Closeness Lab

Can Sex Toys Be Hacked? Every Case We Could Document

In January 2021 an attacker locked several people out of a chastity device and asked for bitcoin to release it. One of them, who gave his name as Robert, said the demand was 0.02 bitcoin, worth about $750 at the time, and that the cage was definitely locked and he could not get into it. He had not been wearing it when the message arrived. Another said the practical effect was that he was no longer the owner of the device. The message quoted in that report claimed ownership of the body part inside the lock (Franceschi-Bicchierai, Motherboard, 11 Jan 2021).

Research-based, not hands-on (how we review) · This page carries no affiliate links, and nothing below was shown to any manufacturer before publication · Lovense appears in three of the cases below and We-Vibe in one; we may earn a commission on Lovense products through our app-controlled vibrator guide, and the full list of programmes we are in is on our disclosure page

Quick take: the question has a factual answer and it is not the one either side of the argument gives. Ten incidents involving connected sex toys are documented in the public record between 2016 and 2026, and they are listed below with the disclosure or filing each one comes from. All but one were databases, accounts, video feeds, research demonstrations, or in one case a stray audio file left on the owner’s own phone. Exactly one was a stranger taking control of devices belonging to people who had not agreed to it. In the public record we assembled, that has happened once, to a chastity lock, five years ago.

The record, 2016 to 2026

Each row between 2016 and 2026 is an event with a date and a primary source: the researcher’s own disclosure, the court reporting, or the outlet that verified the finding. Where a company responded on the record, its response is in the notes rather than the summary, because a denial is evidence of a position rather than of a fact.

DateDevice or companyWhat was actually reachedPrimary source
Sep 2016 – Mar 2017We-Vibe (Standard Innovation)App records of vibration settings and use times, linked to registered email addresses. Settled for $3.75 million without admitting wrongdoing.Guardian, 14 Sep 2016 · NPR, 14 Mar 2017
Apr 2017Svakom Siime EyeThe live video feed. The device is its own Wi-Fi access point with a default password of 88888888; researchers also found code injection in its web interface and hidden functionality to email images and write video to a network share.Pen Test Partners, 3 Apr 2017
Sep 2017Lovense HushThe device itself, over Bluetooth, within radio range. Researchers captured the app’s commands and replayed them from a laptop with no app involved, then went looking for devices in public.Pen Test Partners, 29 Sep 2017
Nov 2017Lovense Remote (Android)A six-minute audio file left in the app’s local folder on the user’s own phone. The company called it a minor bug affecting Android, said nothing reached its servers, and shipped a fix.The Verge, 10 Nov 2017
Feb 2018Vibratissimo Panty Buster (Amor Gummiwaren)The customer database, including images, chat logs, stated sexual orientation and passwords in clear text; also the devices themselves over Bluetooth, and a remote-control link whose ID was a counter an attacker could count backwards from.SEC Consult, 1 Feb 2018
Oct 2020Qiui CellmateThe lock. Researchers found remote attackers could stop the device opening, with no physical release; the API also returned locations and plaintext passwords without authentication.Pen Test Partners, 6 Oct 2020
Jan 2021Qiui CellmateThe lock, by an attacker rather than a researcher, with a bitcoin demand. A US distributor said the flaw was fixed in the latest app version.Motherboard, 11 Jan 2021
Sep 2023Unnamed chastity cage makerMore than 10,000 user records: email addresses, plaintext passwords, home and IP addresses, and in some cases GPS coordinates. Also logs of users’ PayPal payments.TechCrunch, 2 Sep 2023
Jul 2025LovenseAny user’s registered email address, from their public username; and the account itself, without a password.TechCrunch, 29 Jul 2025 · TechCrunch, 1 Aug 2025
Feb 2026TengaOne employee’s work email account, holding customer names, email addresses and past email correspondence. Roughly 600 people in the United States.TechCrunch, 19 Feb 2026

Ten events. Of the five page-one results we were able to open when we checked this search on 5 August 2026, one names four of them and the rest name one or none; none assembles them with dates against what each one actually reached. That is not because any of it is obscure. Each was published by the researcher who found it or by an outlet that verified it, and each has been sitting in public for between five months and ten years.

Three of these ten involved a lock, not a vibrator

This is the distinction that changes the answer. Some of the coverage does draw it — Forbes opens on the chastity case, and The Hustle labels both of its cage entries as chastity devices — but none of the pages we read turns it into something a buyer can check before paying. A vibrator that a stranger reaches is a privacy problem and, at the extreme, a harassment problem. A lock that a stranger reaches is a physical one, because the device is holding a part of the wearer’s body and the wearer cannot get out. All three lock cases below fall between October 2020 and September 2023.

Pen Test Partners put the Qiui Cellmate case plainly: remote attackers could prevent the lock from being opened, there was no physical unlock, and freeing the wearer would need an angle grinder used very close to soft tissue (Pen Test Partners, 6 Oct 2020). The same design made the disclosure harder than usual. The researchers’ normal move — ask the vendor to take the leaking API offline while it is fixed — was unavailable, because anyone wearing the device at that moment would have been locked in permanently by the fix.

