logo
    • Buy Crypto
    • Markets
    • Futures
    • Spot
    • Earn
    • Affiliates & AI
    • More
    1. WEEX
    2. Crypto News
    3. New “Zoomsday” exploit could expose crypto users to zero click attacks

    New “Zoomsday” exploit could expose crypto users to zero click attacks

    By: rootdata|2026/08/13 07:53:24
    0
    Share
    copy
    Prefer us on GooglePrefer us on Google
    APPAPP
    00.00%--
    SPYSPY
    00.00%--
    BASEDBASED
    00.00%--
    BasedBased
     

    A newly disclosed set of Zoom vulnerabilities has shown how attackers could take control of another meeting participant's device without any action from the victim, creating a fresh security risk for crypto users who have repeatedly been targeted through video calls.
    Summary

    • A Security said a researcher used fewer than 20 AI prompts to find three Zoom vulnerabilities and build a working exploit in under 24 hours.
    • The Zoomsday attack could take control of a meeting participant's device without requiring any action from the victim.
    • Crypto users face added risk as hackers have previously used compromised Zoom meetings to steal wallet data and other sensitive information.
    • Zoom released fixes between June 22 and July 20, but users on older versions still need to update their apps.

    According to Israeli cybersecurity firm A Security, a researcher used fewer than 20 prompts with publicly available artificial intelligence models to uncover the flaws and build a working attack in less than 24 hours. The firm named the attack "Zoomsday" and said the vulnerabilities affected Zoom's annotation system, which lets meeting participants draw or add notes to shared content.

    Once exploited, the flaws could allow malicious code to run on another participant's device without requiring the person to download a file, click a link, or approve an action, according to the report. According to the firm, the attacker could then steal personal information, install malware, or activate a device's microphone and camera.

    For cryptocurrency users, the ability to compromise a computer directly through a meeting could carry added risks because attackers have previously used Zoom calls to reach crypto wallets, private files and other sensitive information.

    Zoom exploit could target any meeting participant

    The vulnerabilities, tracked as CVE-2026-53413, CVE-2026-53414 and CVE-2026-53415, were tested against Zoom applications running on Windows, macOS, Linux, Android and iOS.

    The attack could work from either side of a call. According to the researchers, a compromised presenter could attack participants, while a participant could also target the presenter. An attacker only needed to join or host the meeting before sending the malicious data required to trigger the vulnerability.

    No further interaction was required from the target, and A Security said the victim would receive no visible warning that the device had been compromised.
    You might also like: North Korean 'fake Zoom' hustle drains $300m from crypto execs' wallets

    "Once the nefarious code is running on the victim's device, the threat actor can quietly steal personal data, switch on the microphone or camera to spy on the target, or install other malicious software," the firm said.

    "Exploits like this one are weapons. Governments regulate their export. Criminal organizations pay millions for them," the researchers wrote.

    According to the firm, researchers were able to complete the process in a single day with an AI agent and models that were publicly accessible. The finding adds to evidence that AI systems can reduce the time required to identify software weaknesses and develop methods for exploiting them.

    Crypto users have already faced Zoom attacks

    The attack method is particularly relevant to the cryptocurrency industry because threat actors have repeatedly used video meetings as an entry point when targeting founders, developers, investors and executives.

    In January, crypto.news reported hackers were using compromised Telegram accounts and deepfake Zoom calls to target cryptocurrency professionals. The attackers impersonated people known to their targets before using apparent audio problems during the calls to convince victims to install malicious software.

    BTC Prague co-founder Martin Kuchař said at the time that a high-level campaign was targeting Bitcoin and crypto users. Attackers were using compromised accounts belonging to trusted contacts before moving conversations into video calls, where fake participants could appear through deepfake footage.

    Unlike those campaigns, the Zoomsday exploit described by A Security would not require a victim to install a supposed update if an attacker successfully exploited a vulnerable Zoom client. The researchers said simply being in the same meeting could provide the required path to the targeted machine.

    Similar Zoom-based attacks have already resulted in cryptocurrency theft.

