cd /news/ai-safety/us-firm-used-ai-to-hijack-wechat-acc… · home topics ai-safety article
[ARTICLE · art-124314] src=scmp.com ↗ pub= topic=ai-safety verified=true sentiment=· neutral

US firm used AI to hijack WeChat account, spurring call for cyber cooperation with China

US security firm Calif said its AI system identified a critical flaw in Tencent Holdings' WeChat app in July, enabling remote account takeovers via unanswered voice calls, and Tencent patched the bug in late August. The experimental exploit, WeWorm, was developed in just over a week, highlighting how AI accelerates cyber threats and spurring calls for US-China cyber cooperation.

by read1 min views4 publishedSep 9, 2026
US firm used AI to hijack WeChat account, spurring call for cyber cooperation with China
Image: Scmp (auto-discovered)

The flaw allowed for remote account takeovers without user interaction, prompting Tencent to patch the problem after Calif cybersecurity team flagged it

US cybersecurity researchers have demonstrated how artificial intelligence could help hijack WeChat accounts via unanswered voice calls, intensifying concerns about AI-driven cyber threats and prompting renewed calls for bilateral cooperation between the United States and China.

US security firm Calif said on Tuesday that its AI system identified a critical flaw in Tencent Holdings’ widely used messaging and payments app in July. In just a little over a week, researchers developed WeWorm – an experimental exploit that could allow an attacker to take full control of a target’s WeChat account via a simple voice call, without the victim ever picking up the phone.

Tencent patched the bug in late August, according to Calif, which alerted the Chinese tech giant.

A Tencent spokesperson confirmed on Wednesday that a server-side fix was deployed, requiring no user action, and noted there was no evidence that the vulnerability was ever exploited in the wild. Tencent added that it was “grateful to the researchers for bringing this to our attention and working with us”.

The experiment underscores the speed at which AI is accelerating cyber threats. A worm of this complexity previously required months of work from larger engineering teams, but Calif researchers noted that “AI can already do most of the work here”.

The findings left some analysts alarmed.

── more in #ai-safety 4 stories · sorted by recency
── more on @calif 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/us-firm-used-ai-to-h…] indexed:0 read:1min 2026-09-09 ·