Your child’s GPS watch tells everyone where they are

A watch on the wrist is supposed to buy peace of mind. Parents see where their child is on a map, and in an emergency the child presses a button. At the DEF CON 34 security conference on 8 August, Felipe Solferini and Vangelis Stykas demonstrated that the same watches can do the opposite. By their own account they took over millions of devices: read and spoof location, intercept text and voice messages, listen in silently, trigger the camera. Nothing of it showed on the watch.
The most interesting part is not the device count. It sits on a single slide of the talk.
Three servers, dozens of brand names
The two researchers did not take one device apart. They went after the platforms behind them, meaning the servers the watches report to and take their commands from. There are three, and all three come out of the same supply chain in Shenzhen: SETracker with roughly ten million children’s watches, SinoTrack with more than six million vehicle trackers, and TKSTAR, which depending on the source also goes by Thinkrace, with more than twenty million devices.
Behind SETracker, according to the slides, stands a company called YQT, also trading as 3G Electronics. The data sits on Alibaba Cloud in China. 46 apps, 39 brand names, more than twenty countries, aimed at children aged three to twelve.
One slide is headed "39 brands, one server" and names them: Wonlex, SaveFamily, KidiWatch, Garett Kids, Carneo Guard, Osmile, Kuus, Beafon and more. Next to it sits the hardest line of the talk. Moving from Wonlex to SaveFamily, the researchers write, is a sticker change.

The proof is in the Play Store
You can check this yourself, no special knowledge required. Every Android app carries a technical package name that shows up in the Play Store address bar. For the Garett watch it reads com.tgelec.garetts, for KidiWatch com.tgelec.kidiwatch.
And for Beafon it reads com.tgelec.beafon. Beafon is an Austrian vendor whose kids watch also sells on Amazon. Its own product page advertises a "bea-fon Watch App". In the Play Store that same app runs under the tag of the very platform that also serves the nameless budget watches, rated 2.9 out of 5 across 57 reviews.
For parents that means the badge on the shelf does not decide where a child’s location data ends up. And no listing tells you which app the watch needs, and therefore which server it hangs on. On Amazon Germany a search on 12 August returned 249 hits for kids smartwatches, most of them under invented names with no traceable maker.
Why the CE mark says nothing here
Every one of these watches carries a CE mark. The researchers point out that it covers the hardware, not the security of the server behind it. That is where it gets interesting. Since 1 August 2025, privacy by design has been a market access requirement under Article 3(3)(e) of the EU Radio Equipment Directive. A device where one key opens every device does not meet it. Not a single case is on record where a watch was pulled from the market on those grounds.
Germany bans something else, and has since 2017: kids watches with a listening function. The Federal Network Agency writes in its guidance, dated July 2024, that children’s watches with a listening function are prohibited telecommunications equipment under section 8(1) of the German Telecommunications Digital Services Data Protection Act. You spot the feature by terms such as "voice monitoring" or "baby monitor mode", or by the app asking for a monitor number. Location tracking itself the agency explicitly counts among the permitted functions.
The penalties are lopsided. Making such equipment or placing it on the market is a criminal offence carrying up to two years. Advertising the listening capability is a regulatory offence worth up to 10,000 euros. Mere possession and import are banned too, but carry no penalty of their own. In practice the agency works by ordering people to destroy the device.
What parents can do now
The first step costs nothing. Look up the name of the app that controls the watch, then find its package name in the Play Store. If it reads com.tgelec, or if the app is called SeTracker or SeTracker2, the watch sits on one of the platforms under scrutiny.
The second step is about the data already up there. Contact numbers, photos and voice messages live on the server, not on the watch. Retiring the device means deleting the account in the app, not just dropping the watch in a drawer.
What does not help is switching brands inside the same list. What also does not help is waiting. Wonlex published a blog post on 10 August describing three points as fixed, found during an "internal security audit". Researchers, Black Hat and DEF CON appear nowhere in that text. SinoTrack and Thinkrace, according to the researchers, did not respond at all.
Watches with their own backend do exist. Xplora, Anio and Vidimensio run their own servers. That is no free pass: at Xplora, TU Darmstadt showed in late December that a key pulled from a single watch opened every watch of the same type.
That leaves the numbers. The 36 million is an estimate by the researchers, not independently verified, and one of their own slides puts 26 million in the same place. The 45 reported vulnerabilities are filed, by their own account, and no list has been published. The one thing nobody has to estimate is the package name in the Play Store. It is right there.






