READ. SCROLL. LISTEN.

Unbiased headlines. Facts, not spin.

Every story is an unbiased news briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Security Researchers Hijacked a $30 Kids Smartwatch to Track, Photograph, and Eavesdrop on a Reporter

Security Researchers Hijacked a $30 Kids Smartwatch to Track, Photograph, and Eavesdrop on a Reporter
Security researchers Vangelis Stykas and Felipe Solferini remotely hijacked a cheap Chinese-made children's smartwatch to track a WIRED reporter's location, snap covert photos, and record audio without any indication the device was compromised. The watch runs on a backend platform used by more than 30 other GPS wearable brands, meaning the vulnerability likely extends far beyond one product. This is a parental-safety product failing at the one job that matters: not exposing a child to strangers.

A $30 children's smartwatch bought on Amazon was turned into a live surveillance tool aimed at the very adult wearing it, according to WIRED. Security researcher Vangelis Stykas tracked reporter Andy Greenberg's location in real time, remotely triggered the watch's camera to photograph him getting into an elevator and sitting at his desk, and piped live microphone audio to a second researcher, Felipe Solferini, who listened to a coworker's conversation. The watch gave no indication it was doing any of this.

The device is sold under the brand CJC and manufactured by YiQingTeng Electronics, a company based in Shenzhen, China, according to WIRED. It's marketed as a way for parents to keep tabs on their kids. Instead, the reporter's real-time GPS malfunctioned but the watch kept broadcasting nearby Wi-Fi network identifiers to a remote server, which Stykas used to pinpoint Greenberg's location down to a specific Brooklyn block.

A platform problem, not a one-off gadget problem

The more alarming finding isn't the $30 watch itself. It's what's underneath it. Stykas and Solferini say the CJC watch runs on a backend platform, also tied to the brand name Wonlex, that powers more than 30 other GPS-enabled watches and car-tracking accessories, according to WIRED. The two researchers examined more than 70 GPS-enabled wearables and automotive devices total for a presentation scheduled for the Black Hat cybersecurity conference.

That means the vulnerability isn't confined to one obscure brand nobody's heard of. If the underlying platform is insecure, every device built on top of it inherits the same exposure, regardless of the label on the box. Parents shopping by brand name have no way to know which back-end infrastructure their child's watch is actually running on.

Why this happened

Cheap GPS wearables for kids are a commodity hardware category. Manufacturers in Shenzhen build the physical device and license or white-label a software platform to handle location tracking, camera access, and parent-app connectivity. That's a normal, cost-effective supply chain model. It's also one where security review often isn't the priority it should be when margins are this thin and the retail price is under $30.

Nobody buying a $30 smartwatch for their eight-year-old is expecting it to double as a covert listening device for a stranger with the right server access. But that's effectively what happened here, demonstrated live by researchers doing exactly what a malicious actor could do.

What's proven and what isn't

What's documented: Stykas and Solferini successfully tracked Greenberg's location, activated the watch's camera without any visible or audible alert, and streamed live microphone audio, all according to WIRED's own firsthand account of being the test subject. That's a demonstrated capability, not a theoretical vulnerability.

What's not yet established: how many of the 30-plus brands sharing this backend platform have the exact same exploitable flaws, whether any real children's watches have already been compromised by malicious actors rather than researchers, and whether YiQingTeng Electronics or the platform operators have issued any fix. WIRED's report doesn't indicate the company has responded publicly or that any patch has been deployed.

The regulatory gap

No recall has been announced. No U.S. or Chinese regulator has been named as investigating this specific platform, based on the available reporting. A device explicitly marketed for child safety, sold through a major U.S. retailer, running on infrastructure shared across dozens of brands, and there's no indication any government body has stepped in.

This isn't a case of "big tech bad" or "China bad" as a talking point. It's a straightforward consumer-safety failure. A product sold specifically to protect children turned a stranger's laptop into a window onto a person's daily commute, workplace, and desk. Whether that same access has been or could be pointed at an actual child, rather than a consenting journalist, is the question parents who own one of these watches should be asking their retailer right now.

The presentation from Stykas and Solferini at Black Hat is set to lay out the full list of affected device categories. Until platform operators confirm fixes, or until a regulator forces disclosure of which of the 30-plus brands share the vulnerable backend, parents have no reliable way to know if the watch on their kid's wrist is one of them.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
WiredHackers Stalked Me by Hijacking a Smartwatch for Kids