AI built a zero-click WeChat worm in two days, Tencent says
Two stories this morning say the same thing from opposite directions: AI is now fast enough to break things faster than institutions can make rules about them.
Security researchers at Calif say they used AI to find a memory-corruption bug in WeChat's calling code and write a working remote-code-execution exploit in about two days — and that Tencent has now mitigated it. The result is WeWorm, described as the first zero-click worm that spreads through WeChat calls across both iOS and Android: the attacker phones a victim, and while the phone is still ringing the account is hijacked and used to call the next victim. The victim never has to answer or touch the phone, and declining only defers the attempt — the attacker can retry while you sleep. The demo chained three handsets, two Pixels and an iPhone 17e, with one compromised contact used to reach the next, which is the part that should worry anyone: WeChat's trust model gives friends extra privileges, so once one person in a group is taken, that trust becomes the delivery mechanism.
The honest read is that the vulnerability itself is not the headline. Zero-click mobile exploits have been the stock-in-trade of well-funded offensive actors for years; what changed is the labor cost. Calif says a worm at this scale used to take a larger team months, and that AI did most of the work here while the humans supplied judgment about what to target and how to test safely. That is the same compression curve we keep documenting on the defensive side, and it cuts both ways — the tooling that found this bug in 48 hours is not gated by talent, budget, or export control. Calif reported the bug to Tencent in July and is withholding technical detail until a conference talk, which is the right sequencing, but the WannaCry comparison they raise themselves is the real risk: half-finished tooling escaping a lab before the patch cycle catches up.
NeurIPS desk-rejected 178 papers — 18.4% of its Position Paper Track — using a commercial AI detector, with no human review in the first pass. The venue partnered with Pangram to enforce a "substantially human-written" policy, and the organizers' own write-up is more candid than most conferences would be: on default settings the detector flagged 42.7% of submissions as 90–100% AI-written, which they considered implausible, so they shrank the text windows until the flag rate fell to 12.7%. NeurIPS says 273 of 969 submissions scored 100% on the first pass, that AI completions under 20% of a text were never flagged in their own tests, and that authors of the strongest-flagged papers get an appeal dossier — but 22 papers were rejected partly because a black-box score contradicted a checkbox the authors had ticked.
The backlash has centered on the parts the conference did not measure. Independent researchers ran recent papers by the three track chairs through the same detector and got scores between 24% and 69%, and there is no published calibration for non-native English writers — the well-documented failure mode where formal ESL prose reads as machine-generated to a classifier. A conference that rejects work on a black-box score, offers no demographic validation, and treats a high score as evidence an author lied has inverted the burden of proof it claims to be defending. The fix NeurIPS gestures at — an audit trail of the writing process becoming the default — is a better norm than a classifier score, but it should have come before 178 rejections, not after.
What to watch: whether other venues copy the Pangram model before NeurIPS publishes its appeal outcomes, and whether Tencent's mitigation holds once the technical details of the WeChat bug are presented.
If a detector that flags the chairs' own papers can end a submission with no appeal, who should carry the burden of proof — the author or the conference? Tell us in the comments.
Sources: Calif — WeWorm · Calif Newsletter · New York Times · Techmeme · NeurIPS Blog — AI-Generated Papers in the NeurIPS 2026 Position Paper Track · r/MachineLearning discussion