AI-Powered WeChat Attack Exposes China’s Digital Vulnerabilities
A demonstration of a powerful artificial intelligence-powered cyberweapon has exposed vulnerabilities in China’s digital infrastructure and added urgency to discussions between Beijing and Washington over AI safety and cybersecurity.
WeChat has become deeply embedded in China’s national infrastructure. Government agencies, businesses and nearly 80% of Chinese citizens use the messaging and payment platform for communication, business transactions, government services and everyday activities.
That dependence has raised serious concerns following the discovery by a small team of California-based researchers that an AI-powered tool could potentially breach millions of WeChat accounts within hours. The demonstration showed how a relatively small group, without government backing, could potentially launch a highly disruptive attack against a platform used by about 1.4 billion people each month.
Zhao Minghao, deputy director of the Center for American Studies at Fudan University in Shanghai, described the destructive potential as extremely powerful. Given WeChat’s importance to Chinese society and its enormous user base, he compared the potential impact of such a capability to “a new kind of nuclear weapon.”
The development comes amid growing warnings that AI-enabled hacking capabilities are advancing faster than cybersecurity defenses. The issue could become increasingly important in discussions between U.S. President Donald Trump and Chinese President Xi Jinping, who are expected to meet in Washington on Sept. 24. AI security, along with trade and other bilateral issues, is expected to feature in the talks.
The researchers behind the WeChat demonstration work for Calif, a Palo Alto-based cybersecurity company that says it develops such tools for defensive purposes rather than for sale.
The researchers called the tool “WeWorm.” They demonstrated that it could potentially hijack a WeChat account, contact the victim’s friends and spread from one phone to another without requiring the recipient to answer a call. Calif said it took slightly more than a week to develop the tool and that it had disclosed the vulnerability to the White House and Tencent, WeChat’s owner.
Kyle Chan, a fellow at the Brookings Institution who studies Chinese technology and industrial policy, said the discovery could encourage Beijing to work more closely with Washington to manage AI-related risks. He said the incident demonstrated the potential for state and nonstate actors to use AI to attack China’s digital infrastructure.
However, deep mistrust between China and the United States could make cooperation difficult. The disclosure could also intensify competition between the two countries over the development and use of increasingly powerful AI systems.
China is likely to respond by strengthening the defensive capabilities of its domestic AI systems, according to Zhao. Such systems could be used to identify and repair cybersecurity vulnerabilities more quickly.
But the United States could view those same capabilities as potential offensive tools against American companies and institutions, prompting Washington to further strengthen its own cyber defenses. Zhao described this as an emerging “AI security dilemma,” in which the distinction between offensive and defensive capabilities becomes increasingly blurred.
The WeChat incident comes alongside other concerns about the misuse of AI. Anthropic, the company behind the Claude AI models, said in a recent report that it had disrupted attempts to use its systems for research that could potentially contribute to the development of biological weapons.
Anthropic also reported attempts by a Chinese arms manufacturer to use Claude to refine a proposal for an anti-torpedo weapons system for the Chinese military. The company said some Chinese users had also attempted to use its models to develop surveillance operations targeting foreign governments, Uyghurs in Syria and religious leaders.
China’s Foreign Ministry spokeswoman Mao Ning rejected what she described as efforts to distort facts or attack and smear China.
Experts say the latest incidents demonstrate the need for the world’s two leading AI powers to establish channels for sharing information about malicious actors and clarifying their intentions.
Few observers, however, expect the upcoming U.S.-China summit to produce restrictions on AI development itself. Neither government is likely to accept measures that could constrain its own technological capabilities. Establishing a reliable communication channel for managing potential crises could nevertheless be an important step.
Jiang Tianjiao, an associate professor at Fudan University specializing in emerging technologies, described the WeWorm demonstration as an “alarm” and a “wake-up call.” He argued that governments should discuss how AI is creating security risks that differ fundamentally from traditional threats and whether new international cooperation frameworks are necessary.
China has increasingly embraced AI as a strategic technology critical to its economy, while also acknowledging its potential dangers. Chinese regulators have warned local governments and companies about the use of AI assistants such as OpenClaw and issued guidelines in May governing AI agents. Officials are also working on more than a dozen national standards aimed at strengthening cybersecurity in the AI era.
Xi said at an AI conference in July that countries should cooperate to ensure that “AI is always under human control.”
Chinese officials have also warned about the potential use of AI in the development of dangerous weapons and biological threats. Last year, Chinese cybersecurity authorities warned that extremist groups and others could use AI to acquire knowledge related to nuclear, biological, chemical and missile weapons.
Another major challenge is transparency. It remains unclear whether Chinese AI companies would voluntarily disclose security vulnerabilities to U.S. companies if they discovered them. Chinese firms are required to report such discoveries first to China’s Ministry of Industry and Information Technology.
Cybersecurity expert Pei Wang said Chinese companies would likely approach such disclosures cautiously because of the possibility that the information could become politicized amid intense technological competition between Washington and Beijing.
The WeWorm incident also comes at a time when tensions over technology between the two countries are intensifying. China has long accused Washington of attempting to slow its technological development through sanctions, export controls and tariffs.
At the same time, U.S. officials have signaled greater willingness to target Chinese companies for intelligence gathering. On Tuesday, CIA Deputy Director Michael Ellis said Chinese companies could be legitimate targets for espionage involving areas such as AI, semiconductors and biotechnology.
Some Chinese scholars have proposed that the two countries establish voluntary “negative lists” identifying unacceptable AI-enabled cyber activities. They have also suggested designating categories of critical infrastructure that both sides would agree not to target.
Chinese officials have not publicly acknowledged the WeChat vulnerability, possibly because Beijing does not want to create additional tensions ahead of the summit. When asked about WeWorm at a Foreign Ministry briefing, Mao said she was not familiar with the issue.
For Tencent, the incident could bring increased scrutiny from Chinese regulators. Xiaomeng Lu, a researcher at Eurasia Group who studies U.S.-China technology competition, said Chinese cybersecurity authorities could question Tencent officials about what happened and the likelihood of a similar incident occurring again.
The episode underscores a broader challenge facing both countries: as AI systems become increasingly capable of conducting sophisticated cyber operations, technologies developed for defense can potentially be repurposed for offensive purposes.
That growing overlap between AI, cybersecurity and national security could make cooperation between Washington and Beijing more difficult—but also more necessary.
Source: The Newyork Times