Israeli cybersecurity firm ‘A Security’ has revealed three critical vulnerabilities in the Zoom application that allow hackers to take over users’ devices without requiring any victim interaction. The three flaws, labeled CVE-2026-53413, CVE-2026-53414, and CVE-2026-53415, target the annotation system, a feature commonly used to draw or add notes during screen-sharing sessions.
The exploit, named ‘Zoomsday’, is classified as zero-click. This means victims do not need to download suspicious files, click links, or approve any actions on their screens. The only requirement is to be in the same Zoom meeting room as the hacker. The attack is flexible, as it can be launched from the presenter to the participants, or vice versa. Researchers at ‘A Security’ confirmed that this vulnerability has been proven to compromise almost all popular operating systems in use today, including Windows, macOS, Linux, Android, and iOS.
Why This Vector Is Far More Dangerous
The crypto community is already familiar with being targeted via video conferencing applications. Throughout 2025, a series of hacks led to massive losses: THORChain founder JP Thor lost $1.3 million in September, followed by a $300 million campaign by a North Korean hacker syndicate in December that used fake Zoom and Teams applications. A few months earlier, Hypersphere executive Mehdi Farooq also lost a significant portion of his savings during a Zoom call in June.
However, there is a fundamental and critical difference between those previous cases and this latest discovery. In earlier attacks, perpetrators relied on social engineering to trick victims into downloading and installing fake software on their computers. In the Zoomsday scenario, hackers do not force victims to install any malicious programs at all. Once hackers gain entry and control the victim’s device via the annotation feature, they are free to maneuver: stealing personal data, installing crypto-stealing malware, and even turning on the microphone and camera to spy on the victim remotely.
A Weapon Assembled Using AI
There is one more fact worth noting from this vulnerability discovery: the ease and speed of its assembly. The Israeli security research team revealed that it took them less than 24 hours to detect the vulnerability in Zoom’s system and build a ready-to-use attack mechanism.
In the process, they did not write long code from scratch, but instead relied on fewer than 20 artificial intelligence (AI) instructions or prompts, using models freely available to the public. This speed proves how quickly a security vulnerability can be turned into a real hacking weapon with the help of AI.
For players in the Web3 industry whose daily schedules are packed with remote meetings, project presentations, or international screen-sharing sessions, Zoom meetings now present a real risk. Simply logging in, sitting down, and watching a screen presentation in the same virtual room is now enough to open the door for hackers. There are no more warnings or trap link notifications - the threat silently enters your system.
Reported from crypto.news.
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