Their timeline is worth reading in full if you want a sense of how these go. First contact was 20 April 2020 and the vendor answered quickly. A fix was promised for 6 June and a partial one shipped on 11 June, leaving the old endpoints reachable and the new ones still returning exact user locations. When the researchers reported the residue, they got no reply. Approached through a journalist on 25 June, the company said it did not want to fix the rest, or could not, because it had only $50,000. Two UK retailers were contacted in July and one withdrew the product. Three separate researchers had independently found problems with the same device by the time the disclosure went out in October.

Three months later, in January 2021, the attacker arrived. This is the only sequence in the ten where the two halves are both present: a documented flaw, and then a stranger using it on people.

The 2023 case is the same product category with a different failure. A researcher reached the records of more than ten thousand users of an internet-controlled chastity cage — emails, plaintext passwords, home addresses, some GPS coordinates — told the company on 17 June, got no fix, and in August defaced the company’s own homepage to warn its users. The company restored the site within a day and left the flaws in place. TechCrunch did not name the company, because naming it while the holes were open would have pointed attackers at users who had no way to protect themselves (Franceschi-Bicchierai, TechCrunch, 2 Sep 2023).

Researchers proving it is possible is not the same as it happening

Four of the ten entries are demonstrations. Pen Test Partners captured the Bluetooth traffic between the Lovense app and a Hush, saw the command the app writes to make it vibrate, and replayed that command from a laptop with a five-pound Bluetooth dongle and no app at all. They then went out to see whether devices were findable in the wild, and found some (Pen Test Partners, 29 Sep 2017). SEC Consult did the equivalent for the Vibratissimo line, writing a script that scanned for nearby devices, checked the manufacturer string, and set anything it recognised to full intensity — and separately found that the app’s share-control links were numbered in sequence, so a user could count down from their own link and reach a stranger’s device, with the confirmation prompt off by default (SEC Consult, 1 Feb 2018).

Both of those are real, both were reported to the vendors, and both are eight or nine years old now. What neither has is a member of the public it happened to. That is the line worth holding, because the record separates researchers proving a thing is possible from anyone actually doing it. Kaspersky drew the same line about We-Vibe as far back as August 2016: “The hack is still only a theory. But the developer gathering data about device temperature and difference in vibration — that’s really happening” (Kaspersky, 15 Aug 2016). A demonstration tells you the door is unlocked. It does not tell you anyone walked through it, and for vibrators we found no reported case of anyone having done so.

The reason is partly boring and partly structural. Bluetooth Low Energy has poor range, which is why the 2017 researchers had to physically go looking; there is no equivalent of a search engine for nearby devices. An attacker who wants to bother a stranger has to be near them. An attacker who wants to make money has better targets than a vibrator in radio range, and the ones who went after this category mostly went after servers instead. Six of the ten entries involve a company’s own records rather than only a device, and the one attacker in the ten who went for a device is the exception that proves the route: the January 2021 lockout reached the lock through the company’s API.

What the government warning everyone cites actually says

When we checked this search on 5 August 2026, two of the seven results on the first page were coverage of a UK government warning — one of them a forum thread we could not open, so this is from its title. It is worth reading the document, because its sex-toys section is thinner than the headline implies and one of its two physical-harm claims does not survive contact with the record above.

The document is a review of the risks and psychological harms presented by consumer IoT products, by Mark Cote, William Seymour, Jennifer Pybus and Dalia Mariasin, dated 31 March 2023 on its cover and hosted on the government’s publishing service (Cote et al., Department for Science, Innovation and Technology, 31 Mar 2023). It surveys children’s toys, femtech, fitness trackers, voice assistants, doorbells, cameras and vacuums as well. The sex toys section is about a page long, and its substance is that Bluetooth connections are often unencrypted, that the cloud services and chat features around the device add exposure, that intimate data supports extortion, and that a compromised device could in principle be made to overheat or be held to ransom.

Read the section itself and the base narrows sharply. It rests on two cited sources: a security-vendor white paper from 2021, and a New York Times report on the We-Vibe settlement from March 2017. Nothing in the section is newer than 2021, and none of it is a government test of any product.

The passage that has travelled furthest is worth quoting, because one half of it cuts against the distinction this article draws. It sits inside the review’s discussion of the 2021 white paper and carries no citation of its own: “the device can [be] weaponized against the user to propagate malware to cause physical harm, such as overheating the device or through ransomware, wherein an attacker might lock a device and demand a ransom in exchange for it to be unlocked.”

The two halves are not equally supported, and the record inverts the review’s own emphasis. The locking half, which the review hedges with “might”, is the one that happened, to named people, in January 2021. The overheating half, which the review states with “can”, appears in none of the ten events above, and our searching found no published case of a connected sex toy being made to overheat. We cannot tell you what the 2021 white paper rests on, because we have not read it. We can tell you what the section around this sentence rests on: that paper, and a March 2017 newspaper report about data collection. Neither is a documented overheating incident.

