eavesdrop via the built-in microphone or, in the case of camera-equipped models, capture illicit photos and videos of the wearer. For car accessories, the risks are equally dire, with the potential for attackers to track vehicles or potentially send spoofed commands that could manipulate vehicle systems.

Perhaps the most alarming part of this situation is how easily accessible this sensitive information is. The researchers found server-side flaws that exposed personal consumer data, and in one instance, they even uncovered evidence suggesting that an unknown third party had already gained unauthorized access to the system’s backend. This isn’t a theoretical “what-if” scenario; it is a live, ongoing catastrophe where the tools we buy to protect our loved ones are actively compromising them. As Stykas aptly summarized, these devices represent “low-hanging fruit” for criminals. Because the systems are so poorly guarded, a malicious actor doesn’t need to be a nation-state-level hacker to exploit them—they just need the intent and a few minutes of time.

The response from the industry has been as frustrating as the hacks themselves. When faced with clear evidence of these vulnerabilities, companies have relied on a script of defensive deflection. Representatives for platforms like SETracker initially dismissed the findings, claiming that issues were “resolved long before,” despite the researchers demonstrating that their exploits were working just days earlier. It was only after immense public pressure and the looming spotlight of the Black Hat conference that some of these companies began to begrudgingly close the most egregious gaps. Others, like SinoTrack and the operators of the NewGPS2012 platform, have remained entirely silent, leaving millions of devices effectively exposed to the same threats that have existed for years.

Ultimately, this saga is a sobering reminder that we cannot outsource our safety to low-cost hardware without asking hard questions about where that data lives. For over a decade, cybersecurity experts have issued warnings about these products, yet the market continues to churn them out, obscured by a dizzying array of brand names that make it nearly impossible for an average consumer to tell the difference between a secure device and a digital liability. As we continue to integrate more “smart” technology into our lives, we must reckon with the fact that these devices are only as secure as the companies behind them—and right now, those companies are failing us. When it comes to the safety of our children and our personal security, the convenience of a $30 tracker is a price we simply cannot afford to pay.

Share This Article
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *