Researchers Built AI-Powered WeChat Worm
The zero-click exploit, which compromised accounts without user interaction, was patched by Tencent in August 2026.
Updated on Sept. 23, 2026 in Cybersecurity

Live Poll
Do you trust the security of the messaging apps you use for daily communication?
Researchers at the cybersecurity firm Calif created an AI-powered worm capable of hijacking WeChat accounts without any user interaction. Tencent confirmed the vulnerability and completed server-side remediation on August 28, 2026.
Why it matters
This development highlights the emerging capability for AI-generated code to automate complex account compromises. It serves as a benchmark for how quickly automated tools can create security risks in widely used communication platforms.
The WeWorm required only one week to build using artificial intelligence and functioned on both iOS and Android platforms. It operated by placing an unanswered voice call, triggering an exploit that granted access to chat histories and messages within seconds.
The players
Calif
A Palo Alto-based cybersecurity firm specializing in the development of AI-driven offensive security tools.
Tencent
The Chinese technology conglomerate that develops and maintains the WeChat communication platform.
The details
The WeWorm utilized a zero-click exploit, a technique where malicious code executes on a device without requiring the victim to interact with a prompt or link. By initiating an unanswered voice call, the worm automatically gained entry into the WeChat application, subsequently spreading itself to the victim's contacts. The software gained access to internal app data, including messages, call logs, and full chat histories.
Timeline
August 28, 2026: Tencent completed server-side remediation of the vulnerability.
September 2026: US and Chinese leaders are scheduled to discuss AI hazards.
The Tech Race
This research follows the agenda set by the upcoming US-China AI safety dialogue, which aims to address the systemic risks posed by autonomous systems. The project marks a significant escalation in the race to secure communication platforms against AI-augmented attack vectors.
The vulnerability was successfully neutralized via a server-side patch deployed on August 28, 2026, requiring no action from individual app users. Those who remain concerned about account security should ensure their WeChat application is updated to the latest version as a standard practice.
The takeaway
The successful creation of this worm in just one week underscores how quickly AI can accelerate the production of high-impact security exploits. Readers should track the outcomes of the high-level US-China AI meetings in September 2026 for potential shifts in policy regarding AI-assisted security research.
What happens next
US and Chinese leaders are scheduled to meet in September 2026 to formally discuss risks associated with artificial intelligence.
Further reading
For broader trends in vulnerability management and defensive AI, see our latest Cybersecurity analysis.
Source note: This article includes information reported by Dimsum Daily.
Live Poll
Do you trust the security of the messaging apps you use for daily communication?






