Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven’t been intercepted.
The new feature is part of a “key transparency” system that uses Cloudflare and Trail of Bits as trusted third-party independent auditors to verify the integrity of Signal conversations.
“It works through a system of verifications performed by you, your Signal connections, and third-party auditors that together provide the same assurance as manually verifying safety numbers. Unlike safety numbers, these verifications are done independently and do not require an in-person meeting or a secondary communication channel,” Signal software engineer Katherine Yen said.
“This system of verifications ensures that the association between a phone number or username and its public encryption key is globally consistent and transparent to all participants in Signal’s ecosystem. This protects against scenarios where a key is swapped out without the key owner’s knowledge — for example, if a malicious party compromised Signal and associated a different key with your connection’s phone number.”
Users can enable Automatic Key Verification in Signal by going to Settings > Privacy > Advanced and toggling on Automatic Key Verification.
They can also verify the public key of Signal users they’re chatting with by clicking “Verify Automatically” on the safety number verification screen. If the verification is successful, the app displays a green checkmark and an “Encryption verified” message.

Users who do not want to rely on Signal or independent auditors can disable the automatic key verification feature in the privacy settings and continue using manual safety number verification.
“Key transparency offers an easy-to-use way to confirm an important part of messaging security, complementing our existing safety number system,” Signal said.
“Over time, this verification, combined with the ones continually performed by your Signal connection and third-party auditors, ensures the consistency of this Signal connection’s key across the Signal ecosystem.”
In May, Signal also introduced new warning messages and in-app confirmations designed to give users time to evaluate the safety of an external request as additional safeguards against phishing and social engineering attempts.
This was prompted by attacks attributed to Russian state-sponsored hackers who targeted high-profile users with bogus ‘Signal Support’ alerts that abused Signal’s Linked Device feature to gain access to the target’s account, chats, and contact lists, as reported by the FBI, the German authorities, and the Dutch government.
One month later, the U.S. Department of State announced bounties of up to $10 million for anyone who can help identify or locate members of the UNC5792 and UNC4221 hacker groups linked to widespread phishing campaigns targeting Signal users.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.




