← All posts / Meta

Hundreds of Millions of Accounts, Zero Clicks: AI Models Built the WeWorm Attack on WeChat

California researchers used AI models to construct WeWorm, a self-propagating zero-click worm that could have hijacked hundreds of millions of WeChat accounts within hours — reading messages, sending texts, and making calls as the victim. Tencent says it has already patched the flaw.

Hundreds of Millions of Accounts, Zero Clicks: AI Models Built the WeWorm Attack on WeChat

The most consequential cybersecurity story of the AI era landed quietly on a Tuesday morning. The New York Times reports that a team of California-based AI researchers used large language models to build a computer worm — dubbed WeWorm — capable of hacking into WeChat accounts without any interaction from the victim. Security experts who reviewed the work said that, had it been unleashed rather than disclosed, the attack could have compromised hundreds of millions of devices within hours.

Tencent, WeChat’s parent company, says the underlying vulnerability has already been patched. But the demonstration rewires the threat model for the entire messaging-app ecosystem, because WeWorm’s novelty is not the bug it exploited — it is who wrote the exploit.

What WeWorm Actually Does

According to the Times report, WeWorm is a zero-click, self-propagating worm that moves through WeChat’s messaging fabric. Once a single account is compromised, the attacker inherits the full capabilities of a logged-in user:

  • Read incoming and outgoing messages — full conversation history and live traffic.
  • Send messages as the victim, turning each compromised account into a new infection vector aimed at the victim’s contact list.
  • Make calls through the victim’s account.
  • Control the victim’s account more broadly, limited mainly by what the app itself allows a user to do.

The “zero-click” designation is the terrifying part. Traditional phishing needs a human to tap a malicious link. WeWorm’s propagation requires nothing from the target — the worm arrives, exploits, and moves on. And because WeChat is simultaneously China’s dominant messenger, payment rail, and work-communication platform, a hijacked account is not just a privacy problem; it is a financial and reputational one, with scammers able to impersonate the victim to family, colleagues, and business partners who inherently trust messages from a known account.

The researchers responsibly disclosed the vulnerability, and experts quoted in the piece estimated that a real-world deployment could have burned through hundreds of millions of devices within hours — a propagation speed that would dwarf most historical worm outbreaks simply because of WeChat’s scale and the trust graph between contacts.

The Real Story: AI Wrote the Weapon

What separates WeWorm from a conventional CVE disclosure is the construction process. The researchers did not hand-write an exploit from a vulnerability report. They used AI models to build the worm — the discovery, weaponization, and propagation logic were substantially machine-generated.

This lands on top of a year of increasingly pointed warnings from the research community:

  • In June 2026, University of Toronto researchers demonstrated an AI-driven worm that parasitically hijacks compute on compromised machines to run open-weight LLMs, letting the worm “think” — probing each new host for weaknesses and tailoring its attack strategy per device. It infected 62% of a 33-host test network in seven days, with no human in the loop.
  • The AgentWorm / ClawWorm line of research (arXiv 2603.15727) showed the first fully autonomous, self-replicating worm against a production-scale LLM-agent framework: a single message delivered to any agent triggers a persistence → execution → propagation cycle that spreads across the ecosystem with zero clicks.
  • The 2024 “Morris II” proof-of-concept from Cohort research had already shown zero-click worms spreading through GenAI assistants via adversarial self-replicating prompts — an attack class that targets the AI layer rather than the operating system.

WeWorm fuses these threads: the target is a mainstream consumer app with billions of users, and the author of the attack is the same class of model that powers the app’s own features. The asymmetry is stark — defensive engineers patch linearly, one vulnerability at a time, while AI-augmented attackers can generate, test, and adapt exploits at machine speed.

Why WeChat, and Why It Matters Everywhere

WeChat is an unusually attractive target: well over a billion monthly users, deep integration with payments and identity, and a contact graph where a message from a known person carries near-automatic trust. A worm that rides that trust graph doesn’t need to defeat cryptography — it weaponizes social capital.

But the lesson generalizes. Any platform that combines (1) rich messaging, (2) embedded mini-programs or automation hooks, and (3) AI-mediated features is standing in the same blast radius. The Wired analysis from August 2026 framed it bluntly: Chinese researchers had already shown AI models “have the capacity to act like aggressive and adaptive computer viruses.” WeWorm is that capacity pointed at a single, specific, planet-scale application.

There is also a governance wrinkle: the researchers are California-based, the target platform is Chinese, and the disclosure is playing out through Western media. Cross-border vulnerability disclosure around AI-generated exploits remains a regulatory gray zone — there is no established norm for who must be told, how fast, and whether AI-assisted exploit generation should be treated differently from human-authored weapons research.

What Comes Next

For Tencent, the patch closes this particular door; the company says the vulnerability no longer reproduces on current versions. For everyone else, three takeaways:

  1. Zero-click is now an AI-native attack class. When exploit generation is automated, the cost of attacking every user of a platform simultaneously collapses toward zero.
  2. Patch velocity becomes the only meaningful defense metric. U of T’s researchers noted their AI worm spreads slower than classical worms because it reasons about each host — but reasoning buys adaptability, and adaptability defeats signature-based defenses.
  3. Agent ecosystems are the soft underbelly. As messaging apps bolt on AI assistants and agentic features, each new automation surface is a new propagation medium. The AgentWorm research showed that a production agent framework can be infected from a single message; WeWorm shows the same physics applies to consumer scale.

The uncomfortable summary: the same models that write your emails can now write the worm that reads them. WeWorm was disclosed responsibly this time. The next one may not be — and “within hours” is simply how long the next patch race will take.