Wyze had been aware of several remote access vulnerabilities in its home security cameras for months and years without fixing them, despite Bitdefender warnings
Wyze knew hackers could remotely access your camera for three years and said nothing Ryan Whitwam / ExtremeTech : Wyze Left Security Cameras Open to Hacking for Three Years Corbin Davenport / XDA Developers : Wyze knew for years that hackers could remotely access its cameras, but didn't tell anyone Rob Rich / SlashGear : How Wyze Just Torpedoed Its Own Security Reputation Lucas Ropek / Gizmodo : You Should Probably Stop Using Your Wyze Camera Right Now BeauHD / Slashdot : Wyze Cam Security Flaw Gave Hackers Access To Video; Went Unfixed For Almost Three Years Jackson Chen / Input : It took Wyze years to fix galling flaws in their home security cameras Bitdefender Labs : Vulnerabilities Identified in Wyze Cam IoT Device Christopher Baugh / iPhone in Canada Blog : Wyze Cam V1 Security Flaw Still Gives Hackers Access to Saved Videos: Report Tim Sweezy / HotHardware.com News : Unpatched Wyze Security Camera Exploit Pathetically Left Millions Vulnerable To Spying For Years Jon Fingas / Engadget : Wyze was aware of a major camera security flaw for three years Techhive.com : Wyze needs to come clean about the Wyze Cam's security flaws Joe Rice-Jones / KnowTechie : Remember the $20 Wyze Cam? If you do, you should read this Stacey Higginbotham / Stacey on IoT : Podcast: Helium gets a new name and $200 million William Gallagher / AppleInsider : Wyze security flaw let hackers access videos — and a fix took years Ravie Lakshmanan / The Hacker News : Bugs in Wyze Cams Could Let Attackers Takeover Devices and Access Video Feeds Adamya Sharma / Android Authority : You might want to stop using your Wyze security camera right now! (Updated) Rob Thubron / TechSpot : Wyze knew about camera vulnerabilities that let strangers watch your feeds and recordings Jonathan Greig / The Record : Three vulnerabilities found in Wyze Cam devices allow for outside access Duncan Riley / SiliconANGLE : Vulnerabilities in Wyze cams exposed users to device takeover and video access Tweets: @hypervisible : The company knew of a vulnerability that would allow attackers to remotely access a camera's feed and said nothing for *3 years* https://www.theverge.com/... Jerry Gamblin / @jgamblin : I am glad they are not releasing a gun safe... oh... wait. https://twitter.com/... Mikah Sargent / @mikahsargent : I've recommended these cameras in the past. I use the newer versions outside my home and have, in the past, used them inside my home. Not any longer. https://twitter.com/... Craig Poulsen / @craigpoulsen : Things like this is why I have always told people on my channel that cameras should face out and not in. I know there are health and family needs that make indoor cameras very useful My lack of trust with cameras & reading things like this keeps them out https://www.theverge.com/... @followhomekit : The very reason why local control is the only way! Wtf https://twitter.com/... @iwillleavenow : The genuine actual terrifying hell. https://twitter.com/... Jennifer Pattison Tuohy / @jp2e : This lack of transparency is so damaging to the smart home industry as a whole. Bad things happen. Fess up and fix it. https://twitter.com/... @draglikepull : If you have any kind of “smart” devices in your house you should just generally assume that they can be hacked. As the aphorism goes, if it's smart, it's vulnerable. https://twitter.com/... @automateyoulife : So I'd never try to justify something like this. I think with margins and the money storyline with Wyze, we know why. Resourcing. The question in my mind: Is IoT too complex to manage for a startup in the world today? It's easy to say they have to do it all, but...here we are. https://twitter.com/... Vivek Wadhwa / @wadhwa : Companies such as this should face massive lawsuits and be bankrupted. https://twitter.com/... Emma Best / @natsecgeek : It's almost like... pervasive cameras and surveillance... is bad?? https://twitter.com/... https://twitter.com/... Adam Levin / @adam_k_levin : “If these flaws were bad enough to discontinue the camera in 2022, customers deserved to know that back in 2019.” https://www.theverge.com/... Will Oremus / @willoremus : Every person and institution considering surveillance as a security solution needs to understand that it is also every bit as much a security risk. https://twitter.com/... @bitdefender : New Bitdefender Labs research identified several vulnerabilities that let an outside attacker access the camera feed in this IoT Cam. https://www.bitdefender.com/ ... Chris Parker / @chrispcritters : A Wyze Cam internet camera vulnerability allows unauthenticated, remote access to videos and images stored on local memory cards and has remained unfixed for almost three years. https://www.bleepingcomputer.com/ ... @0xmatt : PSA: When you buy a $20 surveillance camera, it comes with a $20 security team. I have these cameras but not in any place I care about privacy. (I use them to watch birds' nests in my carport) https://twitter.com/... Ben Schoon / @nexusben : This is exactly the right take. A couple of years ago, something just had me feeling odd about Wyze, and I ended up replacing everything I had from them (except some outdoor cameras) around the time the latest Wyze Cam launched. I feel vindicated. https://twitter.com/... Tom Warren / @tomwarren : “Wyze knew hackers could remotely access your camera for three years and said nothing” 😲 https://twitter.com/...
Context & Ripple Effects
Wyze had already disclosed a 2019 server leak affecting customer account and camera-related data, making the company's handling of known camera-access flaws a more consequential trust issue rather than an isolated technical lapse.
Later reports of owners seeing unrecognized camera feeds and Wyze's disclosure that roughly 13,000 customers briefly saw others' feeds show that access isolation remained central to the company's camera-service reputation.
First-order effects
- Wyze customers were left using cameras with known remote-access weaknesses that Bitdefender Labs had identified, without the disclosure needed to judge their own exposure.
- Wyze faces an immediate credibility loss because the reported delay covered both remediation and customer notification for a product built around private video access.
Second-order effects
- Bitdefender's warnings gain weight as an external check on IoT vendors' vulnerability-response practices, increasing pressure on camera makers to show that reported flaws are patched and disclosed promptly.
- The incident makes access-control failures more salient for buyers evaluating Wyze against other camera vendors; the later large pool of unpatched Hikvision cameras shows delayed fixes were also an industry-wide security problem.
Third-order effects
- Connected-camera competition is likely to treat vulnerability response and transparent disclosure as part of the product's security boundary, not merely back-end support work.
- Repeated exposure and feed-access incidents point toward a home-security market where lasting trust depends on whether vendors can reliably separate users' video access and communicate failures when that separation breaks.
The trend: Consumer IoT security is shifting from a focus on device features to accountability for patching, disclosure, and the access controls protecting customer data.