Millions of GPS Trackers, Including Kids' Smartwatches, Found Wide Open to Hacking
A new investigation has uncovered severe security vulnerabilities in dozens of brands of GPS-enabled smartwatches and car accessories, potentially exposing millions of users to location tracking, eavesdropping, and even vehicle manipulation. Researchers demonstrated the ease of exploitation by remotely hijacking a child's smartwatch to monitor a reporter's movements, capture photos, and record audio without any indication on the device.
A striking demonstration by security researchers has revealed critical security flaws in widely used GPS tracking devices, including children's smartwatches and car accessories. The vulnerabilities, which stem from insecure backend platforms, allow unauthorized access to sensitive user data and device functionalities.
**Vangelis Stykas**, a Greek security researcher, along with **Felipe Solferini**, orchestrated a live hacking demonstration using a child's smartwatch. A **WIRED** reporter wore the device, purchased for under $30 from an obscure company called **CJC**, which is built on the **YiQingTeng Electronics** platform from Shenzhen, China.
Stykas was able to track the reporter's location in real-time, even when the watch's GPS feature was malfunctioning, by collecting identifiers from nearby Wi-Fi networks. Upon the reporter's arrival at the **WIRED** office, Stykas remotely activated the watch's camera to take photos and then its microphone to capture audio, all without any visual or auditory cues from the device itself.



### Widespread Vulnerabilities Across Supply Chains
These revelations are part of a broader investigation that **Stykas** and **Solferini** are presenting at the **Black Hat** cybersecurity conference. Their research analyzed the security of over 70 GPS-enabled watches and car accessories, uncovering that tens of millions of these devices originate from just three primary supply chains, all based in Shenzhen.
More than 30 brands of geolocation devices utilize the technology and backend servers of **YiQingTeng**, also known by the brand **Wonlex**, or their associated app, **SETracker**. Another 30+ brands of trackers for cars and children operate on a platform called **NewGPS2012**. A third major platform, **SinoTrack**, which sells car trackers and smartwatches, also exhibited significant security flaws.
### Catastrophic Implications for Privacy and Safety
The researchers found that all three supply chains had critical security vulnerabilities, some as simple as a complete lack of authentication. This allowed them to:
* Track children's watches.
* Disable and spoof device locations.
* Intercept and spoof text and audio messages.
* Replace emergency contacts.
* Perform silent audio eavesdropping.
* Capture photos and videos from camera-enabled devices.
For some GPS-enabled car accessories, similar vulnerabilities could allow tracking, message spoofing, and potentially even unlocking or disabling vehicles, though these more extreme scenarios were not tested on live vehicles.
Furthermore, server-side vulnerabilities were identified, exposing consumer information and potentially allowing attackers to execute their own code on the servers. In one instance, evidence suggested that unauthorized access had already been gained to a system's backend.
"Millions of kids are being exposed and vulnerable to exploitation. It's just catastrophic. It's really low-hanging fruit for a lot of bad actors," **Stykas** warned. "Your criminal mind is the only limitation in exploiting those devices."
### Vendor Response and Ongoing Risks
**Stykas** and **Solferini** have been attempting to warn the companies behind these platforms for months. A representative for **SETracker** initially claimed the issues were resolved but later requested evidence of exploitation, which **WIRED** provided. Only hours before the Black Hat presentation did the researchers find their hacking techniques against **SETracker**'s platform had stopped working, though they remain unsure if all flaws are fully patched.
**SinoTrack** and the **NewGPS2012** platform did not respond to requests for comment, and the researchers indicated that their hacking methods against these systems still appear to be effective.
This incident underscores a decade-long concern among cybersecurity experts regarding the privacy and security risks posed by inexpensive, GPS-enabled smartwatches and aftermarket car trackers.