    In September 2025, THORChain co-founder JP Thor lost about $1.3 million after a compromised Telegram account belonging to a friend was used to draw him into what appeared to be a legitimate Zoom meeting. As previously reported in September, Thor said he joined through an official Zoom link and saw a deepfake of his friend before a malicious script began copying files from his computer.

    The attackers gained access to sensitive information after the script started copying his iCloud documents folder into a temporary directory. Thor later traced the compromise back to the meeting.

    Fake Zoom calls have drained crypto wallets

    Other campaigns have relied on a longer chain of social engineering before malware reached the victim.

    A December 2025 report detailed a $300 million campaign in which North Korean hackers allegedly hijacked trusted Telegram accounts and used fake Zoom or Microsoft Teams meetings to target cryptocurrency executives.

    According to the report, attackers used prerecorded footage of recognizable industry contacts during the meetings and created fake technical problems. Victims were then directed to install supposed patches containing remote-access malware, which gave the attackers control over their computers and access to cryptocurrency wallets.

    An earlier attack against Hypersphere investment partner and former Animoca Brands executive Mehdi Farooq followed a similar pattern. In June 2025, Farooq said he lost a large portion of his life savings after receiving a Telegram message from a professional acquaintance whose account had been compromised. The attacker later asked him to move a scheduled conversation to Zoom Business before malware was introduced through a fake update.

    Manta Network co-founder Kenny Li also reported an attempted Zoom attack in April 2025. Li said a known contact invited him to a meeting where the participant appeared on camera but no audio could be heard. He was subsequently asked to download a script presented as a Zoom update, but avoided installing it and tried to verify the participant through another communication channel.

    The Zoomsday findings remove one of the main hurdles seen in those earlier attacks. Successful exploitation would not depend on persuading a crypto holder to install software or accept a fake update because the compromise could be triggered from inside the meeting itself.

    -- Price

    --

    AI cut Zoom vulnerability research to one day

    The speed at which the Zoom flaws were uncovered also follows several cases in which AI models have been used to search large software systems for security weaknesses.

    In April, Mozilla said an early version of Anthropic's Claude Mythos identified 271 vulnerabilities in Firefox during internal testing. All of the identified flaws were patched, while Mozilla said the experiment showed that AI could examine large codebases and identify security problems at a pace that would otherwise require extensive human review.

    The Firefox vulnerability research did not find bugs beyond what highly skilled security researchers could discover, but it demonstrated how the process could be accelerated.

    Zoom fixes still require users to update

    A Security said it reported the first Zoom vulnerability on June 10, two days after discovering it, and worked through the disclosure process while fixes were prepared.

    Zoom released fixes between June 22 and July 20, according to the researchers. According to the firm, updating the application remained necessary because a server-side protection designed to block malicious messages could not inspect the same content inside end-to-end encrypted meetings.

    Zoom separately advises users to run the latest versions of its software to receive current security fixes and improvements. Its July security bulletins also included CVE-2026-53412, a critical improper input validation vulnerability affecting Zoom Workplace for Windows that could allow an unauthenticated attacker to carry out an account takeover through network access.

    According to A Security, Zoom has patched the Zoomsday vulnerabilities, but users running older versions of the app still need to update their clients because server-side protections alone cannot fully block the attack.
    Read more: BitGo Q2 revenue rises 80% to $4.3B as loss hits $19M


    This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.

    You may also like

    Hyperliquid opens low-latency data access under $1K

    Hyperliquid opens low-latency data access under $1K

    Glassnode Identifies Conditions for a New Bitcoin Crash

    Glassnode Identifies Conditions for a New Bitcoin Crash

    From Subsidy Narrative to Real Returns: The Turning Point Year for DePIN Power Networks

    From Subsidy Narrative to Real Returns: The Turning Point Year for DePIN Power Networks

    What Lies Behind the Professional Appearance of Iranian Exchanges? 30 Criteria for Assessing Reality

    What Lies Behind the Professional Appearance of Iranian Exchanges? 30 Criteria for Assessing Reality

    J.P. Morgan's Global Market Strategy: Are Current Commodities Reminiscent of 2022?

