Signal Introduces Automatic Key Verification to Protect Encrypted Chats
Signal has introduced automatic key verification, a new security feature designed to help users confirm that their encrypted conversations have not been intercepted or altered.
The feature uses Signal’s Key Transparency system together with Cloudflare and Trail of Bits, an independent third-party security auditor that helps verify the integrity of Signal conversations.
“It works through a verification system performed by customers, Signal connections, and third-party auditors to provide the same assurance as manually verifying safety numbers,” said Katherine Yen, a Signal software engineer.
“Unlike safety numbers, these verifications are completed independently and do not require in-person meetings or secondary communication channels.”
Signal says the validation system ensures that the link between a user’s phone number or username and their public encryption key remains globally consistent and transparent across the Signal ecosystem.
This helps protect against attacks in which a malicious actor compromises Signal or another part of the communication process and associates a different encryption key with a user’s phone number without the account owner’s knowledge.
Users can enable automatic key verification in Signal by going to Settings > Privacy > Advanced and switching on the automatic key verification option.
Automatic verification can also be started from the safety number verification screen. After verification succeeds, Signal displays a green checkmark and the message “Encryption verified.”

Users who prefer not to rely on Signal or independent auditors can disable automatic key verification in the privacy settings. They can then continue to verify contacts manually using Signal safety numbers.
“Key Transparency provides an easy-to-use way to verify a critical part of messaging security and complements existing safety number systems,” Signal said.
The company added that ongoing validation by Signal connections and third-party auditors helps confirm that a contact’s encryption keys remain consistent across the Signal ecosystem over time.
Signal’s automatic key verification feature arrives as the encrypted messaging platform continues adding protections against phishing, account takeovers, and social engineering attacks.
In May, Signal introduced new warning messages and in-app confirmations designed to give users more time to evaluate suspicious requests. The changes were intended to help prevent attacks involving fake “Signal Support” alerts and abuse of the app’s Link Devices feature.
The attacks, which targeted high-profile Signal users and attempted to access their accounts, chats, and contact lists, were attributed to Russian state-sponsored hackers, according to reports from the FBI, German authorities, and the Dutch government.
A month later, the U.S. Department of State announced a reward of up to $10 million for information that helps identify or locate members of the UNC5792 and UNC4221 hacking groups. The groups have been linked to widespread phishing campaigns targeting Signal users.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




