AIToday
AI Safety & AlignmentAI Business & IndustrySemafor TechPublished: Sep 9, 2026, 10:00 JST2 min read

Startup Calif alerts Tencent to WeChat hacking worm

Startup Calif alerts Tencent to WeChat hacking worm

3 Key Points

  1. What happened

    US startup Calif used AI models to find a worm that could hijack WeChat accounts and spread via contacts. Calif alerted Tencent, which fixed the issue, The New York Times reported.

  2. Why it matters

    The discovery shows AI can identify serious vulnerabilities in major apps. It follows a spate of high-profile AI-powered hacks, highlighting both the capabilities and risks of advanced AI tech.

  3. What to watch

    Whether this incident helps build trust for US-China AI safety talks reportedly planned for later this month. Experts said concerns about safety could offer a good starting point for those negotiations.

WHO IT HITSEnterprise and consumer users of WeChat are affected because the worm could have allowed account hijacking and automatic spread through contacts. Cybersecurity teams and AI developers also face heightened scrutiny as AI-powered attacks become more common.

Ask the AI about this article →

Summaries like this, in your inbox every morning.

Context & Analysis

The discovery by Calif, a US security startup, marks a notable instance of AI being used to uncover a critical vulnerability rather than to exploit one. The worm in question is especially dangerous because it could self-propagate through WeChat's contact network, potentially amplifying the impact far beyond a single user. That Tencent moved to fix the issue after being alerted shows how AI can also serve defensive purposes in cybersecurity.

This episode arrives amid a string of high-profile AI-powered hacks, underscoring the dual-use nature of the technology. The same models that can identify flaws can also be turned to malicious ends, which is why the international community is paying close attention. The fact that the vulnerability was in WeChat, a super-app central to daily life in China, raises the stakes for cross-border cooperation.

The reported US-China talks on AI, possibly later this month, may benefit from this example as a practical starting point for dialogue. Safety concerns, as experts note, could serve as common ground. However, whether governments can convert such incidents into meaningful agreements remains uncertain, given the broader geopolitical tensions between the two nations.

FAQ
Who found the WeChat vulnerability?
Calif, a security company based in the US, found the vulnerability using AI models and alerted Tencent, which fixed the issue.
What could the attack tool do?
The worm could allow someone to hijack WeChat accounts and spread automatically through victims' contacts.
Why is this incident relevant to US-China relations?
Experts said concerns about AI safety could offer a good starting point for US-China talks on AI reportedly planned for later this month.

Get the latest AI Safety & Alignment news every morning

For example, today's edition would include:

  • Meta launches Muse AI agent, stresses securitySiliconANGLE AI · 2h ago
  • OpenAI claims Navier–Stokes breakthrough, faces credit disputeMIT Technology Review AI · 2h ago
  • Linux Foundation opens SAFE comments for AI securityITmedia AI+ · 5h ago

AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. Q&As are published on this page for other readers too.

Related Articles

Next articleOpenAI's ChatGPT Images 2.5 ships with better editing, speed