    J.P. Morgan's Global Market Strategy: Are Current Commodities Reminiscent of 2022?

    Coldcard Hack Triggers $15 Billion in Bitcoin Transfers

    Coldcard Hack Triggers $15 Billion in Bitcoin Transfers

    Strategy sold $100M to defend STRC’s $100 stock price as DeFi packages the risk into a 7% ‘safer’ trade

    Strategy sold $100M to defend STRC’s $100 stock price as DeFi packages the risk into a 7% ‘safer’ trade

    Solstice is packaging Strategy’s STRC Bitcoin-related yield into a Solana-native product targeting 20%+ returns with first-loss exposure.
    MUFG to Demonstrate On-Chain Government Bond Repo Using Canton Infrastructure in Collaboration with Progmat and Digital Asset

    MUFG to Demonstrate On-Chain Government Bond Repo Using Canton Infrastructure in Collaboration with Progmat and Digital Asset

    Hyperliquid Market in the USA: Why DeFi Services Struggle to Exit the Regulatory Gray Zone

    Hyperliquid Market in the USA: Why DeFi Services Struggle to Exit the Regulatory Gray Zone

    The Hyperliquid market in the USA has become one of the main topics for the DeFi industry: decentralized finance projects want to work with American users, but even the potential adoption of the CLARITY Act does not eliminate key legal risks for them. The consideration of the CLARITY Act in the US S...
    US Inflation Slowdown Fails to Revive Bitcoin

    US Inflation Slowdown Fails to Revive Bitcoin

    What is the Sequoia investor who first backed Yushu concerned about?

    What is the Sequoia investor who first backed Yushu concerned about?

    700 Trillion Heading Overseas: The Digital Asset Market South Korea Missed – Tiger Research

    700 Trillion Heading Overseas: The Digital Asset Market South Korea Missed – Tiger Research

    AI Will Need Blockchains: Grayscale Identifies 4 Networks to Watch

    AI Will Need Blockchains: Grayscale Identifies 4 Networks to Watch

    Payments for agents, proof of humanity, decentralized AI: Grayscale places Ethereum, Solana, Worldcoin, and Bittensor at the heart of its thesis.
    Arthur Hayes says a $60 billion Fed cap is Bitcoin’s next liquidity trigger and needed for a price surge

    Arthur Hayes says a $60 billion Fed cap is Bitcoin’s next liquidity trigger and needed for a price surge

    Arthur Hayes sees a higher FIMA cap and usage as a Bitcoin liquidity trigger; the latest H.4.1 release shows zero foreign-official repos.
    Bitwise CIO sees crypto valuations doubling on token revenue

    Bitwise CIO sees crypto valuations doubling on token revenue

    Ethereum: The Awakening of Four Old Whales Revives Selling Fears

    Ethereum: The Awakening of Four Old Whales Revives Selling Fears

    Intel CEO Lip-Bu Tan's Latest Interview: After Missing Mobile, Cloud, and AI, We Cannot Miss the Next Wave

    Intel CEO Lip-Bu Tan's Latest Interview: After Missing Mobile, Cloud, and AI, We Cannot Miss the Next Wave

    MEXC Survey: TradFi Users Increasingly Interested in Multi-Asset Trading on CEX

    MEXC Survey: TradFi Users Increasingly Interested in Multi-Asset Trading on CEX

    Cryptocurrencies: He Steals $500,000 in USDC and Gets Ripped Off by an MEV Bot on Base

    Cryptocurrencies: He Steals $500,000 in USDC and Gets Ripped Off by an MEV Bot on Base

    A hacker steals $500,000 in USDC on Base, then gets sandwiched by an MEV bot on Uniswap V4 and loses $370,000 on August 6, 2026.
    JPMorgan Maintains Tencent's Overweight Rating with Target Price of HKD 690, Focused on AI Investment's Revenue Conversion

    JPMorgan Maintains Tencent's Overweight Rating with Target Price of HKD 690, Focused on AI Investment's Revenue Conversion

