WhatsApp has begun a limited beta rollout of Scam Alert, an optional feature that uses on-device machine learning to flag likely scam messages from non-contacts while preserving end-to-end encryption. Users can decide whether to block, report, continue, or trust a flagged conversation, and can review Scam Alert activity in the app. WhatsApp said message content does not leave the device for classification, and the company has expanded its bug bounty program to cover the new feature, including its model weights and analytics pipeline.
To reduce privacy risks and targeted manipulation, WhatsApp said it verifies model releases through a transparency process that publishes each version’s SHA-256 hash to a third-party append-only ledger before deployment, while model downloads are routed through OHTTP relays with anonymous credentials. The company also said it measures effectiveness through a confidential federated analytics pipeline using Trusted Execution Environments, anonymous aggregation, and differential privacy, and may let users optionally share the last five messages from trusted chats to improve model accuracy. The rollout comes as Signal has also introduced automatic key verification based on key transparency logs and independent auditing to detect unauthorized public key changes in encrypted conversations.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Signal introduced automatic key verification, a key transparency-based feature designed to detect unauthorized public key changes in encrypted conversations. The system complements manual safety number checks and relies on cryptographically verifiable logs and independent auditors.
WhatsApp said it is expanding its bug bounty program to cover Scam Alert, including the feature's model weights and analytics pipeline. The expansion is intended to allow external researchers to assess the system's security and verify its scam-detection design.
WhatsApp started a limited beta rollout of Scam Alert, an optional feature that uses on-device machine learning to flag suspicious messages from non-contacts without breaking end-to-end encryption. The feature lets recipients block, report, ignore, or trust flagged chats, and keeps classification on the device.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
10 references tracked. Mallory keeps watching after this page renders.
infoq.com
Open sourcetechrepublic.com
Open sourceonlinethreatalerts.com
Open sourceghacks.net
Open sourcemkd-cirt.mk
Open sourcecybersecuritynews.com
Open sourcesecurityweek.com
Open sourceengineering.fb.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.