technology 5 min read

AI Built a WeChat Worm in 10 Days — And That Should Terrify You

A security team in California used AI to discover a zero-click WeChat flaw and build a working worm in ten days. The timeline isn't just fast — it represents a fundamental shift in who can launch targeted campaigns at scale.

  • Cybersecurity
  • AI & Security
  • WeChat
  • Tencent
  • Zero-Click Exploit
  • AI Threats

The ten-day weapon

A team of security researchers in California spent roughly two days using AI to find a flaw in WeChat’s calling code and build an exploit that lets them run commands on a target’s phone without the user touching anything. They spent another week wiring that exploit into a self-spreading worm. The total time from discovering the bug to shipping a deployable weapon: ten days.

Ten days. That is not a milestone for a well-resourced nation-state team with years of experience. It is now the baseline for a small group with AI tools.

The vulnerability lives in WeChat’s VoIP stack — specifically, a memory-corruption bug that triggers during the ringing phase, before the called party answers or rejects. The worm activates in that narrow gap. Once inside, it reads messages, sends messages, makes calls, impersonates the account owner, and then calls people from the victim’s contact list to repeat the chain. It has been demonstrated crossing operating systems: an infected Android device compromised an iPhone, which then infected a second Android device.

WeChat, owned by Tencent, has more than a billion users. Most are in China, but the app has a substantial international footprint across Chinese-speaking communities and diaspora networks worldwide. In a lab setting, the researchers estimated that spreading through contact lists — WeChat users typically carry hundreds of connections — could reach millions of devices in a matter of hours.

Who this changes

The most important detail is not the worm itself. It is the timeline.

Five years ago, discovering a zero-click exploitation path in a widely used messaging app’s VoIP stack would have required a team of specialists, months of work, and likely a government budget. Today, AI turned the same outcome into a sprint project. The researchers said the AI tools lowered the expertise threshold — meaning attackers who previously lacked the skill set can now build weapons that used to belong exclusively to well-funded actors.

That matters because the barrier between reconnaissance and deployment has always been the bottleneck in cyber warfare. AI just removed it.

The realistic constraints are worth acknowledging. The initial attacker must already appear in the target’s contact list, or infect someone who does. The worm currently grants control of the WeChat account, not the device itself — though the Calif team noted that chaining the VoIP flaw with other vulnerabilities let them take over the entire device in lab tests. Tencent said it found no evidence the flaw was exploited in the wild before being patched.

But constraints shrink over time. The first version of any weapon is never the last.

What Tencent did — and did not do

Tencent received Calif’s disclosure on July 24. It shipped patches on August 21 — version 8.0.77 for Android and 8.0.76 for iOS. A server-side mitigation confirmed on August 28 protects even unpatched users at the network level. Tencent says there is currently no residual risk for users on the latest versions.

No CVE number has been assigned. No formal security advisory has been published. The researchers plan a fuller technical disclosure after industry-wide mitigation measures are in place, with a conference presentation expected.

The speed of the patch response was reasonable. The decision to withhold a CVE and a public advisory is not unusual for a company that may not want to draw attention to a flaw that, so far, existed only in a lab. But it leaves the broader security community without a formal reference point for tracking whether the vulnerability resurfaces in other products or gets weaponized differently.

The deeper shift

The WeChat worm is a proof of concept, not an apocalypse. But it is a preview of the operating system for cybercrime in the next decade.

What Calif demonstrated is that generative AI can now compress the most labor-intensive phases of exploit development — vulnerability discovery, exploit writing, weapon assembly — into a timeframe that was previously impossible outside state-grade programs. The researchers called it a lowering of the bar. That understates the change. This is not just easier access to existing capabilities. It is the emergence of a new class of actor: small teams, potentially solo operators, who can now produce campaigns that previously required organizations.

The contact-list dependency limits the worm’s blunt-force potential, but that limitation is solvable. Phishing lures, compromised contacts, credential theft — all of those are well-understood attack vectors that AI can help automate at scale. The VoIP zero-click path is the crown jewel in this case, but the infrastructure around it — the AI-assisted research pipeline, the rapid exploitation cycle — is what will define the threat landscape.

Message-app vendors face a structural problem. Every VoIP implementation is a potential attack surface. Every update cycle is a window. And every AI-augmented researcher is now a potential adversary who can move from discovery to deployment in days instead of months.

For WeChat users, the immediate risk is low if you are on the latest patch. The server-side mitigation adds a second layer of protection. But the real story here is not whether your phone is vulnerable today. It is that the clock has moved. Ten days from bug to worm is no longer a fantasy. It is the new normal.

And the next team with ten days and an AI tool does not have to be researchers showing you what is possible. They just have to want to.