    Ethereum Reward Burn Proposal, Issuance at 60.25 Million Reaches Zero

    Ethereum Reward Burn Proposal, Issuance at 60.25 Million Reaches Zero

    The EIP-8363 proposal to burn a portion of Ethereum (ETH) validator rewards is intensifying the debate surrounding staking yield structures. If the proposal is confirmed, as the total staking approaches 60.25 million ETH, the ratio of newly issued validator rewards that are burned will increase, eve...
    Arizona crypto ATM law refunds $171K to scam victims

    Arizona crypto ATM law refunds $171K to scam victims

    The World We Will Face in 2036

    The World We Will Face in 2036

    Nebius Reports $5.6574 Billion in Capital Expenditures for Q1: Where Does the Expansion Funding Come From?

    Nebius Reports $5.6574 Billion in Capital Expenditures for Q1: Where Does the Expansion Funding Come From?

    How to Reasonably Value Unitree, the First Stock of Humanoid Robots?

    How to Reasonably Value Unitree, the First Stock of Humanoid Robots?

    Lao Bai Analyzes the Next Round of Crypto: VCs Will Disappear, Market Predictions Are Overvalued

    Lao Bai Analyzes the Next Round of Crypto: VCs Will Disappear, Market Predictions Are Overvalued

    Coherent's $2 Billion Quarter: Revenue, Profit Margins, and Capital Expenditures

    Coherent's $2 Billion Quarter: Revenue, Profit Margins, and Capital Expenditures

    Ethereum Awakens as ETH Price Awaits Its Moment

    Ethereum Awakens as ETH Price Awaits Its Moment

    Spotify Labels AI Artists: The Platform Finally Answers 'Who Are You Listening To'

    Spotify Labels AI Artists: The Platform Finally Answers 'Who Are You Listening To'

    DeepSeek Pushes Model Competition Back to the Application Layer with 6 Yuan per Million Tokens

    DeepSeek Pushes Model Competition Back to the Application Layer with 6 Yuan per Million Tokens

    Hyperliquid opens low-latency data access under $1K

    Glassnode Identifies Conditions for a New Bitcoin Crash

    From Subsidy Narrative to Real Returns: The Turning Point Year for DePIN Power Networks

    What Lies Behind the Professional Appearance of Iranian Exchanges? 30 Criteria for Assessing Reality

    J.P. Morgan's Global Market Strategy: Are Current Commodities Reminiscent of 2022?

    Coldcard Hack Triggers $15 Billion in Bitcoin Transfers

    ...
    Invite friends, get rewards
    Invite to get up to $160 + 40% commission
    Invite friends, get rewardsInvite

    Contents

    Zoom exploit could target any meeting participant
    Crypto users have already faced Zoom attacks
    Fake Zoom calls have drained crypto wallets
    APP
    AI cut Zoom vulnerability research to one day
    Zoom fixes still require users to update

    Latest articles

    2026/08/13

    New “Zoomsday” exploit could expose crypto users to zero click attacks

    APPAPP
    00.00%--
    SPYSPY
    00.00%--
    BASEDBASED
    00.00%--
    2026/08/13

    700 Trillion Heading Overseas: The Digital Asset Market South Korea Missed – Tiger Research

    SPOTSPOT
    00.00%--
    APPAPP
    00.00%--
    INDEXINDEX
    00.00%--
    BASEDBASED
    00.00%--
    2026/08/13

    The World We Will Face in 2036

    INDEXINDEX
    00.00%--
    APPAPP
    00.00%--
    NOWNOW
    00.00%--
    POWERPOWER
    00.00%--
    2026/08/12

    Solana Community Argues Over Whether Its Foundation Should Pick Winners

    APPAPP
    00.00%--
    THETHE
    00.00%--
    OPENOPEN
    00.00%--
    2026/08/12

    Who Really Captures Crypto Revenues?

