Edited by humans. Written by AI. How our editing works
All articles

Kids' Smartwatches Have a Serious Security Problem

Security researchers tracked and eavesdropped on a journalist through a children's smartwatch. The flaws weren't sophisticated. The industry pattern is familiar.

Mike Sullivan

Written by AI. Mike Sullivan

August 8, 20266 min read
Share:
Kids' Smartwatches Have a Serious Security Problem

The watch was pink. It was plastic. It had a cartoon face on the packaging and GPS so a parent could see where their kid was after school. It also let security researchers track and eavesdrop on a WIRED reporter without her knowledge.

That's the lede of WIRED's recent investigation into children's smartwatches, and it lands the way it should — not because the attack was technically impressive, but because it wasn't. The flaws researchers found across three watches in that investigation included, in some cases, a simple lack of authentication that allowed anyone to access any device. No credential theft. No zero-day exploit. Just: there was no lock on the door, and no one bothered to put one there.

"Move Fast and Break Things" Has a Different Meaning When the Things Are Children

The security problems here are not exotic. CSO Online reports that the vulnerabilities identified across these devices include unauthorized access, remote audio surveillance, location spoofing, compromised SOS emergency functionality, and insecurely stored data. That's not a list of edge cases — that's a list of the things a children's safety device is specifically supposed to prevent.

A separate WIRED investigation into six brands found that researchers could abuse GPS features to track a target child's location in five out of six watches tested. Several watches had vulnerabilities severe enough to go well beyond tracking.

The discussion on Hacker News after the story broke surfaced a comment worth sitting with: "Is this what is meant by 'Shenzhen Speed'? Dump all safeguards and get any piece of crap out the door as soon as possible?" The commenter was careful to note the phenomenon isn't geographically exclusive — other parts of the world call the same approach "move fast and break things."

Both labels describe the same incentive structure. Speed to market is rewarded. Security costs time and money. The consumer who buys a $30 children's watch has no practical way to audit its backend API architecture before handing it to a seven-year-old.

The Supply Chain Nobody Secured

What makes this harder to fix than it looks: these devices don't exist in isolation. Behind each watch is a chain of hardware manufacturers, firmware providers, cloud platform operators, and app developers — often mixed across multiple vendors and jurisdictions. The GPS-enabled gadget a parent buys at a big-box store may be running firmware and a backend infrastructure that the retailer couldn't describe if you asked them.

Fixing "the watch" is actually a request to fix every link in that chain simultaneously. Some of those links are under no legal obligation to cooperate with each other, and some are under no legal obligation to cooperate with anyone. If the authentication flaw lives in a third-party cloud platform used by a dozen different watch brands across four countries, patching one brand's app doesn't close the hole.

Linuxsecurity.com notes that recent investigations have unveiled significant vulnerabilities across children's GPS-enabled watches. The breadth across brands — not just one bad actor — is what makes this a structural observation rather than an isolated product recall problem.

Industry Didn't Ignore the Warnings. It Filed Them.

This is not a new discovery wearing new clothes. It is a new discovery wearing the same clothes as last time.

The pattern across IoT devices goes back at least a decade: researchers find serious vulnerabilities, publish findings, generate headlines, prompt calls for regulation, and then watch the market absorb the story cycle without fundamentally changing its incentives. The next generation of devices arrives. Researchers test them. Findings are published.

What's different about children's watches is the specificity of the harm. A compromised smart thermostat is a property crime. A compromised child location tracker — one that can be remotely accessed, one whose SOS function can be hijacked, one that streams audio — is something else. The device was sold to families as a safety tool, and the security failure converts it into a surveillance tool for whoever finds the vulnerability first.

The Regulatory Lag That Isn't Getting Shorter

Governments have taken notice at various speeds. The FTC has faced pressure to investigate these devices, per CSO Online's reporting. Various jurisdictions have moved toward IoT security baseline requirements — some with more enforcement muscle than others.

The challenge regulators face is the same one researchers face: jurisdiction ends at borders, supply chains don't. A mandate requiring authentication on devices sold in one country creates pressure on manufacturers serving that market. It does not automatically pressure the backend platform operators who may be domiciled elsewhere.

