The reported kids smartwatch hack was not a movie-trailer cyberattack: researchers tracked the wearer of a tested GPS watch, remotely took photographs and listened through its microphone without an obvious warning on the device. The watch was sold by CJC, made by YiQingTeng Electronics and connected to the SETracker ecosystem. The demonstration took place before the research was scheduled for presentation at Black Hat.

That result applies to the tested watch—not automatically to every children’s smartwatch. But it exposes a less visible problem: a familiar product label may sit on top of a shared backend used by many other devices.

The Watch That Quietly Watched Back

Kids Smartwatch Hack Exposed a Hidden Risk

The tested watch initially had trouble with GPS. Researchers nevertheless tracked the wearer using nearby Wi-Fi network identifiers, then demonstrated location tracking once the GPS feature was functioning. They also remotely captured photographs and accessed microphone audio without an obvious visible indication on the watch.

So, can an attacker track a child through a smartwatch? A vulnerable device can expose the wearer’s location, as the reported demonstration showed. That does not mean every children’s watch can be tracked, and it does not establish that every model connected to the same ecosystem is exploitable.

The physical device was a low-cost GPS-enabled children’s smartwatch with a camera, microphone, messaging and location features. Its appearance matters here only as identification: the product photograph shows the pink-and-lavender watch involved in the reported demonstration, not the hack itself.

Why Different Brands May Share the Same Risk

The researchers analyzed more than 70 GPS-enabled watches and car accessories. They identified three major Shenzhen-based white-label supply chains: YiQingTeng/SETracker, NewGPS2012 and SinoTrack. In a white-label model, products can appear unrelated to shoppers while relying on the same software, servers or account infrastructure behind the scenes.

The researchers said those three supply chains were associated with tens of millions of GPS tracker gadgets. That is their estimate, not an independently audited device count. They also reported that more than 30 analyzed geolocation devices used YiQingTeng/SETracker technology, while more than 30 brands of car and child-tracking devices used NewGPS2012.

That scale is what turns a single cheap watch into a broader security story. A flaw in one backend can potentially affect many product labels at once. It still does not prove that every device using a given platform has the same vulnerability.

What the Researchers Reported Finding

The technical problems were not limited to one dramatic camera demonstration. They included missing authentication—the checks that should confirm whether a request comes from an authorized account—along with SQL injection, a technique that abuses unsafe database queries. Other reported weaknesses involved message spoofing, location manipulation and replacement of emergency contacts.

Platform or ecosystemAssociated device scope reported in the investigationReported technical weaknessReported consequence
YiQingTeng/SETrackerMore than 30 analyzed geolocation devices used the technologyMissing authentication that could allow commands to reach devicesReported access to location features, camera and microphone functions, plus message and emergency-contact manipulation
NewGPS2012More than 30 brands of car and child-tracking devicesSQL injection and the ability to run code on serversReported exposure of tracking infrastructure and device-related data
SinoTrackGPS platform associated with smartwatches and vehicle trackersSQL injection and abuse of demonstration accountsReported exposure of locations, passwords and vehicle records

These are reported research findings tied to the platforms and testing described above. They are not a claim that every branded product in those ecosystems can be remotely controlled.

The answer to the most alarming practical question is yes—but only within that boundary: the tested watch allowed researchers to listen through its microphone and take photographs remotely without an obvious warning. Earlier testing of MiSafes watches also found remote listening, location exposure and spoofed parental calls. The incidents show why a camera or microphone on a child’s wrist deserves the same security scrutiny as any connected device in the home.

A Platform Name Is Not Proof of a Vulnerable Watch

If a watch’s app says SETracker or NewGPS2012, should parents assume it has been hacked? No. Platform association is a risk indicator, not proof that an individual model is exploitable. The researchers and the investigation did not confirm every branded device linked to those systems.

SETracker said that it had blocked ports used by a legacy client version and that the vulnerability had been thoroughly remediated. That statement is the company’s response; it does not establish that every affected model, client version or backend service shares the same outcome. The reported demonstration and the company’s remediation statement therefore belong to different parts of the story: one describes an observed attack against a tested device, while the other describes SETracker’s claimed response.

Why This Is a Recurring Category Problem

The children’s GPS-watch category has faced serious security concerns before. In an earlier case involving the MiSafes Kid’s Watcher Plus, researchers reported access to children’s data and locations, remote listening and calls that could appear to come from a parent.

A 2020 study associated with Münster University of Applied Sciences tested six children’s smartwatches and found serious vulnerabilities in five. That result does not show that today’s products share identical flaws, but it does show that the risks are not limited to one isolated demonstration.

The recurring pattern is straightforward: these products combine sensitive data, remote-control features and a child’s physical location. When security is weak, the watch can become more than a tracker. It can become a path into conversations, messages, contacts and nearby surroundings.

What Parents Should Check Before Buying

There is no reliable shortcut from a colorful case or a familiar app name to a secure product. Before buying or continuing to use a children’s smartwatch, check four things:

  1. Look for an established manufacturer with documented security practices. A company with a mature security team and clear family-account protections is a better starting point than an anonymous device with vague support information.
  2. Check how accounts are protected. Two-factor authentication adds a second verification step beyond the password and should be enabled whenever the service offers it.
  3. Use a unique, complex password. Never reuse the password from email, social media or another family account. One exposed credential should not unlock several parts of your digital life.
  4. Treat the camera, microphone and location features as sensitive access. If the product does not clearly explain who can use those functions and how accounts are secured, that is a meaningful reason to pause.

Those steps cannot certify a particular model, and they do not turn platform association into proof of compromise. They do improve the odds that the device is backed by security practices proportionate to what it can reveal.

The bottom line is uncomfortable but useful: a children’s smartwatch is not just a tiny phone with a fun strap. In the reported demonstration, one vulnerable watch exposed location, camera and microphone functions. The hidden white-label infrastructure means the product name on the box may tell you less about security than the backend powering it.