Signal has added a new feature meant to help users confirm they are really chatting with the intended person and not an impostor inserted in the middle. The feature, Automatic Key Verification (AKV), uses a new open-source key-transparency system with a public-key ledger, searchable index structures, and third-party auditors including Cloudflare and Trail of Bits to check whether a contact’s public encryption key unexpectedly changed. Users must still have the contact’s phone number to use it.
Why it matters: This matters for journalists, activists, officials, and other users who depend on Signal to resist interception and impersonation. It is not an emergency patch, but it is a meaningful security improvement that users should enable when available, especially for sensitive conversations.
Eduard Kovacs
2026.08.12
81% relevant
This article directly updates that Signal event by adding implementation details on how users invoke Automatic Key Verification and what attack scenario it is meant to detect, while also bundling separate news about WhatsApp’s new on-device Scam Alert beta.
Sergiu Gatlan
2026.08.12
99% relevant
This article is a direct report on Signal’s rollout of Automatic Key Verification, adding implementation details on how key transparency works, how users enable it, and how it complements manual safety number checks.
2026.08.11
100% relevant
This article establishes a new trackable security story about Signal’s rollout of Automatic Key Verification, not a breach or vulnerability already listed in the tracker.
← Back to all stories