    APPAPP
    00.00%--
    SPACESPACE
    00.00%--
    NOWNOW
    00.00%--
    THETHE
    00.00%--
    More

    Latest coin listings on WEEX

    logoCommunity
    iconiconiconiconiconiconicon
    Customer Support:@weikecs
    Business Cooperation:@weikecs
    Quant Trading & MM:bd@weex.com
    VIP Program:support@weex.com
    • About Us
    • Announcement Center
    • Media Kit
    • WEEX Community
    • WXT Zone
    • Announcement
    • Legal Statement
    • Risk Disclosure
    • Terms and Policies
    • Privacy Policy
    • Whistleblower Notice
    • AML/CTF Policy
    • Law Enforcement
    • User Guide
    • Product Launches
    • Crypto News
    • Product Launches
    • Crypto Wiki
    • Learn
    • Q&A
    • Spot
    • Futures
    • Glossary
    • VIP Program
    • Download
    • Affiliate
    • Protection Fund
    • Proof of Reserves
    • Sitemap
    • ETFs
    • Crypto Prices
    • Price Predictions
    • WXT Price
    • BTC Price
    • ETH Price
    • DOGE Price
    • How to Buy Crypto
    • How to Buy WXT
    • How to Buy BTC
    • How to Buy ETH
    • How to Buy DOGE
    • Help Center
    • Fee Schedule
    • Trading Rules
    • WEEX Academy
    • Contact Verifier
    • Submit Feedback
    • About Us
    • Announcement Center
    • Media Kit
    • WEEX Community
    • WXT Zone
    • Announcement
    • Help Center
    • Fee Schedule
    • Trading Rules
    • WEEX Academy
    • Contact Verifier
    • Submit Feedback
    • Customer Support Bot
    • VIP Services
    • Legal Statement
    • Risk Disclosure
    • Terms and Policies
    • Privacy Policy
    • Whistleblower Notice
    • AML/CTF Policy
    • Law Enforcement
    • Proof of Reserves
    • Invite Friends
    • OTC
    • Download
    • Affiliate
    • VIP Program
    • API
    • Broker
    • Listing Application
    • Affiliate T&C
    • Sitemap
    • Futures
    • Spot
    • Copy Trade
    • Markets
    • WEEX Store
    • User Guide
    • Product Launches
    • Crypto News
    • Product Launches
    • Crypto Wiki
    • Learn
    • Q&A
    • Spot
    • Futures
    • Glossary
    • VIP Program
    • Download
    • Affiliate
    • Protection Fund
    • Proof of Reserves
    • Sitemap
    • ETFs
    • Crypto Prices
    • Price Predictions
    • WXT Price
    • BTC Price
    • ETH Price
    • DOGE Price
    • How to Buy Crypto
    • How to Buy WXT
    • How to Buy BTC
    • How to Buy ETH
    • How to Buy DOGE
    • About Us
    • Announcement Center
    • Media Kit
    • WEEX Community
    • WXT Zone
    • Announcement
    • Help Center
    • Fee Schedule
    • Trading Rules
    • WEEX Academy
    • Contact Verifier
    • Submit Feedback
    • Legal Statement
    • Risk Disclosure
    • Terms and Policies
    • Privacy Policy
    • Whistleblower Notice
    • AML/CTF Policy
    • Law Enforcement
    • Customer Support Bot
    • VIP Services
    • Futures
    • Spot
    • Copy Trade
    • Markets
    • WEEX Store
    • Proof of Reserves
    • Invite Friends
    • OTC
    • Download
    • Affiliate
    • VIP Program
    • API
    • Broker
    • Listing Application
    • Affiliate T&C
    • Sitemap
    • User Guide
    • Product Launches
    • Crypto News
    • Product Launches
    • Crypto Wiki
    • Learn
    • Q&A
    • Spot
    • Futures
    • Glossary
    • VIP Program
    • Download
    • Affiliate
    • Protection Fund
    • Proof of Reserves
    • Sitemap
    • ETFs
    • Crypto Prices
    • Price Predictions
    • WXT Price
    • BTC Price
    • ETH Price
    • DOGE Price
    • How to Buy Crypto
    • How to Buy WXT
    • How to Buy BTC
    • How to Buy ETH
    • How to Buy DOGE

    Where new wealth is made

    Download app

    Sign Up
    h5 logo
    Download