Camera Glasses That Run on the HeyCyan App Can Be Hijacked by Anyone Nearby

Camera Glasses That Run on the HeyCyan App Can Be Hijacked by Anyone Nearby

You paid under a hundred dollars for a pair of camera glasses from a marketplace, and the box told you to install an app called HeyCyan. On 22 September 2026, ABC News in Australia published tests showing that glasses paired through the HeyCyan app can be taken over by a stranger within Bluetooth range, with no password. Once connected, the attacker can take new photos and video, copy what is already stored and intercept media on its way to the owner’s phone. The researchers found more than a dozen flaws across the glasses, the app and its website, and most were still open after the developer’s first patches. If your glasses use HeyCyan, the brand printed on the frame does not change any of this.

Six days of testing

The tests were run for the ABC by two security firms, NSB Cyber and Abstract Shield, over six days. They bought two pairs: one for 60 Australian dollars from Temu, the other for 110 Australian dollars from a Sydney importer, BDI Technology, through Big W’s online marketplace. The ABC did not publish model names. Similar glasses sold by Dick Smith, Kmart and Amazon in Australia appear to use the same app.

The flaw that gives an attacker control is the pairing. When the glasses are switched on but not connected to the owner’s phone, anyone nearby with the same app can connect first. There is no password and no button to hold. David Crees, the lead researcher, compared it with earbuds, which make you hold a button for several seconds before a new phone can pair.

The other findings, as the ABC describes them:

  • Audio and images can be intercepted while they travel from the glasses to the phone.
  • An attacker’s device can pose as your glasses and connect to your app.
  • Unpaired glasses broadcast a device ID, and a separate flaw on the app’s website returns the owner’s email address and date of birth for that ID.

Where your voice and photos go

Everything spoken or typed to the built-in AI assistant, and any image sent to it, went first to a server in Shenzhen, according to the tests. Depending on the task, the data could then pass to another Chinese company’s server or to one in the US. The app’s privacy policy names Singapore and does not mention China, which Kimberlee Weatherall, a technology law specialist at the University of Sydney, told the ABC is hard to justify under Australia’s Privacy Act.

The assistant also gave censored answers. Asked about the persecution of Uyghurs in Xinjiang, it said there was “no credible evidence”, and it declined to discuss Tiananmen Square.

The store listing says no data is collected

This is where an owner checking for themselves would be misled. The HeyCyan listing on Google Play, published under the developer name Glasses Dev, carries a data safety section filled in by the developer. It says “No data collected” and “Data is encrypted in transit”. The only data it admits sharing is crash logs and diagnostics.

Set that against the findings above. Voice and images leave the phone for servers in China, and media moving between glasses and phone can be intercepted. The label describes an app the testers did not find. Google Play presents these sections as the developer’s own statements.

The listing also shows the reach. HeyCyan has more than 500,000 downloads, and its last update, dated 16 September 2026, says only “Fix bug”. The problem is not confined to Australia.

Diagram of the HeyCyan camera glasses setup showing where testers found weaknesses: unpaired Bluetooth pairing, the glasses-to-phone link, the app's website and AI requests routed to a server in Shenzhen

Why a patch is unlikely to fix it

The app’s developer is Shenzhen Qingcheng Future Technology Co, according to the ABC, which says the company did not reply to repeated requests. After the ABC shared its findings, the developers appeared to patch some flaws, but most remained open.

Crees estimates that about 300 brands of glasses rely on the same app. Fixing them would mean updating the firmware of all of them, plus the app and the website, which he put at about a year of work. “The only real solution that I see is a recall,” he told the ABC. BDI Technology says it no longer sells smart glasses, and the ABC understands at least one Australian retailer paused its supply.

Weatherall said the flaws likely breach Australian consumer law and the country’s new Cyber Security Act, in force since March, as well as the Privacy Act.

What to do if you own a pair

Start with the app. If your glasses asked you to install HeyCyan, you are in the tested group, whatever name is on the box.

The pairing flaw works while the glasses are on and not connected to your phone. Switch them off when they are not paired with you. Import photos and video to your phone and delete them from the glasses, since stored media is what an attacker can copy. Keep the app updated, knowing that updates so far have closed only part of the problem.

Treat the AI assistant as a service that sends what you say and show it to servers in China. Don’t show it documents, faces or anything you would not post publicly. If you have not bought yet, a pair on this app is hard to recommend at any price while the pairing flaw stays open. Our look at how the Dutch regulator treats smart glasses privacy covers the other side of the problem, the people you film.

Several questions are still open:

  • Which retail brands and models use HeyCyan. The 300 figure is the researcher’s estimate.
  • Whether the iPhone version of the app behaves the same way. The tests the ABC describes do not say.
  • Whether any fix has shipped since the report.
  • Whether a regulator in Australia or elsewhere will act.

← Back to the blog