Dozens of GPS tracking brands marketed to parents and vehicle owners across more than 50 countries all funnel back to the same vulnerable server infrastructure in China, according to security researchers presenting at Black Hat USA 2026.
The shared weakness allows attackers to remotely hijack children's smartwatches and vehicles, the researchers found.
The findings were detailed in a briefing titled "Tracking the Trackers: How We Took Over 36 Million GPS Devices Protecting Children & Vehicles," delivered on Aug. 6, by Vangelis Stykas, chief technology officer at Kumio, and Felipe Solferini, principal AI security engineer at Kumio, according to the Black Hat USA 2026 session listing.
NTD News has sent messages seeking comment to representatives for Kumio but received no response prior to publication.
3 Platforms, 1 Supply Chain
The researchers examined SETracker, which spans roughly 10 million devices across 39 brands; SinoTrack, covering more than 6 million vehicles; and TKSTAR/Thinkrace, which accounts for more than 20 million devices. Though marketed as competing products, all three trace back to the same Shenzhen-based supply chain and contain matching architectural weaknesses.Using reverse engineering, protocol analysis, and backend exploitation, the team said it achieved full compromise of all three platforms, including remote code execution on devices and on server infrastructure, in some cases reaching the highest level of Windows system access.
Starting from nothing more than a free account with no device ownership, an attacker could silently switch on microphone wiretaps on children's smartwatches, trigger hidden video recording, track vehicle locations in real time, and issue remote commands such as unlocking car doors or cutting off fuel.
45 Vulnerabilities Disclosed
The team said it identified and responsibly disclosed 45 vulnerabilities, 19 of them rated critical and nine given the maximum possible severity score under the CVSS v3.1 scale, across more than 26 million devices in over 50 countries.The research also points to a larger structural problem in the white-label internet-of-things manufacturing model. Numerous consumer-facing brands, including Wonlex, SaveFamily, KidiWatch, and Garett, rely on shared backend systems such as myaqsh.com, meaning a single point of failure can compromise the entire market.
Manufacturers Unresponsive
Despite the researchers sending more than 30 emails to device manufacturers, none replied."I really wanted this to be a nice story and say that we fixed it, but we didn't. Nobody really knows where this will end up or what we are going to do from here," Stykas told PCMag. One unnamed device reseller did respond and claims to be assisting with the ongoing investigation, while the manufacturers themselves have not engaged, he said.
"They have broken every law that I know," Stykas said. He urged the audience to stop using the devices altogether: "If you have one of those devices for your kid. Burn it. Break it. I don't care. It is compromised," he said.
