"It works through a system of verifications performed by you, your Signal connections, and third-party auditors that together provide the same assurance as manually verifying safety numbers," Signal software engineer Katherine Yen said, describing a new layer of protection intended to prevent attackers from quietly swapping encryption keys.
Katherine Yen on Automatic Key Verification
Signal has rolled out Automatic Key Verification, a feature that lets users confirm that their encrypted chats have not been intercepted without having to meet in person or use a secondary channel. The company describes the capability as part of a broader "key transparency" approach that combines verifications by end users, their Signal contacts, and third‑party auditors.
Key transparency and independent auditors: Cloudflare and Trail of Bits
The key transparency system relies on two named third‑party independent auditors: Cloudflare and Trail of Bits. Signal says these auditors verify the integrity of conversations by checking that the association between a phone number or username and its public encryption key is "globally consistent and transparent to all participants in Signal's ecosystem." The company framed this as protection against situations where "a key is swapped out without the key owner's knowledge"—for example if the service itself were compromised and a different key was associated with a contact's phone number.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleHow Automatic Key Verification appears to users
Users can enable Automatic Key Verification by navigating in the Signal app to Settings > Privacy > Advanced and toggling the feature on. When chatting, a user can also click "Verify Automatically" on the safety number verification screen; a successful automatic verification displays a green checkmark and the message "Encryption verified." Signal emphasized that users who prefer not to rely on automatic verifications or third‑party auditors can disable the feature and continue to use manual safety number checks.
May warnings and the Linked Device abuse that prompted them
Automatic Key Verification follows other recent security changes. In May, Signal introduced new warning messages and in‑app confirmations intended to give users time to evaluate external requests—safeguards the company linked to attacks attributed to Russian state‑sponsored hackers. Those attacks targeted high‑profile users with bogus "Signal Support" alerts that abused Signal's Linked Device feature to gain access to accounts, chats, and contact lists, according to reports cited from the FBI, the German authorities, and the Dutch government.
U.S. Department of State bounties and named threat clusters
One month after the May advisories, the U.S. Department of State announced bounties of up to $10 million for information that helps identify or locate members of two named hacker groups—UNC5792 and UNC4221—linked to "widespread phishing campaigns targeting Signal users," according to Signal's account of the timeline. The bounty announcement and the earlier abuse of the Linked Device feature frame Automatic Key Verification as one element in a broader effort to blunt phishing and account‑takeover techniques.
What this means for technologists, policymakers, and end users
- Technologists and security teams: will evaluate whether key transparency proofs and third‑party auditors such as Cloudflare and Trail of Bits provide a practical, scalable alternative to manual safety‑number verification—especially for users who cannot meet in person or use a secondary channel.
- Policymakers and law enforcement: now have a public, technical response layered on top of attribution and bounty efforts; the Department of State's up to $10 million bounties for UNC5792 and UNC4221 remain a parallel approach to disrupting phishing campaigns targeting Signal users.
- End users, including high‑profile targets: can choose between Automatic Key Verification and manual safety number verification. The new in‑app warnings introduced in May and the automatic verification option give users two different, user‑facing controls to counter the Linked Device abuse documented by the FBI, German authorities, and the Dutch government.
Signal frames Automatic Key Verification not as a replacement for existing safeguards but as a complement: "Key transparency offers an easy‑to‑use way to confirm an important part of messaging security, complementing our existing safety number system," the company said. That emphasis on layered defenses echoes a separate line in the source material noting that overall prevention metrics can obscure what happens after attackers gain initial access—an argument in favor of continuous, independent checks that make key‑swapping or silent interception harder to achieve.
The rollout leaves open practical questions for observers and defenders alike: how auditors will surface inconsistencies, how often automatic verifications will disagree with manual safety numbers in the wild, and whether the added visibility will change attacker tradecraft. For now, users have a new toggle and a visible green checkmark; the broader test will be whether those signals reduce successful account takeovers in the campaigns already tied to UNC5792 and UNC4221.




