• Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
EU’s Cyber Resilience Act gives crypto wallet makers 24 hours to report exploited flaws

EU’s Cyber Resilience Act gives crypto wallet makers 24 hours to report exploited flaws

09/15/2026
AI helped researchers find a WeChat flaw that could hijack over 1 billion accounts with a single call

AI helped researchers find a WeChat flaw that could hijack over 1 billion accounts with a single call

09/15/2026
AI data

AI chip boom threatens South Korea’s financial stability, Bank of Korea warns

09/15/2026
  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
EU’s Cyber Resilience Act gives crypto wallet makers 24 hours to report exploited flaws

EU’s Cyber Resilience Act gives crypto wallet makers 24 hours to report exploited flaws

09/15/2026
AI helped researchers find a WeChat flaw that could hijack over 1 billion accounts with a single call

AI helped researchers find a WeChat flaw that could hijack over 1 billion accounts with a single call

09/15/2026
AI data

AI chip boom threatens South Korea’s financial stability, Bank of Korea warns

09/15/2026
Tuesday, September 15, 2026
  • Login
The Bit Gazette
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion
No Result
View All Result
The Bit Gazette
No Result
View All Result
Home Crypto News

AI helped researchers find a WeChat flaw that could hijack over 1 billion accounts with a single call

A WeChat exploit disclosed by California cybersecurity firm Calif allowed a self-spreading worm to take over accounts through unanswered voice calls, prompting Tencent to patch the vulnerability in August.

by Muhammad Abubakar
1 hour ago
in Crypto News
Reading Time: 3 mins read
0
AI helped researchers find a WeChat flaw that could hijack over 1 billion accounts with a single call

AI helped researchers find a WeChat flaw that could hijack over 1 billion accounts with a single call

Share on FacebookShare on Twitter

Security firm Calif has disclosed a zero-click vulnerability in WeChat’s voice-call system that could have let attackers hijack accounts within seconds of placing a call, with no answer, click or download required from the victim.

Tencent patched the flaw in August after being notified in July, but Calif says the exploit could have been weaponized to affect more than a billion accounts had it been discovered by malicious actors first.

WeChat exploit spreads through victims’ contacts

The worm’s ability to propagate through a victim’s social network is central to the WeChat exploit.

After compromising an account, WeWorm can use the hijacked account to place calls to people in the victim’s contacts. Those contacts can then become targets themselves, allowing the attack to move laterally through WeChat’s social graph.

Calif has not released the technical details of the underlying vulnerability publicly. The company said it is withholding those specifics until a conference presentation, and no CVE identifier had been assigned at the time of the disclosure.

The discovery also highlights the changing economics of vulnerability research. Calif said artificial intelligence helped researchers identify the flaw and develop working exploitation tools at an unusually rapid pace.

The vulnerability was discovered in July with AI assistance. By July 30, the team had produced its first Android remote-code-execution tool, taking roughly two days from discovery to a functioning exploit. An iOS version followed on August 2, while a cross-platform worm demonstration was completed on August 11.

Calif Chief Executive Thai Duong said the researchers remained responsible for directing and supervising the process.

“AI helped us accelerate the process, but we had to supervise it from start to finish for the worm to work,”  Thai Duong, CEO of Calif.

The company has not identified the AI model used in its research. Its findings instead emphasize how AI-assisted security work can shorten the time required to move from vulnerability discovery to functional exploitation.

Tencent responds to WeChat exploit disclosure

Tencent was notified about the WeChat exploit on July 24, according to Calif. The research accounts used during testing were subsequently blocked between July 25 and July 28 before being restored.

Tencent released updated versions on August 21, including Android 8.0.77 and iOS 8.0.76. Calif later confirmed that Tencent had also deployed server-side protections covering all WeChat users between August 26 and August 28.

The server-side mitigation was particularly significant because it did not require individual users to take action. The company also received technical analysis and working tools from Calif on September 3, five days before the research was publicly released.

The timeline from disclosure to patches underscores the importance of coordinated vulnerability reporting when flaws can potentially affect a large user base.

Tencent’s second-quarter 2026 filing reported combined monthly active users of WeChat and Weixin at 1.439 billion as of June 30. That figure provides context for the potential reach of a vulnerability affecting the platform’s calling infrastructure, although Tencent has not disclosed how many accounts were actually exposed or affected.

The WeChat exploit was ultimately addressed through both application updates and server-side measures, but the episode illustrates how quickly mobile threats can evolve.

WeChat exploit raises Bitcoin self-custody concerns

For cryptocurrency users, the WeChat exploit also underscores a distinction between blockchain security and device security.

Bitcoin’s underlying network may remain cryptographically secure, but users can still lose control of their assets if an attacker gains access to the device, credentials or signing environment used to manage them.

A compromised smartphone could expose exchange credentials or other sensitive information. For users relying on mobile devices to interact with self-custodied wallets, the threat is therefore not necessarily a weakness in Bitcoin itself but a compromise of the environment surrounding the wallet.

The WeChat exploit reinforces the importance of separating critical wallet operations from everyday internet-connected devices. Hardware wallets can provide an additional layer of isolation by keeping private-key operations away from a potentially compromised smartphone or computer.

The incident also demonstrates why software updates remain a basic but important security measure. Tencent’s August patches and subsequent server-side mitigations reduced the exposure without requiring users to manually configure additional protections.

Calif’s disclosure ultimately presents two connected security lessons: AI-assisted exploit development can accelerate the discovery and weaponization of mobile vulnerabilities, while widespread messaging platforms can provide an unusually large network through which those vulnerabilities may spread.

For Bitcoin holders, the episode is a reminder that protecting digital assets requires more than relying on the security of the blockchain itself. The devices, applications and credentials used to access those assets can become the practical point of failure.

Tags: AIBitcoincybersecurityexploitsmalwareself-custodyWeChatWeWorm
Share196Tweet123
Muhammad Abubakar

Muhammad Abubakar

Muhammad Abubakar is a researcher, and tech-oriented communicator with a keen interest in data analysis, writing, and leadership.He enjoys football, evening walks, and cultivating meaningful professional relationships.

  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
EU’s Cyber Resilience Act gives crypto wallet makers 24 hours to report exploited flaws

EU’s Cyber Resilience Act gives crypto wallet makers 24 hours to report exploited flaws

09/15/2026
AI helped researchers find a WeChat flaw that could hijack over 1 billion accounts with a single call

AI helped researchers find a WeChat flaw that could hijack over 1 billion accounts with a single call

09/15/2026
AI data

AI chip boom threatens South Korea’s financial stability, Bank of Korea warns

09/15/2026
The Bit Gazette

Copyright © 2025 - The Bit Gazette.

Navigate Site

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion

Copyright © 2025 - The Bit Gazette.