A US cybersecurity firm demonstrated an AI-powered exploit that could hijack WeChat accounts via unanswered voice calls, revealing a critical security flaw in Tencent’s app and intensifying calls for closer US-China collaboration on cyberthreat mitigation.
- AI enabled rapid development of a WeChat account hijacking exploit
- Tencent confirmed patch deployment and no known exploitation in the wild
- Experts urge US-China cooperation to address escalating AI cyber threats
What happened
US cybersecurity firm Calif revealed that their AI system detected a critical vulnerability in Tencent’s WeChat messaging and payment platform during July. Within just over a week, the researchers created WeWorm, an AI-driven exploit able to hijack WeChat accounts by placing unanswered voice calls, requiring no interaction from the victim.
Calif promptly informed Tencent, which deployed a server-side fix in late August, eliminating the vulnerability without requiring any action from users. Tencent stated it found no evidence that the flaw had been exploited maliciously and expressed gratitude toward the researchers for responsibly disclosing the issue.
Why it matters
This experiment underscores how artificial intelligence is dramatically speeding the pace at which complex cyberattacks can be developed, compressing what once took months of manual engineering to just days. The ease with which AI enabled the creation of WeWorm highlights a rising threat landscape where malicious actors could replicate such attacks at scale.
The revelation has alarmed cyber policy experts like Ryan Fedasiuk of the American Enterprise Institute, who stress that neither the US nor China is well prepared for escalating AI-powered cyber risks. This has prompted calls for renewed communication and collaboration to safeguard billions of online users in both countries.
What to watch next
With President Xi Jinping set to visit Washington later this month, cybersecurity and AI safety are expected to be key topics even amid ongoing tensions. US Treasury Secretary Scott Bessent’s skepticism of China’s tech model and recent US accusations against Chinese AI firms for leveraging American AI knowledge complicate cooperation prospects.
Nonetheless, voices from both sides emphasize the urgent need for a bilateral cybersecurity dialogue focused on identifying and mitigating genuine threats. How this discussion unfolds could shape future norms and strategies for managing AI-driven vulnerabilities across global tech platforms.