
Signal has launched Automatic Key Verification, a new security feature designed to ensure that encrypted conversations haven’t been silently intercepted. The system uses Cloudflare and Trail of Bits as trusted, independent third-party auditors to verify the integrity of Signal conversations — confirming that the public encryption key associated with a phone number or username is genuine and hasn’t been secretly swapped for an attacker’s key. “This protects against scenarios where a key is swapped out without the key owner’s knowledge — for example, if a malicious party compromised Signal and associated a different key with your connection’s phone number,” Signal software engineer Katherine Yen explained.
The feature is opt-in and builds on Signal’s existing safety numbers system, which previously required users to compare codes in person or via a secondary channel. With Automatic Key Verification, that check happens continuously in the background using the auditor network. Users who prefer to rely on manual verification can keep the feature off. The update was prompted in part by a wave of Russian state-sponsored attacks that abused Signal’s Linked Device feature to silently gain access to high-profile users’ accounts — incidents reported by the FBI, German authorities, and Dutch government agencies.
How to check if you’re affected
Affected versions of Signal include all current versions on iOS, Android, and desktop. To enable the new protection, open Signal and go to Settings → Privacy → Advanced, then toggle on Automatic Key Verification. Once enabled, Signal will display a green checkmark and “Encryption verified” message after successfully confirming a contact’s key. If you prefer not to use the auditor-based system, you can continue using manual safety number verification with no change to your security.