Forbes, the top-ranked result, actually softened that overclaim on its way past: it writes that physical harm “could come about by ‘overheating the device’ or the aforementioned locking of a device with a ransom required to unlock it”, where the review writes “can”. And on the date it got the important thing right, which is the part that did not travel — its second paragraph says the research was “originally published Mar. 2023” and “has, for some unknown reason been picked up by multiple media outlets again on Jan. 11”, and it links the PDF (Winder, Forbes, 11 Jan 2025). The correction was there in January 2025 for anyone who read the top result. It is the headline that travelled.

There is even an answer to the puzzle Forbes leaves open. The department first published the 2023 research on gov.uk on 5 December 2024, five weeks before the January pickup (Risks and psychological harms of consumer IoT products, GOV.UK, published 5 Dec 2024). Nothing mysterious happened: a 2023 document went online in December, and the coverage arrived on its own schedule.

There is a related problem with the freshest general-audience page on this question. Its entire security analysis is quoted from one named expert, described as a sextech industry figure, who is the chief executive of a company that sells connected toys (Yahoo Lifestyle, 15 Sep 2025, read 5 Aug 2026). The quotes are reasonable. But a reader is not told that the person explaining the risks of the product category sells the product category, and no incident or primary document appears anywhere on the page. We hold ourselves to the same standard we are applying here, which is why the small print under the opening paragraph tells you we may earn a commission on Lovense products elsewhere on this site, before Lovense appears anywhere below it, and why the full list of programmes we are in is on our disclosure page.

What to do with this before you buy

Three things follow from the shape of the record rather than from any single case:

If you are still deciding whether you want a connected device at all, the prior question — what the app actually buys you — comes first. Bluetooth pairing in the same room and an internet relay across a distance are different architectures with different exposure, and that is why the question leads our guide to choosing a couples toy.

Two limits on this list

This is the record we could verify, not the record. The 2023 entry shows the specific way that fails: TechCrunch withheld the company’s name because the holes were open, so a buyer searching that brand next to “hacked” would find nothing, and the nothing would be wrong. A brand with no entry here is a brand we found no published research on, which is a statement about researchers rather than about the product.

The second limit is that we have not tested any of these ten products, reproduced any of these findings, or inspected any traffic, and nothing above rests on our having done so. Every entry traces to a court filing, a researcher’s own disclosure, or an outlet that verified its own finding, and where a company’s statement is the only evidence for something we have said so in the row.

FAQ

Has anyone actually had their sex toy hacked? Yes, once in the record we assembled, and the device was a chastity lock rather than a vibrator. In January 2021 an attacker locked users of the Qiui Cellmate out of the device and demanded bitcoin to release it; one victim said he was asked for 0.02 bitcoin, and that he could not get it open. Everything else in the public record is either a researcher demonstrating that something is possible, or an ordinary data exposure: databases of email addresses, passwords and in some cases home addresses. Those are common. A stranger operating a device in someone’s home is not.

Can someone control my vibrator over Bluetooth from outside my house? Bluetooth Low Energy is short-range, so an attacker has to be close, and researchers who tried it in 2017 had to walk around a city looking for devices. Within that range the attack has been demonstrated more than once: Pen Test Partners replayed vibration commands to a Lovense Hush without the app, and SEC Consult wrote a script that set any Vibratissimo device it found to full intensity. Both were research demonstrations published with the vendor notified. Neither has a reported case of it happening to a member of the public.

Is a chastity device more dangerous than a vibrator? In the specific sense that matters here, yes. Three of the ten incidents we could document involve chastity locks, and they include the only cases where the failure was physical rather than informational — the 2023 chastity-cage entry is a data exposure like most of the rest. Pen Test Partners found that remote attackers could stop the Qiui Cellmate from opening, that there was no physical release, and that freeing the wearer would take an angle grinder. A vibrator that stops responding to its app is an annoyance. A lock that stops responding is a different kind of problem, and it is the reason a manual release is worth checking for before you buy.

What is the UK government warning about sex toy hacking? It is a literature review, and it is older than the headlines suggest. The document behind the January 2025 headlines is a review of psychological harms from consumer IoT products by Cote, Seymour, Pybus and Mariasin, dated 31 March 2023 on its cover but only published on gov.uk in December 2024, five weeks before the coverage. Its section on sex toys runs to about a page and cites two sources, the more recent of which is a 2021 security-vendor white paper. It is a fair summary of what was already known. It is not a new finding, and it is not based on the government testing anything.

Related reading: Are sex toy apps safe? → · What sex toy apps say they collect → · How to choose a couples sex toy → · App-controlled vibrators for couples → · How we review →

Sourcing: every entry above links the disclosure, filing or report it comes from, and all of them were retrieved and read on 5 August 2026. We have not tested these products, reproduced any finding, or inspected any traffic. For adults 18+. General information, not security, legal or medical advice.