ABC: Temu Smart Glasses Hijacked Over Bluetooth. HeyCyan App Leaks Email.

An ABC News investigation published September 22 finds ultra-cheap AI smart glasses sold in Australia can be HIJACKED over BLUETOOTH with no password, while the companion HeyCyan app website leaks owner EMAIL and date of birth from a DEVICE ID.

ABC News national technology reporter Ange Lavoipierre reports independent testing by NSB Cyber and Abstract Shield uncovered a suite of serious VULNERABILITIES across the glasses, the phone app, and the related website. Mixed News summarizes the same probe for an XR audience and stresses the findings cover the CHEAPEST end of the market — not Meta, Snap, or Xreal hardware.

Camera-equipped smart glasses form factor. Wikimedia Commons Google Glass Explorer Edition, illustrative only.
Camera-equipped smart glasses form factor for CONTEXT. Wikimedia Commons (Google Glass Explorer Edition) — illustrative only; not the Temu or BDI units ABC tested.

Bluetooth Hijack With No Pairing Barrier

David Crees, who runs Abstract Shield and led the testing for the ABC, says another person with the same app can log into a stranger’s glasses because there is NO PASSWORD. When the glasses are switched on but the owner is not connected, an ATTACKER in Bluetooth range can RACE to connect first, then copy stored photos and videos, take new recordings, and INTERCEPT audio and images in transit. Crees compares that to AirPods or Samsung earbuds, where pairing a new phone requires holding a button on the device for several seconds. These glasses ask for NOTHING.

Close view of camera-equipped smart glasses. Wikimedia Commons, illustrative of wearable cameras.
Wearable camera hardware makes stored MEDIA the prize once a pairing path exists. Wikimedia Commons, illustrative.

Crees spent six days on two pairs and found MORE THAN A DOZEN flaws. His blunt assessment, quoted by ABC: there was not a single thing the product stack had done correctly. He told the broadcaster a full fix would mean updating roughly 300 brands of glasses plus the app and website — and that the only REAL SOLUTION he sees is a RECALL.

Two Cheap Pairs, One Shared App Stack

The ABC tested a AU$60 pair from TEMU and a AU$110 pair from Sydney importer BDI Technology via Big W Marketplace. Comparable SKUs in a similar price range have also appeared through Dick Smith, Kmart, and Amazon. All of them appear to rely on the same companion app: HEYCYAN, developed by Shenzhen Qingcheng Future Technology Co in mainland China.

Everysight Raptor AR glasses. Wikimedia Commons CC BY-SA 4.0, illustrative hardware.
AR and smart glasses hardware varies widely by price bracket. Wikimedia Commons (Everysight Raptor) — not a HeyCyan SKU.

A separate failure on the app’s website turns the DEVICE ID — visible to others within Bluetooth range while the glasses remain unpaired — into a LOOKUP key for the owner’s email address and date of birth. That is OWNER DATA leakage layered on top of the hijack path, not a bystander-recording story alone.

AI Traffic Routes Through China

Beyond the hacking risk, the testing found Australian user data tied to the built-in AI companion often travels first to a SERVER in SHENZHEN. Depending on the function, the data may then move to another Chinese server or to the US, without users being explicitly told. HeyCyan’s privacy policy, per the ABC, specifically named Singapore — not China — drawing criticism from University of Sydney tech regulation specialist Kimberlee Weatherall, who said the Privacy Act expects the country to be identified when practical.

Ray-Ban Stories camera glasses form factor. Wikimedia Commons — not the Temu/HeyCyan units tested.
Camera glasses form factor for scale CONTEXT. Wikimedia Commons (Ray-Ban Stories) — Mixed News notes Meta and Snap SKUs were not in the ABC test set.

The ABC also reported the AI companion returned denials or redirects on topics the Chinese government treats as SENSITIVE, including Uyghur persecution and Tiananmen Square, leading researchers to conclude the chatbot relied at least in part on Chinese sovereign AI models. Evan Vougdis of NSB Cyber, who oversaw the research, said there is a high degree of UNCERTAINTY about where the data goes and whether it feeds further training or SURVEILLANCE. The testing did not definitively prove how the data is used.

Law, Retail Pullback, and What Was Not Proven

Weatherall told the ABC the security failures look like a CLEAR BREACH of the Privacy Act and likely run into Australian consumer law and the government’s newer cyber security act. Privacy commissioner Carly Kind pointed to extreme community BACKLASH against the category. BDI Technology told the ABC it is no longer selling smart glasses; the broadcaster understands at least one Australian retailer PAUSED supply amid the furore. The ABC said it contacted HeyCyan’s developer repeatedly and received NO REPLY. Some flaws appear to have been patched after findings were shared; MOST remain.

AR smart glasses hardware detail. Wikimedia Commons Everysight Raptor, illustrative.
Hardware detail for context. Wikimedia Commons — the ABC story is about ULTRA-CHEAP HeyCyan-powered SKUs, not flagship XR headsets.

Mixed News is careful on scope: only those two devices were examined, neither carries a keynote brand, and nothing in the testing should be read across to Meta, Snap, or Xreal. Meta’s cheapest AI glasses start around $299 in the US — a different PRICE BRACKET from either pair tested. What the PROBE establishes is EXPOSURE at the bottom of the market, not a proven mass breach of stranger photos in the wild.

Sources: ABC News / Ange Lavoipierre (Sep 22, 2026); Mixed News / Michael Zelich (Sep 22, 2026).

Leave a Comment