A newly disclosed set of Zoom vulnerabilities has shown how attackers could take control of another meeting participant's device without any action from the victim, creating a fresh security risk for crypto users who have repeatedly been targeted through video calls.
Summary
According to Israeli cybersecurity firm A Security, a researcher used fewer than 20 prompts with publicly available artificial intelligence models to uncover the flaws and build a working attack in less than 24 hours. The firm named the attack "Zoomsday" and said the vulnerabilities affected Zoom's annotation system, which lets meeting participants draw or add notes to shared content.
Once exploited, the flaws could allow malicious code to run on another participant's device without requiring the person to download a file, click a link, or approve an action, according to the report. According to the firm, the attacker could then steal personal information, install malware, or activate a device's microphone and camera.
For cryptocurrency users, the ability to compromise a computer directly through a meeting could carry added risks because attackers have previously used Zoom calls to reach crypto wallets, private files and other sensitive information.
The vulnerabilities, tracked as CVE-2026-53413, CVE-2026-53414 and CVE-2026-53415, were tested against Zoom applications running on Windows, macOS, Linux, Android and iOS.
The attack could work from either side of a call. According to the researchers, a compromised presenter could attack participants, while a participant could also target the presenter. An attacker only needed to join or host the meeting before sending the malicious data required to trigger the vulnerability.
No further interaction was required from the target, and A Security said the victim would receive no visible warning that the device had been compromised.
You might also like: North Korean 'fake Zoom' hustle drains $300m from crypto execs' wallets
"Once the nefarious code is running on the victim's device, the threat actor can quietly steal personal data, switch on the microphone or camera to spy on the target, or install other malicious software," the firm said.
"Exploits like this one are weapons. Governments regulate their export. Criminal organizations pay millions for them," the researchers wrote.
According to the firm, researchers were able to complete the process in a single day with an AI agent and models that were publicly accessible. The finding adds to evidence that AI systems can reduce the time required to identify software weaknesses and develop methods for exploiting them.
The attack method is particularly relevant to the cryptocurrency industry because threat actors have repeatedly used video meetings as an entry point when targeting founders, developers, investors and executives.
In January, crypto.news reported hackers were using compromised Telegram accounts and deepfake Zoom calls to target cryptocurrency professionals. The attackers impersonated people known to their targets before using apparent audio problems during the calls to convince victims to install malicious software.
BTC Prague co-founder Martin Kuchař said at the time that a high-level campaign was targeting Bitcoin and crypto users. Attackers were using compromised accounts belonging to trusted contacts before moving conversations into video calls, where fake participants could appear through deepfake footage.
Unlike those campaigns, the Zoomsday exploit described by A Security would not require a victim to install a supposed update if an attacker successfully exploited a vulnerable Zoom client. The researchers said simply being in the same meeting could provide the required path to the targeted machine.
Similar Zoom-based attacks have already resulted in cryptocurrency theft.
In September 2025, THORChain co-founder JP Thor lost about $1.3 million after a compromised Telegram account belonging to a friend was used to draw him into what appeared to be a legitimate Zoom meeting. As previously reported in September, Thor said he joined through an official Zoom link and saw a deepfake of his friend before a malicious script began copying files from his computer.
The attackers gained access to sensitive information after the script started copying his iCloud documents folder into a temporary directory. Thor later traced the compromise back to the meeting.
Other campaigns have relied on a longer chain of social engineering before malware reached the victim.
A December 2025 report detailed a $300 million campaign in which North Korean hackers allegedly hijacked trusted Telegram accounts and used fake Zoom or Microsoft Teams meetings to target cryptocurrency executives.
According to the report, attackers used prerecorded footage of recognizable industry contacts during the meetings and created fake technical problems. Victims were then directed to install supposed patches containing remote-access malware, which gave the attackers control over their computers and access to cryptocurrency wallets.
An earlier attack against Hypersphere investment partner and former Animoca Brands executive Mehdi Farooq followed a similar pattern. In June 2025, Farooq said he lost a large portion of his life savings after receiving a Telegram message from a professional acquaintance whose account had been compromised. The attacker later asked him to move a scheduled conversation to Zoom Business before malware was introduced through a fake update.
Manta Network co-founder Kenny Li also reported an attempted Zoom attack in April 2025. Li said a known contact invited him to a meeting where the participant appeared on camera but no audio could be heard. He was subsequently asked to download a script presented as a Zoom update, but avoided installing it and tried to verify the participant through another communication channel.
The Zoomsday findings remove one of the main hurdles seen in those earlier attacks. Successful exploitation would not depend on persuading a crypto holder to install software or accept a fake update because the compromise could be triggered from inside the meeting itself.
The speed at which the Zoom flaws were uncovered also follows several cases in which AI models have been used to search large software systems for security weaknesses.
In April, Mozilla said an early version of Anthropic's Claude Mythos identified 271 vulnerabilities in Firefox during internal testing. All of the identified flaws were patched, while Mozilla said the experiment showed that AI could examine large codebases and identify security problems at a pace that would otherwise require extensive human review.
The Firefox vulnerability research did not find bugs beyond what highly skilled security researchers could discover, but it demonstrated how the process could be accelerated.
A Security said it reported the first Zoom vulnerability on June 10, two days after discovering it, and worked through the disclosure process while fixes were prepared.
Zoom released fixes between June 22 and July 20, according to the researchers. According to the firm, updating the application remained necessary because a server-side protection designed to block malicious messages could not inspect the same content inside end-to-end encrypted meetings.
Zoom separately advises users to run the latest versions of its software to receive current security fixes and improvements. Its July security bulletins also included CVE-2026-53412, a critical improper input validation vulnerability affecting Zoom Workplace for Windows that could allow an unauthenticated attacker to carry out an account takeover through network access.
According to A Security, Zoom has patched the Zoomsday vulnerabilities, but users running older versions of the app still need to update their clients because server-side protections alone cannot fully block the attack.
Read more: BitGo Q2 revenue rises 80% to $4.3B as loss hits $19M
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.



![[Editorial] The Rails Are Laid Before the World Notices](/public-static/01_76947305d1.png?format=avif)















Since 2018, WEEX has built its trading experience on three pillars — security, cross-asset access, and liquidity. Here's how a 1,000 BTC Protection Fund, 330+ TradFi pairs, and Top-2 BTC futures liquidity translate into faster fills, safer trades, and more markets in one account.










