WeChat fixes flaws after US firm shows AI cyberattack worm could hijack accounts
Tencent's WeChat, a mega-app used by over a billion people globally, has addressed critical software vulnerabilities identified by US cybersecurity firm Calif. Calif demonstrated how artificial intelligence could be used to create a cyberattack "worm" capable of hijacking WeChat accounts without user interaction. The firm's "WeWorm" project showed it could gain full control of an account in seconds, reading messages, making calls, and acting on the victim's behalf. Tencent confirmed it investigated the report and deployed a server-side fix, assuring users no app update or action is required. The company stated it found no evidence of exploitation or affected users.
The WeChat vulnerability, quickly identified and exploited by AI, underscores a growing concern for digital defenses across Asia. Calif's ability to develop a sophisticated "WeWorm" in just over a week, a task that previously required months for larger teams, points to AI democratizing cyberattack capabilities. This development means less-skilled actors can now pose significant threats, putting ordinary users and critical infrastructure at unprecedented risk. For Asian tech companies, particularly those operating large-scale platforms like WeChat, this incident highlights the urgent need to integrate AI-driven security measures into their development cycles. While Tencent acted swiftly to patch the flaw, the speed at which AI can uncover and exploit vulnerabilities means that proactive, continuous security auditing with AI tools will become essential to protect user data and maintain trust in ubiquitous apps across the region.
Related reading
6 stories
Viral: Anthropic Researcher Drops A Bombshell, Quits After Warning Of AI Risks | ‘Gamble With Lives’
AI's democratizing of cyberattack capabilities raises the same urgent safety questions we explored with Anthropic.

Anthropic researcher says more than 10% chance AIcould kill all humans
The rapid development of AI-driven threats echoes the serious warnings about AI risks from Anthropic researchers.

If driverless cars already work, why aren’t they everywhere?

People’s Daily rejects US claims of malicious AI distillation, warns of countermeasures

Databricks to Invest Over US$350 Million in Singapore, Double Its Workforce

