Yu Xian, founder of SlowMist, analyzed the "He Yi's WeChat account theft" incident, stating that the hacker likely seized control of the user's long-abandoned phone number, thereby taking over the identity infrastructure linked to WeChat. Another common risk is CAPTCHA social engineering attacks: after obtaining a user's leaked account password, hackers impersonate the user and request a 6-digit verification code from two of their frequently contacted WeChat friends, thus completing the account theft. Yu Xian pointed out that the prerequisites for such attacks include matching account passwords from leaked data and prior collection of information about the victim's frequently contacted friends (even users who only interact in group chats). Attackers often choose to carry out these attacks late at night, commonly seen in OTC scams targeting cryptocurrency users. He reminded users to be cautious when adding unfamiliar WeChat friends, change their passwords promptly, and pay attention to various risk warnings from WeChat.