In short: At Black Hat USA 2026, security researchers Vangelis Stikas and Felipe Solferini demonstrated critical vulnerabilities in more than 60 brands of children's GPS watches. All of them run on one of three Chinese server platforms — SETracker, NewGPS2012 or SinoTrack — with near-zero authentication. Any attacker can track a child's real-time location, silently activate the camera and microphone, intercept messages, and tamper with emergency contacts. The watch shows no sign that any of this is happening.
What the researchers found
Cybersecurity researchers Vangelis Stikas and Felipe Solferini reviewed more than 70 GPS devices — children's watches and vehicle trackers — and presented their findings at Black Hat USA 2026, one of the world's leading cybersecurity conferences. They found that more than 60 brands rely on server infrastructure from three Chinese companies: SETracker (by YiQingTeng), NewGPS2012 and SinoTrack. SETracker alone powers over 30 of the tested brands, and the combined device count across all three platforms runs into the tens of millions. Our security news section regularly covers threats like these as they emerge.
The core problem is the near-total absence of authentication at the platform level. An attacker can send commands to almost any connected device without a password or any form of verification — no special hardware or advanced skills required. After the disclosure, SETracker announced patches on its side; NewGPS2012 and SinoTrack did not respond to inquiries.
Three platforms, tens of millions of devices
To understand the scale, it helps to know how this market works. Most inexpensive children's GPS watches (priced under $30–50) are not independent products — they are white-label hardware sharing one of a small number of server platforms, with different brand logos applied at the end. The entire architecture reduces to three platforms:
- SETracker (YiQingTeng) — the most widespread platform, powering more than 30 of the tested brands, managed via the SETracker or SeTracker2 app.
- NewGPS2012 — the second most common platform, used by dozens of additional brands.
- SinoTrack — primarily for vehicle trackers, but also found in some children's watches.
Because the vulnerability lives at the platform level, it affects every brand built on it at once — regardless of the price tag or the manufacturer's name on the box.
What an attacker can do
The weak authentication on these platforms enables a disturbing range of actions:
- Real-time location tracking — follow the child's route without the parents' knowledge.
- Silent photography — trigger the watch's camera with no on-screen indication.
- Covert audio surveillance — activate the microphone and listen to the child's surroundings.
- Message interception — read parent-child communications in the companion app.
- Emergency contact tampering — replace the numbers a child would call in an emergency.
A WIRED journalist experienced this first-hand at Black Hat 2026: researchers used his inexpensive GPS watch to track his movements, take camera photos and activate the microphone — the device gave no visible sign that any of this was happening.
Why this threat is especially serious
Children's GPS watches are marketed as safety devices — parents buy them precisely to always know where their child is. The unsettling paradox is that a device designed to protect a child can be turned into a tool to surveil them. The vulnerability is not in the watch's firmware but on the server platform, which means updating the watch will not fix the problem. The fix depends entirely on SETracker, NewGPS2012 and SinoTrack. After disclosure, SETracker announced patches; the situation with the other two platforms remains unclear.
How to reduce the risk today
While the patch situation develops, several steps can reduce your family's exposure:
- Identify your watch's platform. Check the companion app: if it is SETracker, SeTracker2, SinoTrack or a near-identical interface, the device likely runs on a vulnerable platform.
- Restrict app permissions. Where possible, limit the companion app's access to contacts and notifications on your phone.
- Watch for updates. Install firmware updates as soon as the manufacturer provides them. Platforms can push server-side fixes without a device update.
- Make a different choice next time. Watches from larger manufacturers with their own dedicated server infrastructure typically carry lower risk — research before the next purchase.
Protecting your family's data also means protecting the network that carries it. LiMP VPN encrypts your phone's traffic so data cannot be intercepted in transit — a separate but important layer of protection alongside safe device choices.
Sources
- Anti-Malware.ru — Children's Smart Watches Used as Spy Tools (August 7, 2026)
- Habr — Researchers Hacked Children's Smart Watches (August 9, 2026)
- WIRED — original investigation with live demonstration at Black Hat USA 2026, researchers Vangelis Stikas and Felipe Solferini
