What the WeChat “WeWorm” case tells us about zero-click attacks — and why “don’t click the link” is no longer a complete defense.
A number you recognize starts ringing. You are in a meeting, or asleep, or simply not in the mood. You let it go. A few seconds later, that should have been the end of it.
In the attack described this week by The New York Times and by the Palo Alto security firm Calif, those few seconds were enough. The call did not need to be answered. The victim did not need to tap a notification, open a file, or visit a website. While the phone was still ringing, a vulnerability in WeChat’s voice-call stack could hand an attacker control of the account: private messages, the ability to place new calls, and — crucially — the contact list that would carry the same attack to the next person.
Calif named the proof of concept WeWorm. It is the first publicly documented worm that could jump between Apple iOS and Google Android through WeChat calls without any click from the victim. Tencent, which owns WeChat, has since patched the flaw on the server side. No public evidence shows it was used against real users. That is the good news.
The rest of the story is harder. Zero-click attacks are not new. What is new is how quickly a small team, working with AI, can find the bug, write a remote-code-execution exploit, and turn it into a self-spreading worm.
What a zero-click attack actually is
Most people still picture cybercrime as a transaction: someone sends a lure, you make a mistake, the attacker gets in. Those attacks still dominate the cases we see at vali.now. They work because they ask the victim to participate.
A zero-click attack removes that participation. The payload is delivered by something the device already does for you — rendering a message, processing an incoming call, previewing an image. The software meant to make communication effortless becomes the door.
That is why these attacks have historically belonged to intelligence services and a handful of commercial spyware vendors. WeWorm is alarming not because one messaging app had a bug — every large app has bugs — but because the economics have changed.
“This bug is exceptional. Its simplicity and powerful abilities would be a dream come true for hackers.”
— Thai Duong, CEO of Calif
What Calif actually demonstrated
In a controlled lab, the chain was: call a saved contact → trigger a memory-corruption flaw in WeChat’s VoIP stack while the phone is still ringing → take over the account in seconds → dial the next names in the address book. Declining the call could stop that attempt; the attacker could try again later. The demo crossed from Android to iPhone and back.
WeChat is used by well over a billion people. A live worm of this type could, in principle, have reached hundreds of millions of accounts in hours. That is why a worm is different from a one-off hack: once it is loose, it uses your social graph as infrastructure.
Tencent confirmed the vulnerability after Calif reported it in July 2026 and later applied a server-side mitigation, so users didn’t have to do anything. Calif is withholding exploit details. That is responsible disclosure. The public write-up is the warning, not the recipe.
Why AI is the force multiplier — and not the whole story
Calif says an AI system surfaced the bug, the first remote-code-execution exploit took about two days with AI assistance, and the worm itself took another week. Work that once required a large team for months is now within reach of a small lab.
Two conclusions follow. Neither is “ban the models.”
First, the vulnerabilities were already there. AI did not invent the VoIP bug. It compressed the time between “this looks interesting” and “this works across iOS and Android.”
Second, the same compression is available to people who will not file a responsible report. Elite capabilities are leaking downward. You no longer need a nation-state budget to hunt for zero-click bugs in consumer apps.
The part that should worry you even if you do not use WeChat
If you do not have WeChat installed, this specific bug cannot reach you. That is not the same as being safe from the class of attack.
Every major messenger has a comparable surface: incoming calls, rich media, “trusted contact” privileges. For the people we advise at vali.now, the practical overlap is this: once an account is taken over, the next move is rarely technical. It is social. The attacker messages your partner as you. They ask a parent for a code. They send a payment request that looks exactly like the last legitimate one.
Zero-click is the entry. Impersonation is the cash-out.
That is why we treat “the message came from their usual number” as evidence of nothing. Compromised accounts speak with the victim’s voice, from the victim’s thread, to the victim’s people.
What to do this week
The WeChat bug is patched. Use that as a drill, not an all-clear.
Households: update apps and the OS; turn on the strongest 2FA the app allows; change your phone’s settings as described here; agree on an out-of-band check (a passphrase, a call you place) before any money or codes move; if a known contact suddenly wants secrecy or a transfer, stop and forward the thread to help@vali.now.
Companies: treat work messengers as production systems; separate “I know this person” from “I authorize this payment”; train staff that a call from a known contact is not authentication. Deepfake audio and hijacked accounts now sit on the same spectrum — the channel looks right, and the request is wrong. That is the problem Deepface is built to catch in real time: live impersonation during the call, not a report after the wire has left.
The lesson we are not going to draw.
The easy reaction is to treat AI as the villain and messaging apps as unusable. Neither holds. The bugs are already in the software we depend on. AI shortens both the attacker’s calendar and the defender’s.
Zero-click attacks remove the victim’s mistake from the first sentence of the incident report. They do not remove the second sentence — the moment a human being trusts a familiar name and does what the name asks. That moment is still where most of the damage is done. It is also the moment we can still change.
If you think this already happened to you: stop the chat, do not send codes or money, reach the real person on a channel you initiate, screenshot the thread, and write to help@vali.now. We will only ever email you from that address, and only after you contact us first. Anyone selling a “WeWorm cleanup fee” is running a recovery scam.
