Signal has rolled out a new security feature designed to thwart man-in-the-middle (MITM) attacks on its encrypted chat platform. Automatic Key Verification is part of a “key transparency” system that uses trusted third-party auditors to verify the integrity of Signal conversations, giving users a new way to ensure their chats haven’t been intercepted.
This new feature is particularly relevant in today’s digital landscape, where cyber threats are increasingly sophisticated and targeted. In recent months, we’ve seen high-profile attacks on Signal users, including phishing campaigns attributed to Russian state-sponsored hackers who exploited the platform’s Linked Device feature to gain access to victims’ accounts, chats, and contact lists. As a result of these incidents, the U.S. Department of State has offered bounties of up to $10 million for anyone who can help identify or locate members of the UNC5792 and UNC4221 hacker groups.
So how does Automatic Key Verification work? In essence, it’s a system of verifications performed by the user, their Signal connections, and third-party auditors that together provide assurance similar to manually verifying safety numbers. Unlike traditional safety number verification, which requires an in-person meeting or secondary communication channel, this new feature allows users to verify the public key of Signal users they’re chatting with directly within the app.
To enable Automatic Key Verification on Signal, simply go to Settings > Privacy > Advanced and toggle the switch on. You can also verify a user’s public key by clicking “Verify Automatically” on the safety number verification screen. If the verification is successful, the app displays a green checkmark and an “Encryption verified” message.
While this new feature offers an easy-to-use way to confirm the security of Signal conversations, it’s essential to remember that no system is foolproof. Users who prefer not to rely on Signal or independent auditors can still disable automatic key verification in their privacy settings and continue using manual safety number verification.
The introduction of Automatic Key Verification marks a significant step forward for Signal’s commitment to user security. As the platform continues to evolve, it’s clear that the company is taking seriously the need to protect its users from increasingly sophisticated cyber threats.
In practical terms, this new feature offers an additional layer of protection against MITM attacks, which are particularly concerning in encrypted chat platforms like Signal. By verifying the public key of Signal users you’re chatting with, you can ensure that your conversations remain secure and private. As always, it’s essential to stay vigilant and keep your security settings up-to-date to minimize the risk of falling victim to cyber threats.
Source: Bleeping Computer — 2026-08-12