
Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats are not intercepted.
The new feature is part of a “Key Transparency” system that Cloudflare uses and Trail of bits as trusted independent auditors to verify the integrity of Signal conversations.
“It works through a system of checks carried out by you, your signals connections and external auditors, which together provide the same level of security as manual verification of security numbers. Unlike security numbers, these checks are carried out independently and do not require a face-to-face meeting or a secondary communication channel.” Signal software engineer Katherine Yen said.
“This verification system ensures that the association between a phone number or username and its public encryption key is globally consistent and transparent to all participants in the Signal ecosystem. This protects against scenarios where a key is exchanged without the knowledge of the key owner – for example, if a malicious party has manipulated Signal and associated a different key with the phone number on your connection.”
Users can enable automatic key verification in Signal by going to Settings > Privacy > Advanced and turning on automatic key verification.
You can also verify the public key of the Signal users they are chatting with by clicking “Auto Verify” on the security number verification screen. If the verification is successful, the app will display a green checkmark and an “Encryption verified” message.

Users who do not want to rely on Signal or independent verifiers can disable the automatic key verification feature in the privacy settings and continue to use manual security number verification.
“Key Transparency provides a user-friendly way to confirm an important part of message security and complements our existing security number system,” Signal said.
“Over time, this verification, combined with the checks conducted on an ongoing basis by your Signal connection and third-party auditors, ensures the consistency of that Signal connection’s key across the Signal ecosystem.”
In May, Signal also introduced new alerts and in-app confirmations designed to give users time to assess the security of an external request, as additional protections against phishing and social engineering attempts.
This was triggered by attacks attributed to state-sponsored Russian hackers who targeted high-profile users with fake “Signal Support” notifications that abused Signal’s linked device feature to gain access to the target’s account, chats and contact lists, according to the FBI, German authorities and the Dutch government.
A month later, the U.S. State Department announced bounties of up to $10 million for anyone who can help identify or locate members of hacking groups UNC5792 and UNC4221, which are linked to widespread phishing campaigns against Signal users.
Overall prevention scores can hide what happens after the first access. Once attackers use valid credentials, prevention drops sharply.
The 2026 Blue Report measures defense technology for technology in 338 million simulations conducted in customer production environments.


