Signal has introduced Automatic Key Verification, a new security feature designed to help users confirm that their encrypted conversations have not been intercepted or manipulated. The feature adds automated checks to Signal’s existing safety-number system and aims to make secure verification easier for everyday users.
Signal adds a key transparency system
Automatic Key Verification is based on key transparency, a system that checks whether a Signal account’s phone number or username is consistently linked to the correct public encryption key.
This matters because a man-in-the-middle attack can succeed if an attacker secretly replaces a user’s encryption key. For example, a malicious party that gained access to Signal’s systems could attempt to associate its own key with a victim’s account.
Signal says its new system helps detect this type of inconsistency. It combines checks performed by the user, their Signal contacts and independent third-party auditors.
Cloudflare and Trail of Bits act as external auditors within the system. Their role is to help verify that the public-key records remain consistent across Signal’s wider ecosystem.
Automatic verification removes a common barrier
Until now, Signal users who wanted to verify a chat manually needed to compare safety numbers with their contact. That often required meeting in person or using another trusted communication channel.
Automatic Key Verification provides similar assurance without requiring that additional step. Instead, the app carries out the verification independently over time.
Users can enable the feature through Signal’s privacy settings. They can also open the safety-number screen for an existing chat and select the automatic verification option.
Once the check succeeds, Signal displays a green checkmark and an Encryption verified message. This confirms that the contact’s public key has passed the automated verification process.
Users can still verify safety numbers manually
Automatic Key Verification is optional. Users who prefer not to rely on Signal or the independent auditors can turn it off in the privacy settings.
They can then continue using Signal’s manual safety-number verification process. The new feature is intended to complement that existing option rather than replace it completely.
Signal says the repeated checks performed by users, contacts and auditors create stronger long-term confidence that a contact’s key has not changed unexpectedly.
The feature focuses on one important part of secure messaging: confirming that the encryption key attached to a specific Signal account is genuine and globally consistent.
Signal continues to address phishing attacks
The release follows other security changes Signal introduced in May 2026. The company added warnings and in-app confirmations to help users recognise suspicious external requests before acting on them.
Those changes followed phishing campaigns that used fake Signal Support alerts. The attacks abused Signal’s Linked Device feature to gain access to targeted accounts, chats and contact lists.
Authorities in the United States, Germany and the Netherlands warned about the campaigns, which targeted high-profile users. The activity was attributed to Russian state-linked threat actors.
In June, the US Department of State announced rewards of up to $10 million for information that could help identify members of the UNC5792 and UNC4221 hacking groups, which were linked to broader phishing operations against Signal users.
Automatic Key Verification adds another layer of protection by helping Signal users detect unauthorised changes that could expose otherwise encrypted conversations.


0 responses to “Signal adds Automatic Key Verification to block man-in-the-middle attacks”