The stronger regulatory argument isn't "ban the bad watches." It's "establish minimum security requirements as a condition of market access, and put liability somewhere in the chain that can actually feel it." Whether that happens — and how fast — is a separate question from whether it should.

The Parent Standing in the Store

Here's the practical position this research leaves consumers in: the devices marketed as tools for keeping children safe cannot, as a category, be trusted to meet that description.

That's not because every children's smartwatch is compromised right now. It's because the market as currently structured provides no reliable signal for which ones are. The $30 watch and the $80 watch both have cartoon packaging. Neither one comes with a security audit report. The parent in the store is making a purchase decision based on price, features, and brand recognition — none of which correlate meaningfully with the security posture of the backend infrastructure.

Security researchers can test six brands and publish findings. They can't test every brand, every firmware revision, every backend update. The WIRED investigation demonstrated what's possible when researchers have direct access and time. The market is larger than what any research team can continuously monitor.

If you hand a child a GPS device that streams location and audio to a cloud server, you are trusting that server's security posture — and the security posture of every vendor in the supply chain that built and maintains it. The WIRED investigation, the CSO Online reporting, and the six-brand test all suggest that trust has not been earned.

The device was sold as peace of mind. Whether it delivers that, or its opposite, depends on variables the buyer had no way to evaluate at the point of purchase.

That's the problem. The watches were just how it showed up this week.

More Like This

Black HDMI 2.1 cable with gold connectors against grid background, labeled "8K & 4K 120 FPS" in bold text with red oval…

Do You Really Need an $80 HDMI Cable? Maybe Not

Tech reviewer Adam tests a premium HDMI 2.1 cable. We examine what you're actually paying for and whether most users need it.

Mike Sullivan·7 months ago·6 min read
Anthropic Found a Secret Tracker in Claude Code

Anthropic Found a Secret Tracker in Claude Code

A hidden tracker in Claude Code was secretly monitoring Chinese users until a security researcher exposed it. Here's what happened and why it matters.

Zara Chen·2 months ago·6 min read
A man with long dark hair and a beard speaks on stage at a tech demo day, with "CopilotKit" branding visible and yellow…

When Agents Generate Their Own UI: The Three Flavors Explained

CopilotKit's Tyler Slaton maps the spectrum of generative UI—from pixel-perfect control to agents writing raw HTML. Each approach makes different tradeoffs.

Mike Sullivan·5 months ago·6 min read
Laptop displaying Unreal Engine 5.7 announcement with purple branding, surrounded by gaming figurines on wooden desk

Can Unreal Engine 5 Run on a $500 MacBook? Sort Of.

Testing Unreal Engine 5.7 on the MacBook Neo reveals what happens when professional software meets budget hardware—and why friction matters.

Mike Sullivan·5 months ago·5 min read
Starlink Dog Collars Track Pets From Space

Starlink Dog Collars Track Pets From Space

Fi's new Ultra collar uses Starlink to track dogs anywhere in the U.S. — and a rival AI-powered collar is right behind it. Here's what that really means.

Mei Zhang·2 months ago·7 min read
MacBook laptop displayed with Unreal Engine logo and Apple M4 chip branding on wooden desk setup

Unreal Engine 5 Still Doesn't Play Nice With Apple Silicon

While most 3D software runs smoothly on M-series Macs, Unreal Engine 5 remains frustratingly unreliable. One creator documents the disconnect.

Mike Sullivan·7 months ago·6 min read
TypeScript 7 Go Rewrite announcement with red cartoon mascot character and "10x faster" claim on dark background

TypeScript 7 Rewrites Its Compiler in Go for 10x Speed

TypeScript 7's RC rewrites the compiler in Go, delivering roughly 10x faster type checking. Here's what actually changed and what it means for your build.

Mike Sullivan·3 months ago·7 min read
Blue racing drone surrounded by components under red LED lighting with "NOT A TUTORIAL" text overlay

TBS Source One V6 FPV Build: Cheap Frame, Real Costs

FPV Geek builds the TBS Source One V6 freestyle quad and hits a power layout problem that forced a full rework. Here's what actually happened.

Mike Sullivan·3 months ago·7 min read