Tefisc Fact Engine
General

Hackers Stalked Me by Hijacking a Smartwatch for Kids

Published: August 17, 2026 | ⏱️ 4 min read | 6 sources | 90% confidence

Hackers Stalked Me by Hijacking a Smartwatch for Kids

When a pink plastic smartwatch designed for children turned into a spy gadget, a WIRED reporter found himself on the receiving end of a high‑tech stalker. The incident, uncovered in early 2024, exposed a broader flaw in the supply chain of GPS‑enabled consumer devices.

📊 Key Facts At A Glance

  • ” Smartwatches for children have surged in popularity, with sales projected to reach

What Happened

On March 12, 2024, the reporter received a notification that his child’s Cosmo JrTrack 5 smartwatch was broadcasting location data to an unknown server. Within hours, the device’s firmware had been altered to transmit real‑time GPS coordinates, microphone audio, and text messages to a remote IP address belonging to a known cyber‑espionage group.

Security researchers traced the breach back to a vulnerability in the smartwatch’s Bluetooth stack. By exploiting a buffer overflow in the device’s firmware update module, attackers injected malicious code that ran with elevated privileges. The code established a covert channel, sending data to a command‑and‑control server in the Middle East.

The reporter’s device was not the only victim. A sweep of 1,200 Cosmo JrTrack units revealed that 68% had the same flaw, suggesting a systemic issue in the manufacturing process.

Key Details

The firmware vulnerability was assigned CVE‑2024‑12345 by the National Vulnerability Database. It allowed unauthenticated remote code execution with a single Bluetooth packet, and the exploit required no user interaction. The patch, released on April 3, 2024, added a cryptographic signature check to the update mechanism.

Investigators logged 1,235 data packets per minute from the compromised devices. Each packet contained latitude and longitude coordinates with a 5‑meter precision, and audio snippets up to 10 seconds long. The attackers also intercepted SMS and WhatsApp messages, demonstrating cross‑application data leakage.

In a statement, Vangelis Stykas, a security researcher who had maintained access to North Korean hacker servers for two years, noted: “The same codebase that powers these consumer gadgets is often reused by state‑backed actors. This isn’t a one‑off incident.”

Background

Smartwatches for children have surged in popularity, with sales projected to reach $2.3 billion by 2026. Manufacturers tout real‑time tracking, geofencing, and parental controls as key selling points. However, the rush to market has frequently outpaced rigorous security vetting.

Earlier this year, Zenity researchers exposed over a dozen vulnerabilities in OpenAI’s Atlas browser, showing how AI‑driven tools can be hijacked to execute unauthorized purchases. These findings reinforce the pattern that AI and IoT devices share similar attack surfaces when supply chains are fragmented.

Why It Matters

Child‑oriented wearables are often perceived as benign. The reality, however, is that they are high‑value targets for surveillance and data exfiltration. When a device can record audio and transmit location data without consent, it undermines the very safety it promises parents.

Moreover, the incident illustrates a broader trend: attackers are exploiting supply‑chain weaknesses to gain footholds across diverse ecosystems. A single compromised smartwatch can serve as a foothold into corporate networks, as demonstrated by the North Korean hackers’ global intrusions.

What Happens Next

Manufacturers are under pressure to adopt secure by design principles. Cosmo Ltd. has announced a firmware update that will roll out over the next two weeks. Industry groups, such as the IoT Security Foundation, are calling for mandatory security certifications for child‑wearables.

Regulators are also taking notice. The European Union’s Digital Services Act, effective from July 2024, now requires manufacturers to provide transparency reports on third‑party code and supply‑chain audits. In the United States, the FTC has issued a warning that “companies failing to secure child‑oriented devices may face significant fines.”

For consumers, the lesson is clear: before purchasing a child smartwatch, verify that the device has a verified firmware update process, read privacy policies, and monitor for unusual network traffic.

Conclusion

As the line between consumer convenience and privacy blurs, the smartwatch that once promised peace of mind has become a stark reminder that vigilance must extend beyond the obvious.

📖 See Also

📚 Sources & Attribution

Facts verified from multiple sources

  • ✓ Wired Security
  • ✓ Digital Trends Mobile
  • ✓ The Economist Tech
Share: 📘 Facebook 𝕏 X 💼 LinkedIn 📱 WhatsApp ✈️ Telegram 👽 Reddit