China's WeChat makes fix after US firm shows AI hack risk
Tencent's WeChat, a mega-app used by over a billion people globally for messaging and payments, has patched security vulnerabilities identified by US cybersecurity firm Calif. Calif demonstrated how artificial intelligence could be used to create a cyberattack worm, dubbed "WeWorm," capable of spreading between phones via WeChat calls without user interaction. The firm claimed this worm could take full control of a WeChat account and, when chained with other mobile bugs, even a device. Tencent confirmed it investigated Calif's report, implemented a server-side fix that is now live for all users, and found no evidence of exploitation or user impact.
The WeChat security fix, prompted by US firm Calif's AI-driven vulnerability discovery, highlights the accelerating pace of cyber threat development. Calif reported using AI to find the WeChat flaw in two days and build the "WeWorm" in one week, a process that would typically take months for a larger human team. This speed points to a new era where less-skilled actors can wield advanced cyberattack capabilities, posing an unprecedented risk to ordinary users across Asia. For companies like Tencent, which operates one of the world's most ubiquitous apps, this means a constant, rapid need to adapt defenses against AI-powered threats. While Tencent quickly deployed a fix, the incident underscores the critical need for robust digital defenses across the region. The ability of AI to rapidly identify and exploit vulnerabilities in widely used platforms like WeChat, which is central to daily life for Chinese speakers globally, suggests that cybersecurity will become an even more dynamic and resource-intensive challenge for Asian tech giants and governments alike. This also points to a potential area of cooperation between the US and China on internet safety, despite broader geopolitical tensions, as suggested by Calif's chief Thai Duong.
Related reading
6 stories
Viral: Anthropic Researcher Drops A Bombshell, Quits After Warning Of AI Risks | ‘Gamble With Lives’
We've covered AI safety warnings before, including a researcher quitting Anthropic over AI risks.

Anthropic researcher says more than 10% chance AIcould kill all humans
Another Anthropic researcher previously warned of AI's potential to kill all humans, echoing the risks here.

People’s Daily rejects US claims of malicious AI distillation, warns of countermeasures

Databricks to Invest Over US$350 Million in Singapore, Double Its Workforce

Personetics Launches AI Banking Console for Relationship Managers

