• Calif published WeWorm research on September 8 showing zero-click WeChat VoIP account takeover
• AI helped Calif find the flaw and build the first remote code execution tool in about two days
• Tencent shipped patches Android 8.0.77 and iOS 8.0.76 on August 21
Zero-Click WeChat Account Takeover
Security researchers in Palo Alto have built a self-spreading worm that can seize control of a WeChat account through nothing more than an unanswered voice call. The California security firm Calif published its findings on September 8, detailing a zero-click worm dubbed “WeWorm” that exploits a memory-corruption flaw in WeChat's voice-over-IP call processing. Because the attack executes without any tap, download or user interaction, it sits in the most severe class of mobile exploits — a class that matters well beyond messaging apps, since a compromised handset exposes every credential stored on it, from exchange logins to the keys guarding self-custodied Bitcoin (BTC) and assets moved via spot trading platforms. Under the constraints documented in the research report, the attacker must already appear in the victim's WeChat friend list, which narrows who can pull off the dial-based assault. Once the call is placed, full control of the account is obtained within seconds. The victim does not need to answer, and answering changes nothing: the call carries no sound while the takeover runs its course in the background. The hijacked account then places calls to the victim's own contacts, turning each new victim into the next attacker and letting the worm spread laterally through the social graph. Calif demonstrated the chain hopping across mobile ecosystems — from a Pixel 10a to an iPhone 17e and back to a second Pixel 10a — in a cross-platform demonstration video. The firm assessed that a real-world weaponization of the technique could compromise more than one billion phones or accounts. The flaw lives in the code handling WeChat's internet voice calls, though the team is withholding specifics until a conference presentation; no CVE identifier has been assigned so far.
AI Wrote the First Exploit in Two Days
The development timeline attached to the disclosure shows how quickly artificial intelligence is compressing exploit engineering. The flaw was surfaced in July with AI assistance, and the team produced its first remote code execution tool for Android by July 30 — roughly two days of work from discovery to working exploit. An iOS version followed on August 2, and a complete, demonstrable worm linking the two platforms was finished by August 11. Calif was explicit about the division of labor: the models accelerated vulnerability discovery and tool-writing, while researchers supplied the judgment on what to target and how to test safely. Chief executive Thai Duong said the team had to supervise the process from start to finish for the worm to function, and the report does not name the AI model involved. Responsible disclosure moved on a parallel clock. Calif reported the flaw to Tencent on July 24; the research accounts used for testing were blocked between July 25 and 28 before being restored. Tencent shipped version patches on August 21 — Android 8.0.77 and iOS 8.0.76 — and Calif confirmed that server-side mitigations covering all users went into effect between August 26 and 28, protections that required no action from the user base. Technical analysis and working tooling were handed to Tencent on September 3, and the research went public on September 8. The company's official second-quarter 2026 filing put combined monthly active users of WeChat and Weixin at 1.439 billion as of June 30, a measure of the scale riding on the call stack that contained the flaw. From report to shipped patch was four weeks, with roughly another week for the server-side block to reach everyone. Tencent has confirmed the vulnerability and completed its patches, but it has not disclosed how many accounts were affected.
Bitcoin (BTC) Self-Custody Lessons
For crypto holders, the episode reframes where wallet risk actually lives. AI now produces working zero-click exploits in days — a cadence that outpaces monthly patch cycles — so COINOTAG's read is that device-level compromise, not on-chain cryptography, remains the weakest link protecting Bitcoin (BTC) and other self-custodied assets. Once a handset is controlled, no protocol feature helps: funds can be swept and traces obscured through a crypto mixer, while privacy coins such as Zcash (ZEC) cannot stop an attacker reading the screen in real time. A hardware wallet paired with a protected recovery key keeps signing isolated from the compromised device, and the monitoring discipline behind our cryptojacking coverage applies equally to worm-class mobile threats.
