Signal adds Automatic Key Verification to detect tampering with contacts’ encryption keys

Signal has added a new feature meant to help users confirm they are really chatting with the intended person and not an impostor inserted in the middle. The feature, Automatic Key Verification (AKV), uses a new open-source key-transparency system with a public-key ledger, searchable index structures, and third-party auditors including Cloudflare and Trail of Bits to check whether a contact’s public encryption key unexpectedly changed. Users must still have the contact’s phone number to use it.
Why it matters: This matters for journalists, activists, officials, and other users who depend on Signal to resist interception and impersonation. It is not an emergency patch, but it is a meaningful security improvement that users should enable when available, especially for sensitive conversations.

Sources

WhatsApp Unveils New Scam Alert Feature
Eduard Kovacs 2026.08.12 81% relevant
This article directly updates that Signal event by adding implementation details on how users invoke Automatic Key Verification and what attack scenario it is meant to detect, while also bundling separate news about WhatsApp’s new on-device Scam Alert beta.
Signal adds new security feature to thwart man-in-the-middle attacks
Sergiu Gatlan 2026.08.12 99% relevant
This article is a direct report on Signal’s rollout of Automatic Key Verification, adding implementation details on how key transparency works, how users enable it, and how it complements manual safety number checks.
Signal adds an extra layer of security to make sure you're actually chatting with the right person
2026.08.11 100% relevant
This article establishes a new trackable security story about Signal’s rollout of Automatic Key Verification, not a breach or vulnerability already listed in the tracker.
← Back to all stories