An ABC News investigation published September 22 finds ultra-cheap AI smart glasses sold in Australia can be HIJACKED over BLUETOOTH with no password, while the companion HeyCyan app website leaks owner EMAIL and date of birth from a DEVICE ID.
ABC News national technology reporter Ange Lavoipierre reports independent testing by NSB Cyber and Abstract Shield uncovered a suite of serious VULNERABILITIES across the glasses, the phone app, and the related website. Mixed News summarizes the same probe for an XR audience and stresses the findings cover the CHEAPEST end of the market — not Meta, Snap, or Xreal hardware.

Bluetooth Hijack With No Pairing Barrier
David Crees, who runs Abstract Shield and led the testing for the ABC, says another person with the same app can log into a stranger’s glasses because there is NO PASSWORD. When the glasses are switched on but the owner is not connected, an ATTACKER in Bluetooth range can RACE to connect first, then copy stored photos and videos, take new recordings, and INTERCEPT audio and images in transit. Crees compares that to AirPods or Samsung earbuds, where pairing a new phone requires holding a button on the device for several seconds. These glasses ask for NOTHING.

Crees spent six days on two pairs and found MORE THAN A DOZEN flaws. His blunt assessment, quoted by ABC: there was not a single thing the product stack had done correctly. He told the broadcaster a full fix would mean updating roughly 300 brands of glasses plus the app and website — and that the only REAL SOLUTION he sees is a RECALL.
Two Cheap Pairs, One Shared App Stack
The ABC tested a AU$60 pair from TEMU and a AU$110 pair from Sydney importer BDI Technology via Big W Marketplace. Comparable SKUs in a similar price range have also appeared through Dick Smith, Kmart, and Amazon. All of them appear to rely on the same companion app: HEYCYAN, developed by Shenzhen Qingcheng Future Technology Co in mainland China.

A separate failure on the app’s website turns the DEVICE ID — visible to others within Bluetooth range while the glasses remain unpaired — into a LOOKUP key for the owner’s email address and date of birth. That is OWNER DATA leakage layered on top of the hijack path, not a bystander-recording story alone.
AI Traffic Routes Through China
Beyond the hacking risk, the testing found Australian user data tied to the built-in AI companion often travels first to a SERVER in SHENZHEN. Depending on the function, the data may then move to another Chinese server or to the US, without users being explicitly told. HeyCyan’s privacy policy, per the ABC, specifically named Singapore — not China — drawing criticism from University of Sydney tech regulation specialist Kimberlee Weatherall, who said the Privacy Act expects the country to be identified when practical.

The ABC also reported the AI companion returned denials or redirects on topics the Chinese government treats as SENSITIVE, including Uyghur persecution and Tiananmen Square, leading researchers to conclude the chatbot relied at least in part on Chinese sovereign AI models. Evan Vougdis of NSB Cyber, who oversaw the research, said there is a high degree of UNCERTAINTY about where the data goes and whether it feeds further training or SURVEILLANCE. The testing did not definitively prove how the data is used.
Law, Retail Pullback, and What Was Not Proven
Weatherall told the ABC the security failures look like a CLEAR BREACH of the Privacy Act and likely run into Australian consumer law and the government’s newer cyber security act. Privacy commissioner Carly Kind pointed to extreme community BACKLASH against the category. BDI Technology told the ABC it is no longer selling smart glasses; the broadcaster understands at least one Australian retailer PAUSED supply amid the furore. The ABC said it contacted HeyCyan’s developer repeatedly and received NO REPLY. Some flaws appear to have been patched after findings were shared; MOST remain.

Mixed News is careful on scope: only those two devices were examined, neither carries a keynote brand, and nothing in the testing should be read across to Meta, Snap, or Xreal. Meta’s cheapest AI glasses start around $299 in the US — a different PRICE BRACKET from either pair tested. What the PROBE establishes is EXPOSURE at the bottom of the market, not a proven mass breach of stranger photos in the wild.
Sources: ABC News / Ange Lavoipierre (Sep 22, 2026); Mixed News / Michael Zelich (Sep 22, 2026).