On a rainy Manhattan morning, a WIRED reporter began his daily commute with a lavender and pink plastic child’s smartwatch strapped to his wrist. To the casual observer, it was a piece of innocuous wearable tech designed to offer parents peace of mind. To Vangelis Stykas, a Greek security researcher sitting thousands of miles away, it was a wide-open surveillance window.
As the reporter navigated the Brooklyn streets toward the subway, he sent a quick text to Stykas, warning that he might lose signal underground. The reply was chilling in its simplicity: “I know.”
Stykas had been tracking the reporter’s every movement since he stepped out his front door. Despite a malfunctioning GPS module, the device was transmitting unique identifiers from every nearby Wi-Fi network to a remote server, allowing the researcher to triangulate the reporter’s location with terrifying precision. By the time the reporter reached the WIRED offices in Manhattan, Stykas had remotely activated the watch’s camera to snap photos of him entering the elevator and sitting at his desk. He then triggered the microphone, allowing a colleague to listen in as the reporter discussed his weekend plans. Throughout the entire ordeal, the watch remained silent, providing no visual or audible notification that it was compromised.
The Anatomy of a Digital Breach: A Chronology of Access
The demonstration was not a one-off anomaly but a calculated exposure of a massive, systemic failure in the Internet of Things (IoT) supply chain. The device in question, a sub-$30 gadget manufactured by the obscure Shenzhen-based firm YiQingTeng Electronics, is part of a vast, interconnected ecosystem of insecure hardware.

The chronology of the hack followed a predictable, yet alarming, path:
- 08:00 AM: The reporter leaves his apartment. Stykas monitors his real-time location via Wi-Fi triangulation, bypassing the device’s faulty GPS entirely.
- 08:30 AM: Upon arrival at the office, Stykas exploits a backend vulnerability to send silent commands to the watch.
- 08:32 AM: The watch’s camera is triggered remotely, capturing a high-resolution image of the reporter in the office elevator.
- 08:40 AM: The device’s microphone is activated, streaming ambient audio directly to researcher Felipe Solferini, who confirms the interception by listening to a conversation about an art exhibition.
- 09:00 AM: The researchers confirm that no logs, alerts, or system notifications have been triggered, proving the device is a "black box" that operates entirely at the whim of anyone with access to the backend.
The Illusion of Consumer Choice
The most harrowing takeaway from Stykas and Solferini’s research is that the diverse "choice" consumers believe they have in the marketplace is a complete illusion. A parent in Sweden purchasing a "SafeKid" branded watch and a parent in Spain buying a "SaveFamily" device are, in practice, funneling the same sensitive location data into the exact same vulnerable backend, myaqsh.com, hosted on Alibaba Cloud.
This "white-label" business model means that a single, critical vulnerability in a central server can compromise tens of millions of devices simultaneously across dozens of different brands. Consumers have no way of knowing which backend their device uses, nor do they have a way to demand security patches from the manufacturers, who often operate as anonymous shell entities.
Supporting Data: A Landscape of Vulnerability
At the Black Hat cybersecurity conference, Stykas and Solferini presented findings from a year-long investigation into the supply chains of over 70 GPS-enabled devices, including watches for children and tracking accessories for vehicles. Their data revealed a deeply fractured but interconnected network:

- The YiQingTeng Ecosystem: Used by the "Wonlex" brand and the SETracker app, this platform services over 30 distinct brands of geolocation devices.
- The NewGPS2012 Network: This platform manages another 30-plus brands of trackers for both children and vehicles.
- SinoTrack: A major player in the automotive tracking market, this platform provides the backbone for millions of vehicles worldwide.
The researchers found that all three supply chains suffered from "catastrophic" security flaws. In several instances, the "authentication" process was non-existent. An attacker could send commands to any device simply by knowing its unique ID—a string of numbers often easily guessed or derived from the parent’s registration email. Once inside, an attacker could spoof location data, intercept text messages, replace emergency contact numbers with their own, or engage in persistent, silent audio and visual surveillance.
For automotive trackers, the risks shift from privacy to physical safety. While the researchers stopped short of testing these on public roads, they noted that the ability to spoof messages could theoretically allow an attacker to send "kill" commands to vehicles, potentially disabling engines or manipulating electronic systems.
Official Responses and Corporate Apathy
The researchers have spent months attempting to engage with the companies behind these platforms, but the results have been largely discouraging.
When WIRED contacted representatives for SETracker, the initial response was a blanket denial. A spokesperson claimed, "The issues you mentioned have been resolved long before," and insisted that the company "attaches great importance to the security of SETracker." However, when presented with the evidence of the WIRED reporter’s hack—conducted just days prior—the company’s narrative shifted, eventually leading to a partial patching of the vulnerability hours before the Black Hat presentation.

Other major players, including SinoTrack and the operators of the NewGPS2012 platform, ignored multiple requests for comment. As of the time of the conference, the researchers confirmed that their exploit techniques for these two platforms remained fully functional.
The Broader Implications: A Decade of Warnings
This is not the first time the security community has sounded the alarm. The "Trackmageddon" vulnerabilities of 2018 exposed similar rot in GPS-tracking services, and warnings from the Norwegian government and academic institutions have been circulating since 2017. Yet, the market for cheap, insecure, internet-connected tracking devices continues to grow unabated.
The primary issue is the race to the bottom in manufacturing costs. By prioritizing low-cost components and off-the-shelf, insecure software, these companies have turned millions of children into "low-hanging fruit" for bad actors. As Stykas noted during his presentation, "Your criminal mind is the only limitation in exploiting those devices."
The Regulatory Gap
The persistence of these vulnerabilities highlights a glaring gap in global consumer protection. While smartphones and laptops are subject to rigorous security standards and constant software updates, these low-cost IoT devices exist in a regulatory vacuum. Because they are often sold through third-party marketplaces and white-labeled under dozens of transient brand names, holding a single manufacturer accountable is nearly impossible.

The researchers argue that the burden of security should not rest on the consumer, who currently has no way to verify the safety of a product before purchase. Instead, they suggest that the liability must be shifted to the backend providers and the cloud infrastructure companies that host them.
Conclusion: A Catastrophic Reality
As the WIRED investigation and the Black Hat findings make clear, the convenience of real-time location tracking comes at a hidden, and potentially devastating, cost. For millions of families, the device meant to keep their children safe has become a permanent, silent spy.
"I really hoped we could tell a nice story that there were vulnerabilities and they fixed them," Stykas said. "But in many cases, they didn’t. It’s a position I really didn’t want to be in."
For parents currently using these devices, the takeaway is stark: if a product seems too inexpensive to be secure, it likely is. Until the industry is forced to adopt basic encryption and authentication standards, the "illusion of safety" provided by these gadgets remains, for many, a dangerous gamble with their family’s privacy and physical security.
